Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following vulnerabilities have been discovered systemd: CVE-2026-4105 The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged. Debian LTS Advisory DLA-4533-1
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7655-1 July 18, 2025 linux-intel-iotg-5.15 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-intel-iotg-5.15: Linux kernel for Intel IoT platforms Details: Michael Randrianantenaina discovered that the Bluetooth driver in the Linux Kernel contained an improper access control vulnerability. A nearby attacker could use this to connect a rougue device and possibly execute arbitrary code. (CVE-2024-8805) It was discovered that the CIFS network file system implementation in the Linux kernel did not properly verify the target namespace when handling upcalls. An attacker could use this to expose sensitive information. (CVE-2025-2312) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - PA-RISC architecture; - PowerPC architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - ACPI drivers; - Serial ATA and Parallel ATA drivers; - Bluetooth drivers; - Bus devices; - Clock framework and drivers; - CPU frequency scaling framework; - Buffer Sharing and Synchronization framework; - DMA engine subsystem; - ARM SCMI message protocol; - GPU drivers; - HID subsystem; - HSI subsystem; - I2C subsystem; - I3C subsystem; - IIO subsystem; - InfiniBand drivers; - IOMMU subsystem; - IRQ chip drivers; - MCB driver; - Multiple devices driver; - Media drivers; - MemoryStick subsystem; - Multifunction device drivers; - PCI Endpoint Test driver; - MTD block device drivers; - Network drivers; - Mellanox network drivers; - NTB driver; -Device tree and open firmware driver; - PCI subsystem; - TI SCI PM domains driver; - PWM drivers; - Voltage and Current Regulator drivers; - Remote Processor subsystem; - S/390 drivers; - SCSI subsystem; - QCOM SoC drivers; - Samsung SoC drivers; - TCM subsystem; - Thermal drivers; - UFS subsystem; - Cadence USB3 driver; - ChipIdea USB driver; - USB Device Class drivers; - DesignWare USB3 driver; - USB Gadget drivers; - USB Type-C support driver; - USB Type-C Connector System Software Interface driver; - Backlight driver; - Framebuffer layer; - Xen hypervisor drivers; - BTRFS file system; - Ext4 file system; - F2FS file system; - File systems infrastructure; - JFS file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NTFS3 file system; - Proc file system; - SMB network file system; - Kernel stack handling interfaces; - Bluetooth subsystem; - IPv6 networking; - Network traffic control; - SCTP protocol; - RDMA verbs API; - SoC audio core drivers; - BPF subsystem; - Kernel command line parsing driver; - Tracing infrastructure; - Watch queue notification mechanism; - Memory management; - 802.1Q VLAN protocol; - Asynchronous Transfer Mode (ATM) subsystem; - Networking core; - IPv4 networking; - MAC80211 subsystem; - Management Component Transport Protocol (MCTP); - Multipath TCP; - Netfilter; - Open vSwitch; - Phonet protocol; - SMC sockets; - Sun RPC protocol; - TIPC protocol; - TLS protocol; - SoC Audio for Freescale CPUs drivers; - Virtio sound driver; - CPU Power monitoring