Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7553-6 June 09, 2025 linux-azure-fips vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-azure-fips: Linux kernel for Microsoft Azure Cloud systems with FIPS Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Clock framework and drivers; - GPU drivers; - Parport drivers; - Ext4 file system; - JFFS2 file system; - JFS file system; - File systems infrastructure; - Sun RPC protocol; - USB sound devices; (CVE-2024-56551, CVE-2024-47701, CVE-2024-57850, CVE-2024-26966, CVE-2021-47211, CVE-2024-56596, CVE-2024-53155, CVE-2024-42301, CVE-2024-53168) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS linux-image-4.15.0-2098-azure-fips 4.15.0-2098.104 Available with Ubuntu Pro linux-image-azure-fips 4.15.0.2098.94 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7553-6 https://ubuntu.com/security/notices/USN-7553-5 https://ubuntu.com/security/notices/USN-7553-4 https://ubuntu.com/security/notices/USN-7553-3 https://ubuntu.com/security/notices/USN-7553-2 https://ubuntu.com/security/notices/USN-7553-1 CVE-2021-47211, CVE-2024-26966, CVE-2024-42301, CVE-2024-47701, CVE-2024-53155, CVE-2024-53168, CVE-2024-56551, CVE-2024-56596, CVE-2024-57850 Package Information: . Addresses multiple vulnerabilities in the Ubuntu 20.04 LTS kernel for Azure FIPS environments, improving overall performance.. Azure FIPS, Linux kernel, Ubuntu security, flaw correction, cloud security. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7450-1 April 23, 2025 linux-gcp, linux-gke, linux-gkeop vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-gke: Linux kernel for Google Container Engine (GKE) systems - linux-gkeop: Linux kernel for Google Container Engine (GKE) systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - MIPS architecture; - PowerPC architecture; - RISC-V architecture; - S390 architecture; - SuperH RISC architecture; - User-Mode Linux (UML); - x86 architecture; - Block layer subsystem; - Cryptographic API; - Compute Acceleration Framework; - ACPI drivers; - Drivers core; - RAM backed block device driver; - Compressed RAM block device driver; - TPM device driver; - Clock framework and drivers; - Data acquisition framework and drivers; - CPU frequency scaling framework; - Hardware crypto device drivers; - CXL (Compute Express Link) drivers; - EDAC drivers; - ARM SCMI message protocol; - ARM SCPI message protocol; - EFI core; - GPIO subsystem; - GPU drivers; - HID subsystem; - I3C subsystem; - IIO ADC drivers; - IIO subsystem; - InfiniBand drivers; - IOMMU subsystem; - LED subsystem; - Multiple devices driver; - Media drivers; - Multifunction device drivers; - MMC subsystem; - MTD block device drivers; - Network drivers; - Mellanox network drivers; - STMicroelectronics network drivers; - NVME drivers; - PCI subsystem; - PHY drivers; - Pin controllers subsystem; - x86 platform drivers; - i.MX PM domains; - Voltage and Current Regulator drivers; - StarFive reset controller drivers; - Real Time Clock drivers; - SCSI subsystem; - i.MX SoC drivers; - QCOM SoC drivers; - Xilinx SoC drivers; - SPI subsystem; - Media staging drivers; - TCM subsystem; - UFS subsystem; - DesignWare USB3 driver; - USB Dual Role (OTG-ready) Controller drivers; - USB Serial drivers; - USB Type-C support driver; - USB Type-C Port Controller Manager driver; - USB Type-C Connector System Software Interface driver; - vDPA drivers; - VFIO drivers; - Framebuffer layer; - Xen hypervisor drivers; - AFS file system; - BTRFS file system; - File systems infrastructure; - EROFS file system; - F2FS file system; - JFFS2 file system; - JFS file system; - Network file systems library; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NILFS2 file system; - NTFS3 file system; - Overlay file system; - Proc file system; - Diskquota system; - SMB network file system; - UBI file system; - DRM display driver; - BPF