subsystem; (CVE-2025-37989, CVE-2025-22071, CVE-2025-37808, CVE-2025-37983, CVE-2025-38001, CVE-2024-46816, CVE-2024-50125, CVE-2025-38575, CVE-2025-37766, CVE-2022-49168, CVE-2025-22025, CVE-2025-22035, CVE-2025-37923, CVE-2024-49989, CVE-2025-23148, CVE-2024-53051, CVE-2025-39728, CVE-2025-21956, CVE-2025-37741, CVE-2025-37970, CVE-2025-37798, CVE-2025-23157, CVE-2025-38177,CVE-2022-49535, CVE-2025-22027, CVE-2025-37756, CVE-2025-38023, CVE-2025-22066, CVE-2025-37780, CVE-2025-37995, CVE-2025-37739, CVE-2025-37932, CVE-2025-37982, CVE-2025-37812, CVE-2025-23156, CVE-2025-38005, CVE-2025-21839, CVE-2025-37892, CVE-2025-22073, CVE-2024-35866, CVE-2023-52757, CVE-2025-37785, CVE-2025-23150, CVE-2024-58093, CVE-2025-21992, CVE-2025-37905, CVE-2025-37836, CVE-2025-21964, CVE-2025-23140, CVE-2025-22056, CVE-2025-37915, CVE-2025-22054, CVE-2025-37859, CVE-2025-22050, CVE-2025-37811, CVE-2024-38540, CVE-2025-37794, CVE-2025-37839, CVE-2022-21546, CVE-2025-22089, CVE-2025-22079, CVE-2024-56751, CVE-2025-37789, CVE-2025-37790, CVE-2025-23159, CVE-2025-22097, CVE-2025-37883, CVE-2025-37829, CVE-2023-52572, CVE-2025-21962, CVE-2025-37823, CVE-2024-53203, CVE-2025-38000, CVE-2025-38152, CVE-2025-37771, CVE-2025-39735, CVE-2025-37992, CVE-2025-37937, CVE-2025-22081, CVE-2024-35943, CVE-2025-37803, CVE-2025-37940, CVE-2025-22005, CVE-2025-22014, CVE-2025-37742, CVE-2022-49063, CVE-2025-37890, CVE-2025-37969, CVE-2025-37788, CVE-2022-48893, CVE-2025-23161, CVE-2024-46753, CVE-2025-21853, CVE-2025-37817, CVE-2022-49636, CVE-2025-37985, CVE-2025-37787, CVE-2025-37810, CVE-2025-22008, CVE-2025-37824, CVE-2025-37765, CVE-2025-23145, CVE-2025-37830, CVE-2025-37913, CVE-2025-37881, CVE-2025-37967, CVE-2025-37912, CVE-2024-42230, CVE-2024-46821, CVE-2024-56608, CVE-2025-37805, CVE-2025-37838, CVE-2025-38637, CVE-2025-38024, CVE-2025-23138, CVE-2025-37949, CVE-2024-46751, CVE-2025-22007, CVE-2025-37844, CVE-2024-46812, CVE-2025-37889, CVE-2023-53034, CVE-2025-37927, CVE-2025-37998, CVE-2024-42322, CVE-2024-50280, CVE-2025-22086, CVE-2025-21963, CVE-2024-50272, CVE-2024-54458, CVE-2024-36908, CVE-2025-22062, CVE-2025-37994, CVE-2025-22044, CVE-2025-22018, CVE-2025-22010, CVE-2024-49960, CVE-2025-37768, CVE-2025-37911, CVE-2025-22060, CVE-2025-37781, CVE-2024-26686, CVE-2024-50047, CVE-2025-37850, CVE-2024-46742, CVE-2025-37797, CVE-2025-37767, CVE-2025-23136, CVE-2025-23158, CVE-2025-37792, CVE-2025-37749,CVE-2025-38009, CVE-2024-35867, CVE-2025-37885, CVE-2025-37914, CVE-2024-46774, CVE-2025-38094, CVE-2025-23163, CVE-2024-38541, CVE-2025-37819, CVE-2025-22020, CVE-2025-37857, CVE-2025-21975, CVE-2024-53144, CVE-2025-21991, CVE-2025-37867, CVE-2025-37930, CVE-2025-37796, CVE-2025-21968, CVE-2025-22075, CVE-2025-37997, CVE-2025-22063, CVE-2025-37840, CVE-2025-37909, CVE-2025-22045, CVE-2024-46787, CVE-2025-37738, CVE-2025-22055, CVE-2025-37862, CVE-2024-56664, CVE-2025-21959, CVE-2025-22004, CVE-2024-50258, CVE-2025-23146, CVE-2025-22021, CVE-2025-21994, CVE-2025-21957, CVE-2025-37758, CVE-2024-26739, CVE-2025-37858, CVE-2025-37757, CVE-2025-23142, CVE-2025-23151, CVE-2025-21996, CVE-2025-21970, CVE-2025-37770, CVE-2024-35790, CVE-2025-37773, CVE-2025-37990, CVE-2025-21941, CVE-2025-21999, CVE-2024-53128, CVE-2025-37851, CVE-2025-23147, CVE-2025-37964, CVE-2025-37841, CVE-2025-37875, CVE-2024-53168, CVE-2022-49728, CVE-2025-23144, CVE-2025-37991, CVE-2024-56551, CVE-2025-21981, CVE-2024-27402, CVE-2025-37740, CVE-2024-36945) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.15.0-1083-intel-iotg 5.15.0-1083.89~20.04.1 Available with Ubuntu Pro linux-image-intel 5.15.0.1083.89~20.04.1 Available with Ubuntu Pro linux-image-intel-iotg 5.15.0.1083.89~20.04.1 Available with Ubuntu Pro linux-image-intel-iotg-5.15 5.15.0.1083.89~20.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic,linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7655-1 CVE-2022-21546, CVE-2022-48893, CVE-2022-49063, CVE-2022-49168, CVE-2022-49535, CVE-2022-49636, CVE-2022-49728, CVE-2023-52572, CVE-2023-52757, CVE-2023-53034, CVE-2024-26686, CVE-2024-26739, CVE-2024-27402, CVE-2024-35790, CVE-2024-35866, CVE-2024-35867, CVE-2024-35943, CVE-2024-36908, CVE-2024-36945, CVE-2024-38540, CVE-2024-38541, CVE-2024-42230, CVE-2024-42322, CVE-2024-46742, CVE-2024-46751, CVE-2024-46753, CVE-2024-46774, CVE-2024-46787, CVE-2024-46812, CVE-2024-46816, CVE-2024-46821, CVE-2024-49960, CVE-2024-49989, CVE-2024-50047, CVE-2024-50125, CVE-2024-50258, CVE-2024-50272, CVE-2024-50280, CVE-2024-53051, CVE-2024-53128, CVE-2024-53144, CVE-2024-53168, CVE-2024-53203, CVE-2024-54458, CVE-2024-56551, CVE-2024-56608, CVE-2024-56664, CVE-2024-56751, CVE-2024-58093, CVE-2024-8805, CVE-2025-21839, CVE-2025-21853, CVE-2025-21941, CVE-2025-21956, CVE-2025-21957, CVE-2025-21959, CVE-2025-21962, CVE-2025-21963, CVE-2025-21964, CVE-2025-21968, CVE-2025-21970, CVE-2025-21975, CVE-2025-21981, CVE-2025-21991, CVE-2025-21992, CVE-2025-21994, CVE-2025-21996, CVE-2025-21999, CVE-2025-22004, CVE-2025-22005, CVE-2025-22007, CVE-2025-22008, CVE-2025-22010, CVE-2025-22014, CVE-2025-22018, CVE-2025-22020, CVE-2025-22021, CVE-2025-22025, CVE-2025-22027, CVE-2025-22035, CVE-2025-22044, CVE-2025-22045, CVE-2025-22050, CVE-2025-22054, CVE-2025-22055, CVE-2025-22056, CVE-2025-22060, CVE-2025-22062, CVE-2025-22063, CVE-2025-22066, CVE-2025-22071, CVE-2025-22073, CVE-2025-22075, CVE-2025-22079, CVE-2025-22081, CVE-2025-22086, CVE-2025-22089, CVE-2025-22097, CVE-2025-2312, CVE-2025-23136, CVE-2025-23138, CVE-2025-23140, CVE-2025-23142, CVE-2025-23144, CVE-2025-23145, CVE-2025-23146, CVE-2025-23147, CVE-2025-23148, CVE-2025-23150, CVE-2025-23151, CVE-2025-23156, CVE-2025-23157, CVE-2025-23158, CVE-2025-23159, CVE-2025-23161, CVE-2025-23163, CVE-2025-37738, CVE-2025-37739, CVE-2025-37740, CVE-2025-37741, CVE-2025-37742, CVE-2025-37749, CVE-2025-37756, CVE-2025-37757, CVE-2025-37758, CVE-2025-37765, CVE-2025-37766, CVE-2025-37767, CVE-2025-37768, CVE-2025-37770, CVE-2025-37771, CVE-2025-37773, CVE-2025-37780, CVE-2025-37781, CVE-2025-37785, CVE-2025-37787, CVE-2025-37788, CVE-2025-37789, CVE-2025-37790, CVE-2025-37792, CVE-2025-37794, CVE-2025-37796, CVE-2025-37797, CVE-2025-37798, CVE-2025-37803, CVE-2025-37805, CVE-2025-37808, CVE-2025-37810, CVE-2025-37811, CVE-2025-37812, CVE-2025-37817, CVE-2025-37819, CVE-2025-37823, CVE-2025-37824, CVE-2025-37829, CVE-2025-37830, CVE-2025-37836, CVE-2025-37838, CVE-2025-37839, CVE-2025-37840, CVE-2025-37841, CVE-2025-37844, CVE-2025-37850, CVE-2025-37851, CVE-2025-37857, CVE-2025-37858, CVE-2025-37859, CVE-2025-37862, CVE-2025-37867, CVE-2025-37875, CVE-2025-37881, CVE-2025-37883, CVE-2025-37885, CVE-2025-37889, CVE-2025-37890, CVE-2025-37892, CVE-2025-37905, CVE-2025-37909, CVE-2025-37911, CVE-2025-37912, CVE-2025-37913, CVE-2025-37914, CVE-2025-37915, CVE-2025-37923, CVE-2025-37927, CVE-2025-37930, CVE-2025-37932, CVE-2025-37937, CVE-2025-37940, CVE-2025-37949, CVE-2025-37964, CVE-2025-37967, CVE-2025-37969, CVE-2025-37970, CVE-2025-37982, CVE-2025-37983, CVE-2025-37985, CVE-2025-37989, CVE-2025-37990, CVE-2025-37991, CVE-2025-37992, CVE-2025-37994, CVE-2025-37995, CVE-2025-37997, CVE-2025-37998, CVE-2025-38000, CVE-2025-38001, CVE-2025-38005, CVE-2025-38009, CVE-2025-38023, CVE-2025-38024, CVE-2025-38094, CVE-2025-38152, CVE-2025-38177, CVE-2025-38575, CVE-2025-38637, CVE-2025-39728, CVE-2025-39735 . Various vulnerabilities in the Linux kernel of Ubuntu may result in unauthorized entrance or potential system breach.. Ubuntu Security, Linux Kernel, Privilege Escalation, Bluetooth Exploit. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7591-5 July 04, 2025 linux-intel-iotg vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-intel-iotg: Linux kernel for Intel IoT platforms Details: Michael Randrianantenaina discovered that the Bluetooth driver in the Linux Kernel contained an improper access control vulnerability. A nearby attacker could use this to connect a rougue device and possibly execute arbitrary code. (CVE-2024-8805) It was discovered that the CIFS network file system implementation in the Linux kernel did not properly verify the target namespace when handling upcalls. An attacker could use this to expose sensitive information. (CVE-2025-2312) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - PowerPC architecture; - x86 architecture; - ACPI drivers; - Clock framework and drivers; - GPU drivers; - HID subsystem; - InfiniBand drivers; - Media drivers; - MemoryStick subsystem; - Network drivers; - Mellanox network drivers; - NTB driver; - PCI subsystem; - Voltage and Current Regulator drivers; - Remote Processor subsystem; - SCSI subsystem; - QCOM SoC drivers; - Thermal drivers; - BTRFS file system; - Ext4 file system; - JFS file system; - Network file system (NFS) server daemon; - NTFS3 file system; - File systems infrastructure; - Proc file system; - SMB network file system; - IPv6 networking; - RDMA verbs API; - SoC audio core drivers; - Tracing infrastructure; -Watch queue notification mechanism; - 802.1Q VLAN protocol; - Asynchronous Transfer Mode (ATM) subsystem; - Bluetooth subsystem; - Networking core; - IPv4 networking; - Netfilter; - Network traffic control; - SMC sockets; - SoC Audio for Freescale CPUs drivers; (CVE-2025-23138, CVE-2025-21956, CVE-2025-21970, CVE-2025-22025, CVE-2024-46753, CVE-2025-21962, CVE-2025-37889, CVE-2025-21992, CVE-2025-39728, CVE-2025-22054, CVE-2025-21959, CVE-2024-53144, CVE-2022-49728, CVE-2024-58093, CVE-2025-38637, CVE-2025-21981, CVE-2025-21963, CVE-2025-21968, CVE-2025-22014, CVE-2024-46812, CVE-2025-22005, CVE-2025-21994, CVE-2025-22071, CVE-2025-22008, CVE-2022-49636, CVE-2025-22007, CVE-2023-53034, CVE-2025-22035, CVE-2025-22010, CVE-2025-22081, CVE-2025-22021, CVE-2024-46821, CVE-2025-21999, CVE-2025-38575, CVE-2025-22073, CVE-2025-22004, CVE-2024-42230, CVE-2025-21941, CVE-2024-56664, CVE-2025-22044, CVE-2025-39735, CVE-2025-22060, CVE-2025-22055, CVE-2025-21957, CVE-2025-21975, CVE-2025-22075, CVE-2025-22089, CVE-2025-37937, CVE-2025-38152, CVE-2025-22020, CVE-2025-22066, CVE-2025-22056, CVE-2025-22050, CVE-2025-21964, CVE-2025-21996, CVE-2025-22079, CVE-2025-23136, CVE-2025-22063, CVE-2024-36945, CVE-2025-22097, CVE-2025-37785, CVE-2025-21991, CVE-2025-22086, CVE-2025-22045, CVE-2025-22018) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1081-intel-iotg 