subsystem; - StackDepot library; - Bluetooth subsystem; - IP tunnels definitions; - Netfilter; - Tracing infrastructure; - User-space API (UAPI); - Kernel init infrastructure; - io_uring subsystem; - IPC subsystem; - DMA mapping infrastructure; - Kernel fork() syscall; - KCSAN framework; - RCU subsystem; - Arbitrary resource management; - Scheduler infrastructure; - Signal handling mechanism; - Task handling mechanism; - Timer subsystem; - KUnit library; - Memory management; - 9P file system network protocol; - CAN network layer; - Networking core; - DCCP (Datagram Congestion Control Protocol); - Ethtool driver; - HSR network protocol; - IEEE802154.4 network protocol; - IPv4 networking; - IPv6 networking; - IUCV driver; - MAC80211 subsystem; - Multipath TCP; - Packet sockets; - RxRPC session sockets; - Network traffic control; - SCTP protocol; - SMC sockets; - Sun RPC protocol; - TIPC protocol; - VMware vSockets driver; - Wireless networking; - eXpress Data Path; - XFRM subsystem; - Integrity Measurement Architecture(IMA) framework; - Key management; - ALSA framework; - FireWire sound drivers; - HD-audio driver; - MediaTek ASoC drivers; - QCOM ASoC drivers; - SoC audio core drivers; - STMicroelectronics SoC drivers; - USB sound devices; (CVE-2024-50051, CVE-2024-56546, CVE-2024-56551, CVE-2024-53236, CVE-2024-50244, CVE-2024-53043, CVE-2024-56694, CVE-2025-21700, CVE-2024-56700, CVE-2025-21993, CVE-2024-53224, CVE-2024-50105, CVE-2024-53100, CVE-2024-56690, CVE-2024-50150, CVE-2024-53223, CVE-2024-50285, CVE-2024-50269, CVE-2024-53089, CVE-2024-53044, CVE-2024-53175, CVE-2024-57849, CVE-2024-50296, CVE-2024-50120, CVE-2024-50147, CVE-2024-56540, CVE-2024-56602, CVE-2024-50289, CVE-2024-53127, CVE-2024-56786, CVE-2024-50108, CVE-2024-53045, CVE-2024-53067, CVE-2024-50138, CVE-2024-53173, CVE-2024-50143, CVE-2024-56678, CVE-2024-53130, CVE-2024-53157, CVE-2024-56723, CVE-2024-56623, CVE-2024-53234, CVE-2024-53088, CVE-2024-53068, CVE-2024-53195, CVE-2024-53188, CVE-2024-56613, CVE-2024-56561, CVE-2024-53218, CVE-2024-50215, CVE-2024-53227, CVE-2024-50139, CVE-2024-50170, CVE-2024-56640, CVE-2024-56720, CVE-2024-56780, CVE-2024-56705, CVE-2024-53131, CVE-2024-56597, CVE-2024-50224, CVE-2024-57843, CVE-2024-50251, CVE-2024-50243, CVE-2024-53200, CVE-2024-50280, CVE-2024-50303, CVE-2024-50107, CVE-2024-56606, CVE-2024-53237, CVE-2024-53161, CVE-2024-56685, CVE-2024-53185, CVE-2024-56785, CVE-2024-53150, CVE-2024-53166, CVE-2024-50141, CVE-2024-50158, CVE-2024-47143, CVE-2024-56773, CVE-2024-53090, CVE-2024-56778, CVE-2024-50142, CVE-2025-21701, CVE-2024-50301, CVE-2024-53050, CVE-2024-50211, CVE-2024-50246, CVE-2024-50252, CVE-2024-53122, CVE-2024-53085, CVE-2024-50104, CVE-2024-50288, CVE-2024-53151, CVE-2024-56728, CVE-2024-53086, CVE-2024-56568, CVE-2024-53133,CVE-2024-50290, CVE-2024-56774, CVE-2024-50278, CVE-2024-56565, CVE-2024-53147, CVE-2024-56775, CVE-2024-53239, CVE-2024-56533, CVE-2024-50225, CVE-2024-50124, CVE-2024-47794, CVE-2024-50163, CVE-2024-53680, CVE-2024-56574, CVE-2024-56605, CVE-2024-50112, CVE-2024-53221, CVE-2024-56751, CVE-2024-56538, CVE-2024-53123, CVE-2024-56688, CVE-2024-50239, CVE-2024-56742, CVE-2024-56752, CVE-2024-53059, CVE-2024-50282, CVE-2024-50238, CVE-2024-53108, CVE-2024-50152, CVE-2024-53214, CVE-2024-53226, CVE-2024-50292, CVE-2024-56580, CVE-2024-56621, CVE-2024-56593, CVE-2024-56689, CVE-2024-56649, CVE-2024-56650, CVE-2024-53203, CVE-2024-56626, CVE-2025-21831, CVE-2024-53053, CVE-2024-50257, CVE-2024-50203, CVE-2024-56643, CVE-2024-50231, CVE-2024-53066, CVE-2024-53105, CVE-2024-53233, CVE-2024-56703, CVE-2024-56725, CVE-2024-50172, CVE-2024-53160, CVE-2024-50131, CVE-2024-53196, CVE-2024-56645, CVE-2024-50304, CVE-2024-56746, CVE-2024-53232, CVE-2024-49906, CVE-2024-53129, CVE-2024-53135, CVE-2024-56545, CVE-2024-56600, CVE-2024-56642, CVE-2024-43098, CVE-2024-50291, CVE-2024-53219, CVE-2024-53197, CVE-2024-53084, CVE-2024-53155, CVE-2024-53094, CVE-2024-56581, CVE-2024-56531, CVE-2024-50300, CVE-2024-50232, CVE-2024-56590, CVE-2024-48881, CVE-2024-56708, CVE-2024-56632, CVE-2024-53051, CVE-2024-53177, CVE-2024-56698, CVE-2024-56707, CVE-2024-56693, CVE-2024-53213, CVE-2024-53121, CVE-2024-56681, CVE-2024-56607, CVE-2024-53120, CVE-2024-56615, CVE-2024-53109, CVE-2024-50209, CVE-2024-56592, CVE-2024-50103, CVE-2024-56722, CVE-2024-53046, CVE-2024-50155, CVE-2024-56765, CVE-2024-56572, CVE-2024-56611, CVE-2024-56679, CVE-2024-50259, CVE-2024-50111, CVE-2024-53217, CVE-2024-53113, CVE-2024-53101, CVE-2024-50208, CVE-2024-53115, CVE-2024-56691, CVE-2024-50137, CVE-2024-53194, CVE-2024-41935, CVE-2024-56584, CVE-2022-49034, CVE-2024-53072, CVE-2024-41932, CVE-2024-56729, CVE-2024-53095, CVE-2024-56755, CVE-2024-50268, CVE-2024-56631, CVE-2024-48875, CVE-2025-21756, CVE-2024-50127, CVE-2024-50136, CVE-2024-56562, CVE-2024-56683,CVE-2024-50250, CVE-2024-53184, CVE-2024-50205, CVE-2024-56543, CVE-2024-56787, CVE-2024-50116, CVE-2024-53096, CVE-2024-53169, CVE-2024-50154, CVE-2024-53230, CVE-2024-50247, CVE-2024-56570, CVE-2024-56583, CVE-2025-21702, CVE-2024-50126, CVE-2024-50151, CVE-2024-53208, CVE-2024-50153, CVE-2024-56619, CVE-2024-56532, CVE-2024-56776, CVE-2024-53093, CVE-2024-53139, CVE-2024-50263, CVE-2024-41014, CVE-2024-53126, CVE-2024-53052, CVE-2024-56636, CVE-2024-50299, CVE-2024-56601, CVE-2024-56569, CVE-2024-53168, CVE-2024-53112, CVE-2024-56576, CVE-2024-50230, CVE-2024-56630, CVE-2024-50010, CVE-2024-56599, CVE-2024-50156, CVE-2024-50286, CVE-2024-53174, CVE-2024-50216, CVE-2024-56744, CVE-2024-50265, CVE-2024-50255, CVE-2024-56567, CVE-2024-50118, CVE-2024-50276, CVE-2024-53099, CVE-2024-50234, CVE-2024-56745, CVE-2024-53114, CVE-2024-50273, CVE-2024-49899, CVE-2024-56608, CVE-2024-56625, CVE-2024-56577, CVE-2024-56596, CVE-2024-56634, CVE-2024-56777, CVE-2024-47141, CVE-2024-53180, CVE-2024-56701, CVE-2024-53158, CVE-2024-56566, CVE-2024-56616, CVE-2024-53117, CVE-2024-53181, CVE-2024-50115, CVE-2024-56772, CVE-2024-53163, CVE-2024-50140, CVE-2024-56633, CVE-2024-50262, CVE-2024-56677, CVE-2024-53201, CVE-2024-57850, CVE-2024-50271, CVE-2024-50279, CVE-2024-50226, CVE-2024-53191, CVE-2024-45828, CVE-2024-53106, CVE-2024-50275, CVE-2024-50245, CVE-2024-56783, CVE-2024-50261, CVE-2024-50283, CVE-2024-53062, CVE-2024-50240, CVE-2024-53183, CVE-2024-53222, CVE-2024-53119, CVE-2024-53138, CVE-2024-52332, CVE-2024-50167, CVE-2024-53042, CVE-2024-50169, CVE-2024-50162, CVE-2024-53087, CVE-2024-50298, CVE-2024-56610, CVE-2024-53060, CVE-2024-56578, CVE-2024-50272, CVE-2024-56604, CVE-2024-50287, CVE-2024-47809, CVE-2024-56603, CVE-2024-50237, CVE-2024-56647, CVE-2024-56747, CVE-2024-50221, CVE-2024-53215, CVE-2024-56550, CVE-2024-56748, CVE-2024-56557, CVE-2024-48873, CVE-2024-49569, CVE-2024-50206, CVE-2024-56781, CVE-2024-56638, CVE-2024-50218, CVE-2024-53055, CVE-2024-57838, CVE-2024-50267, CVE-2024-56575, CVE-2024-53202,CVE-2024-53154, CVE-2024-53176, CVE-2024-56779, CVE-2024-50210, CVE-2024-56589, CVE-2024-50130, CVE-2024-53190, CVE-2024-53082, CVE-2024-56549, CVE-2024-56594, CVE-2024-50294, CVE-2024-56754, CVE-2024-53142, CVE-2024-50295, CVE-2024-57872, CVE-2024-53081, CVE-2024-56629, CVE-2024-53209, CVE-2024-56558, CVE-2024-50164, CVE-2024-53162, CVE-2024-56539, CVE-2024-56721, CVE-2024-50121, CVE-2024-56651, CVE-2024-56609, CVE-2024-50207, CVE-2024-50220, CVE-2024-53228, CVE-2024-53171, CVE-2024-53110, CVE-2024-53146, CVE-2024-53148, CVE-2024-50284, CVE-2024-56739, CVE-2024-48876, CVE-2024-50222, CVE-2024-53079, CVE-2024-53048, CVE-2024-50135, CVE-2024-56726, CVE-2024-50110, CVE-2024-53145, CVE-2024-53198, CVE-2024-50249, CVE-2024-44955, CVE-2024-56573, CVE-2024-53047, CVE-2024-50133, CVE-2024-53091, CVE-2024-53134, CVE-2024-50128, CVE-2024-56648, CVE-2024-53111, CVE-2024-50258, CVE-2024-56587, CVE-2024-56644, CVE-2024-53229, CVE-2024-56727, CVE-2024-50159, CVE-2024-57874, CVE-2024-50166, CVE-2024-53210, CVE-2024-53172, CVE-2024-53107, CVE-2024-56620, CVE-2024-53076, CVE-2024-50236, CVE-2024-56627, CVE-2024-56771, CVE-2024-56724, CVE-2024-50235, CVE-2024-50270, CVE-2024-50160, CVE-2024-50067, CVE-2024-56641, CVE-2024-50297, CVE-2024-53178, CVE-2024-53231, CVE-2024-56692, CVE-2024-53128, CVE-2024-56635, CVE-2024-42122, CVE-2024-50223, CVE-2024-56586, CVE-2024-50242, CVE-2024-50256, CVE-2024-56756, CVE-2024-56782, CVE-2024-50145, CVE-2024-56704, CVE-2024-50146, CVE-2024-53058, CVE-2024-56588, CVE-2024-53187, CVE-2024-56548, CVE-2024-56579, CVE-2024-50248, CVE-2024-50125, CVE-2024-57876, CVE-2024-56687, CVE-2024-53061, CVE-2024-53118, CVE-2024-56622, CVE-2024-53083, CVE-2024-53220, CVE-2024-56637) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS linux-image-6.8.0-1010-gkeop 6.8.0-1010.12 linux-image-6.8.0-1023-gke 6.8.0-1023.27 linux-image-6.8.0-1028-gcp 6.8.0-1028.30 linux-image-6.8.0-1028-gcp-64k 6.8.0-1028.30 linux-image-gcp-64k-lts-24.04 6.8.0-1028.30 linux-image-gcp-lts-24.04 6.8.0-1028.30 linux-image-gke 6.8.0-1023.27 linux-image-gkeop 6.8.0-1010.12 linux-image-gkeop-6.8 6.8.0-1010.12 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7450-1 CVE-2022-49034, CVE-2024-41014, CVE-2024-41932, CVE-2024-41935, CVE-2024-42122, CVE-2024-43098, CVE-2024-44955, CVE-2024-45828, CVE-2024-47141, CVE-2024-47143, CVE-2024-47794, CVE-2024-47809, CVE-2024-48873, CVE-2024-48875, CVE-2024-48876, CVE-2024-48881, CVE-2024-49569, CVE-2024-49899, CVE-2024-49906, CVE-2024-50010, CVE-2024-50051, CVE-2024-50067, CVE-2024-50103, CVE-2024-50104, CVE-2024-50105, CVE-2024-50107, CVE-2024-50108, CVE-2024-50110, CVE-2024-50111, CVE-2024-50112, CVE-2024-50115, CVE-2024-50116, CVE-2024-50118, CVE-2024-50120, CVE-2024-50121, CVE-2024-50124, CVE-2024-50125, CVE-2024-50126, CVE-2024-50127, CVE-2024-50128, CVE-2024-50130, CVE-2024-50131, CVE-2024-50133, CVE-2024-50135, CVE-2024-50136, CVE-2024-50137, CVE-2024-50138, CVE-2024-50139, CVE-2024-50140, CVE-2024-50141, CVE-2024-50142, CVE-2024-50143, CVE-2024-50145, CVE-2024-50146, CVE-2024-50147, CVE-2024-50150, CVE-2024-50151, CVE-2024-50152, CVE-2024-50153, CVE-2024-50154, CVE-2024-50155, CVE-2024-50156, CVE-2024-50158, CVE-2024-50159, CVE-2024-50160, CVE-2024-50162, CVE-2024-50163, CVE-2024-50164, CVE-2024-50166, CVE-2024-50167, CVE-2024-50169, CVE-2024-50170, CVE-2024-50172, CVE-2024-50203,CVE-2024-50205, CVE-2024-50206, CVE-2024-50207, CVE-2024-50208, CVE-2024-50209, CVE-2024-50210, CVE-2024-50211, CVE-2024-50215, CVE-2024-50216, CVE-2024-50218, CVE-2024-50220, CVE-2024-50221, CVE-2024-50222, CVE-2024-50223, CVE-2024-50224, CVE-2024-50225, CVE-2024-50226, CVE-2024-50230, CVE-2024-50231, CVE-2024-50232, CVE-2024-50234, CVE-2024-50235, CVE-2024-50236, CVE-2024-50237, CVE-2024-50238, CVE-2024-50239, CVE-2024-50240, CVE-2024-50242, CVE-2024-50243, CVE-2024-50244, CVE-2024-50245, CVE-2024-50246, CVE-2024-50247, CVE-2024-50248, CVE-2024-50249, CVE-2024-50250, CVE-2024-50251, CVE-2024-50252, CVE-2024-50255, CVE-2024-50256, CVE-2024-50257, CVE-2024-50258, CVE-2024-50259, CVE-2024-50261, CVE-2024-50262, CVE-2024-50263, CVE-2024-50265, CVE-2024-50267, CVE-2024-50268, CVE-2024-50269, CVE-2024-50270, CVE-2024-50271, CVE-2024-50272, CVE-2024-50273, CVE-2024-50275, CVE-2024-50276, CVE-2024-50278, CVE-2024-50279, CVE-2024-50280, CVE-2024-50282, CVE-2024-50283, CVE-2024-50284, CVE-2024-50285, CVE-2024-50286, CVE-2024-50287, CVE-2024-50288, CVE-2024-50289, CVE-2024-50290, CVE-2024-50291, CVE-2024-50292, CVE-2024-50294, CVE-2024-50295, CVE-2024-50296, CVE-2024-50297, CVE-2024-50298, CVE-2024-50299, CVE-2024-50300, CVE-2024-50301, CVE-2024-50303, CVE-2024-50304, CVE-2024-52332, CVE-2024-53042, CVE-2024-53043, CVE-2024-53044, CVE-2024-53045, CVE-2024-53046, CVE-2024-53047, CVE-2024-53048, CVE-2024-53050, CVE-2024-53051, CVE-2024-53052, CVE-2024-53053, CVE-2024-53055, CVE-2024-53058, CVE-2024-53059, CVE-2024-53060, CVE-2024-53061, CVE-2024-53062, CVE-2024-53066, CVE-2024-53067, CVE-2024-53068, CVE-2024-53072, CVE-2024-53076, CVE-2024-53079, CVE-2024-53081, CVE-2024-53082, CVE-2024-53083, CVE-2024-53084, CVE-2024-53085, CVE-2024-53086, CVE-2024-53087, CVE-2024-53088, CVE-2024-53089, CVE-2024-53090, CVE-2024-53091, CVE-2024-53093, CVE-2024-53094, CVE-2024-53095, CVE-2024-53096, CVE-2024-53099, CVE-2024-53100, CVE-2024-53101, CVE-2024-53105, CVE-2024-53106,CVE-2024-53107, CVE-2024-53108, CVE-2024-53109, CVE-2024-53110, CVE-2024-53111, CVE-2024-53112, CVE-2024-53113, CVE-2024-53114, CVE-2024-53115, CVE-2024-53117, CVE-2024-53118, CVE-2024-53119, CVE-2024-53120, CVE-2024-53121, CVE-2024-53122, CVE-2024-53123, CVE-2024-53126, CVE-2024-53127, CVE-2024-53128, CVE-2024-53129, CVE-2024-53130, CVE-2024-53131, CVE-2024-53133, CVE-2024-53134, CVE-2024-53135, CVE-2024-53138, CVE-2024-53139, CVE-2024-53142, CVE-2024-53145, CVE-2024-53146, CVE-2024-53147, CVE-2024-53148, CVE-2024-53150, CVE-2024-53151, CVE-2024-53154, CVE-2024-53155, CVE-2024-53157, CVE-2024-53158, CVE-2024-53160, CVE-2024-53161, CVE-2024-53162, CVE-2024-53163, CVE-2024-53166, CVE-2024-53168, CVE-2024-53169, CVE-2024-53171, CVE-2024-53172, CVE-2024-53173, CVE-2024-53174, CVE-2024-53175, CVE-2024-53176, CVE-2024-53177, CVE-2024-53178, CVE-2024-53180, CVE-2024-53181, CVE-2024-53183, CVE-2024-53184, CVE-2024-53185, CVE-2024-53187, CVE-2024-53188, CVE-2024-53190, CVE-2024-53191, CVE-2024-53194, CVE-2024-53195, CVE-2024-53196, CVE-2024-53197, CVE-2024-53198, CVE-2024-53200, CVE-2024-53201, CVE-2024-53202, CVE-2024-53203, CVE-2024-53208, CVE-2024-53209, CVE-2024-53210, CVE-2024-53213, CVE-2024-53214, CVE-2024-53215, CVE-2024-53217, CVE-2024-53218, CVE-2024-53219, CVE-2024-53220, CVE-2024-53221, CVE-2024-53222, CVE-2024-53223, CVE-2024-53224, CVE-2024-53226, CVE-2024-53227, CVE-2024-53228, CVE-2024-53229, CVE-2024-53230, CVE-2024-53231, CVE-2024-53232, CVE-2024-53233, CVE-2024-53234, CVE-2024-53236, CVE-2024-53237, CVE-2024-53239, CVE-2024-53680, CVE-2024-56531, CVE-2024-56532, CVE-2024-56533, CVE-2024-56538, CVE-2024-56539, CVE-2024-56540, CVE-2024-56543, CVE-2024-56545, CVE-2024-56546, CVE-2024-56548, CVE-2024-56549, CVE-2024-56550, CVE-2024-56551, CVE-2024-56557, CVE-2024-56558, CVE-2024-56561, CVE-2024-56562, CVE-2024-56565, CVE-2024-56566, CVE-2024-56567, CVE-2024-56568, CVE-2024-56569, CVE-2024-56570, CVE-2024-56572, CVE-2024-56573, CVE-2024-56574,CVE-2024-56575, CVE-2024-56576, CVE-2024-56577, CVE-2024-56578, CVE-2024-56579, CVE-2024-56580, CVE-2024-56581, CVE-2024-56583, CVE-2024-56584, CVE-2024-56586, CVE-2024-56587, CVE-2024-56588, CVE-2024-56589, CVE-2024-56590, CVE-2024-56592, CVE-2024-56593, CVE-2024-56594, CVE-2024-56596, CVE-2024-56597, CVE-2024-56599, CVE-2024-56600, CVE-2024-56601, CVE-2024-56602, CVE-2024-56603, CVE-2024-56604, CVE-2024-56605, CVE-2024-56606, CVE-2024-56607, CVE-2024-56608, CVE-2024-56609, CVE-2024-56610, CVE-2024-56611, CVE-2024-56613, CVE-2024-56615, CVE-2024-56616, CVE-2024-56619, CVE-2024-56620, CVE-2024-56621, CVE-2024-56622, CVE-2024-56623, CVE-2024-56625, CVE-2024-56626, CVE-2024-56627, CVE-2024-56629, CVE-2024-56630, CVE-2024-56631, CVE-2024-56632, CVE-2024-56633, CVE-2024-56634, CVE-2024-56635, CVE-2024-56636, CVE-2024-56637, CVE-2024-56638, CVE-2024-56640, CVE-2024-56641, CVE-2024-56642, CVE-2024-56643, CVE-2024-56644, CVE-2024-56645, CVE-2024-56647, CVE-2024-56648, CVE-2024-56649, CVE-2024-56650, CVE-2024-56651, CVE-2024-56677, CVE-2024-56678, CVE-2024-56679, CVE-2024-56681, CVE-2024-56683, CVE-2024-56685, CVE-2024-56687, CVE-2024-56688, CVE-2024-56689, CVE-2024-56690, CVE-2024-56691, CVE-2024-56692, CVE-2024-56693, CVE-2024-56694, CVE-2024-56698, CVE-2024-56700, CVE-2024-56701, CVE-2024-56703, CVE-2024-56704, CVE-2024-56705, CVE-2024-56707, CVE-2024-56708, CVE-2024-56720, CVE-2024-56721, CVE-2024-56722, CVE-2024-56723, CVE-2024-56724, CVE-2024-56725, CVE-2024-56726, CVE-2024-56727, CVE-2024-56728, CVE-2024-56729, CVE-2024-56739, CVE-2024-56742, CVE-2024-56744, CVE-2024-56745, CVE-2024-56746, CVE-2024-56747, CVE-2024-56748, CVE-2024-56751, CVE-2024-56752, CVE-2024-56754, CVE-2024-56755, CVE-2024-56756, CVE-2024-56765, CVE-2024-56771, CVE-2024-56772, CVE-2024-56773, CVE-2024-56774, CVE-2024-56775, CVE-2024-56776, CVE-2024-56777, CVE-2024-56778, CVE-2024-56779, CVE-2024-56780, CVE-2024-56781, CVE-2024-56782, CVE-2024-56783, CVE-2024-56785, CVE-2024-56786,CVE-2024-56787, CVE-2024-57838, CVE-2024-57843, CVE-2024-57849, CVE-2024-57850, CVE-2024-57872, CVE-2024-57874, CVE-2024-57876, CVE-2025-21700, CVE-2025-21701, CVE-2025-21702, CVE-2025-21756, CVE-2025-21831, CVE-2025-21993 Package Information: https://launchpad.net/ubuntu/+source/linux-gcp/6.8.0-1028.30 https://launchpad.net/ubuntu/+source/linux-gke/6.8.0-1023.27 https://launchpad.net/ubuntu/+source/linux-gkeop/6.8.0-1010.12 . Important release for Ubuntu 24.04 LTS focusing on rectifying several kernel vulnerabilities to improve protection and system reliability.. Ubuntu kernel update, security issues, latest patch, Linux features. . Severity: Critical. LinuxSecurity.com Team
This kernel update is based on upstream 5.15.25 and fixes at least the following security issues: A vulnerability in the Linux kernel since version 5.8 due to uninitialized variables. It enables anybody to write arbitrary data to arbitrary files, . MGASA-2022-0092 - Updated kernel packages fix security vulnerabilities Publication date: 07 Mar 2022 URL: https://advisories.mageia.org/MGASA-2022-0092.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-0847, CVE-2022-25258, CVE-2022-25375 This kernel update is based on upstream 5.15.25 and fixes at least the following security issues: A vulnerability in the Linux kernel since version 5.8 due to uninitialized variables. It enables anybody to write arbitrary data to arbitrary files, even if the file is O_RDONLY, immutable or on a MS_RDONLY filesystem. It can be used to inject code into arbitrary processes (CVE-2022-0847). An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur (CVE-2022-25258). An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory (CVE-2022-25375). For other upstream fixes, see the referenced changelogs. References: - https://bugs.mageia.org/show_bug.cgi?id=30131 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.24 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.25 - https://www.cve.org/CVERecord?id=CVE-2022-0847 - https://www.cve.org/CVERecord?id=CVE-2022-25258 - https://www.cve.org/CVERecord?id=CVE-2022-25375 SRPMS: - 8/core/kernel-5.15.25-1.mga8 - 8/core/kmod-virtualbox-6.1.32-1.7.mga8 - 8/core/kmod-xtables-addons-3.18-1.57.mga8 . The recent kernel upgrade for Mageiaresolves several security vulnerabilities, including potential arbitrary code execution and issues related to memory corruption.. Mageia Kernel Update, Security Patch, Flaw Fix. . Severity: Important. LinuxSecurity.com Team
Chromium-browser 81.0.4044.92 fixes security issues: Multiple flaws were found in the way Chromium 80.0.3987.149 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code, . MGASA-2020-0174 - Updated chromium-browser-stable packages fix security vulnerabilities Publication date: 16 Apr 2020 URL: https://advisories.mageia.org/MGASA-2020-0174.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-6423, CVE-2020-6430, CVE-2020-6431, CVE-2020-6432, CVE-2020-6433, CVE-2020-6434, CVE-2020-6435, CVE-2020-6436, CVE-2020-6437, CVE-2020-6438, CVE-2020-6439, CVE-2020-6440, CVE-2020-6441, CVE-2020-6442, CVE-2020-6443, CVE-2020-6444, CVE-2020-6445, CVE-2020-6446, CVE-2020-6447, CVE-2020-6448, CVE-2020-6450, CVE-2020-6451, CVE-2020-6452, CVE-2020-6454, CVE-2020-6455, CVE-2020-6456 Chromium-browser 81.0.4044.92 fixes security issues: Multiple flaws were found in the way Chromium 80.0.3987.149 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose sensitive information. (CVE-2020-6423, CVE-2020-6430, CVE-2020-6431, CVE-2020-6432, CVE-2020-6433, CVE-2020-6434, CVE-2020-6435, CVE-2020-6436, CVE-2020-6437, CVE-2020-6438, CVE-2020-6439, CVE-2020-6440, CVE-2020-6441, CVE-2020-6442, CVE-2020-6443, CVE-2020-6444, CVE-2020-6445, CVE-2020-6446, CVE-2020-6447, CVE-2020-6448, CVE-2020-6450, CVE-2020-6451, CVE-2020-6452, CVE-2020-6454, CVE-2020-6455, CVE-2020-6456) References: - https://bugs.mageia.org/show_bug.cgi?id=26470 - https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop_31.html - https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html - https://www.cve.org/CVERecord?id=CVE-2020-6423 -https://www.cve.org/CVERecord?id=CVE-2020-6430 - https://www.cve.org/CVERecord?id=CVE-2020-6431 - https://www.cve.org/CVERecord?id=CVE-2020-6432 - https://www.cve.org/CVERecord?id=CVE-2020-6433 - https://www.cve.org/CVERecord?id=CVE-2020-6434 - https://www.cve.org/CVERecord?id=CVE-2020-6435 - https://www.cve.org/CVERecord?id=CVE-2020-6436 - https://www.cve.org/CVERecord?id=CVE-2020-6437 - https://www.cve.org/CVERecord?id=CVE-2020-6438 - https://www.cve.org/CVERecord?id=CVE-2020-6439 - https://www.cve.org/CVERecord?id=CVE-2020-6440 - https://www.cve.org/CVERecord?id=CVE-2020-6441 - https://www.cve.org/CVERecord?id=CVE-2020-6442 - https://www.cve.org/CVERecord?id=CVE-2020-6443 - https://www.cve.org/CVERecord?id=CVE-2020-6444 - https://www.cve.org/CVERecord?id=CVE-2020-6445 - https://www.cve.org/CVERecord?id=CVE-2020-6446 - https://www.cve.org/CVERecord?id=CVE-2020-6447 - https://www.cve.org/CVERecord?id=CVE-2020-6448 - https://www.cve.org/CVERecord?id=CVE-2020-6450 - https://www.cve.org/CVERecord?id=CVE-2020-6451 - https://www.cve.org/CVERecord?id=CVE-2020-6452 - https://www.cve.org/CVERecord?id=CVE-2020-6454 - https://www.cve.org/CVERecord?id=CVE-2020-6455 - https://www.cve.org/CVERecord?id=CVE-2020-6456 SRPMS: - 7/core/chromium-browser-stable-81.0.4044.92-1.mga7 . The Firefox browser version 76.0.1 resolves several vulnerabilities that could lead to unauthorized code execution and information leakage.. Chromium-Browser, Security Advisory, Mageia Flaw Fix, Software Update. . Severity: Critical. LinuxSecurity.com Team
Rebase to latest minor version fixes CVE-2019-8320 CVE-2019-8321 CVE-2019-8322 CVE-2019-8323 CVE-2019-8324 CVE-2019-8325. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-a155364f3c 2019-05-03 03:40:56.513715 --------------------------------------------------------------------------------Name : ruby Product : Fedora 29 Version : 2.5.5 Release : 101.fc29 URL : https://www.ruby-lang.org/ Summary : An interpreter of object-oriented scripting language Description : Ruby is the interpreted scripting language for quick and easy object-oriented programming. It has many features to process text files and to do system management tasks (as in Perl). It is simple, straight-forward, and extensible. --------------------------------------------------------------------------------Update Information: Rebase to latest minor version fixes CVE-2019-8320 CVE-2019-8321 CVE-2019-8322 CVE-2019-8323 CVE-2019-8324 CVE-2019-8325 --------------------------------------------------------------------------------ChangeLog: * Thu Apr 4 2019 Pavel Valena - 2.5.5-101 - Update to Ruby 2.5.5. * Fri Jan 11 2019 Jun Aruga - 2.5.3-100 - Fix Tokyo TZ tests. - Refresh expired certificates to fix FTBFS. * Fri Oct 19 2018 Jun Aruga - 2.5.3-99 - Update to Ruby 2.5.3. --------------------------------------------------------------------------------References: [ 1 ] Bug #1692530 - CVE-2019-8320 CVE-2019-8321 CVE-2019-8322 CVE-2019-8323 CVE-2019-8324 CVE-2019-8325 rubygems: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1692530 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-a155364f3c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packagesare signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
* Fix for CVE-2018-19840 CVE-2018-19841. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-1315f2dc3a 2019-04-13 00:02:00.009298 --------------------------------------------------------------------------------Name : wavpack Product : Fedora 30 Version : 5.1.0 Release : 12.fc30 URL : https://www.wavpack.com/ Summary : A completely open audiocodec Description : WavPack is a completely open audio compression format providing lossless, high-quality lossy, and a unique hybrid compression mode. Although the technology is loosely based on previous versions of WavPack, the new version 4 format has been designed from the ground up to offer unparalleled performance and functionality. --------------------------------------------------------------------------------Update Information: * Fix for CVE-2018-19840 CVE-2018-19841 --------------------------------------------------------------------------------References: [ 1 ] Bug #1661450 - CVE-2018-19840 CVE-2018-19841 wavpack: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1661450 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-1315f2dc3a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Add few patches from Kurt Roeckx. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-4f9f4d26f0 2018-10-05 17:07:23.707294 --------------------------------------------------------------------------------Name : libmad Product : Fedora 28 Version : 0.15.1b Release : 26.fc28 URL : http://www.underbit.com/products/mad/ Summary : MPEG audio decoder library Description : MAD is a high-quality MPEG audio decoder. It currently supports MPEG-1 and the MPEG-2 extension to Lower Sampling Frequencies, as well as the so-called MPEG 2.5 format. All three audio layers (Layer I, Layer II, and Layer III a.k.a. MP3) are fully implemented. --------------------------------------------------------------------------------Update Information: Add few patches from Kurt Roeckx --------------------------------------------------------------------------------ChangeLog: * Mon Sep 24 2018 Nicolas Chauvet - 0.15.1b-26 - Add patches from debian * Fri Jul 13 2018 Fedora Release Engineering - 0.15.1b-25 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1477499 - CVE-2017-11552 CVE-2018-7263 libmad: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1477499 [ 2 ] Bug #1447357 - CVE-2017-8372 CVE-2017-8373 CVE-2017-8374 libmad: Multiple vulnerabilities [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1447357 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-4f9f4d26f0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
This updates LibOFX to fix assorted CVEs.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-1b3a73b45f 2018-04-11 16:30:59.888260 --------------------------------------------------------------------------------Name : libofx Product : Fedora 27 Version : 0.9.10 Release : 5.fc27 URL : https://github.com/libofx/libofx Summary : A library for supporting Open Financial Exchange (OFX) Description : This is the LibOFX library. It is a API designed to allow applications to very easily support OFX command responses, usually provided by financial institutions. See for details and specification. --------------------------------------------------------------------------------Update Information: This updates LibOFX to fix assorted CVEs. --------------------------------------------------------------------------------References: [ 1 ] Bug #1492203 - CVE-2017-14731 CVE-2017-2816 CVE-2017-2920 libofx: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1492203 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libofx' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.