5.15.0-1081.87 linux-image-intel-iotg 5.15.0.1081.81 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE,linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7591-5 https://ubuntu.com/security/notices/USN-7591-4 https://ubuntu.com/security/notices/USN-7591-3 https://ubuntu.com/security/notices/USN-7591-2 https://ubuntu.com/security/notices/USN-7591-1 CVE-2022-49636, CVE-2022-49728, CVE-2023-53034, CVE-2024-36945, CVE-2024-42230, CVE-2024-46753, CVE-2024-46812, CVE-2024-46821, CVE-2024-53144, CVE-2024-56664, CVE-2024-58093, CVE-2024-8805, CVE-2025-21941, CVE-2025-21956, CVE-2025-21957, CVE-2025-21959, CVE-2025-21962, CVE-2025-21963, CVE-2025-21964, CVE-2025-21968, CVE-2025-21970, CVE-2025-21975, CVE-2025-21981, CVE-2025-21991, CVE-2025-21992, CVE-2025-21994, CVE-2025-21996, CVE-2025-21999, CVE-2025-22004, CVE-2025-22005, CVE-2025-22007, CVE-2025-22008, CVE-2025-22010, CVE-2025-22014, CVE-2025-22018, CVE-2025-22020, CVE-2025-22021, CVE-2025-22025, CVE-2025-22035, CVE-2025-22044, CVE-2025-22045, CVE-2025-22050, CVE-2025-22054, CVE-2025-22055, CVE-2025-22056, CVE-2025-22060, CVE-2025-22063, CVE-2025-22066, CVE-2025-22071, CVE-2025-22073, CVE-2025-22075, CVE-2025-22079, CVE-2025-22081, CVE-2025-22086, CVE-2025-22089, CVE-2025-22097, CVE-2025-2312, CVE-2025-23136, CVE-2025-23138, CVE-2025-37785, CVE-2025-37889, CVE-2025-37937, CVE-2025-38152, CVE-2025-38575, CVE-2025-38637, CVE-2025-39728, CVE-2025-39735 Package Information: https://launchpad.net/ubuntu/+source/linux-intel-iotg/5.15.0-1081.87 . Several significant vulnerabilities addressed in Ubuntu's Linux kernel affecting Intel IoT devices. Ensure your systems are updated without delay.. Linux kernel security, Ubuntu security update, Intel IoT vulnerabilities, kernel patching, improper access control. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7598-1 June 24, 2025 linux-azure-5.15 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-azure-5.15: Linux kernel for Microsoft Azure cloud systems Details: Michael Randrianantenaina discovered that the Bluetooth driver in the Linux Kernel contained an improper access control vulnerability. A nearby attacker could use this to connect a rougue device and possibly execute arbitrary code. (CVE-2024-8805) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - PowerPC architecture; - x86 architecture; - ACPI drivers; - Clock framework and drivers; - GPU drivers; - HID subsystem; - InfiniBand drivers; - Media drivers; - MemoryStick subsystem; - Network drivers; - Mellanox network drivers; - NTB driver; - PCI subsystem; - Voltage and Current Regulator drivers; - Remote Processor subsystem; - SCSI subsystem; - QCOM SoC drivers; - Thermal drivers; - BTRFS file system; - Ext4 file system; - JFS file system; - Network file system (NFS) server daemon; - NTFS3 file system; - File systems infrastructure; - Proc file system; - SMB network file system; - IPv6 networking; - RDMA verbs API; - SoC audio core drivers; - Tracing infrastructure; - Watch queue notification mechanism; - 802.1Q VLAN protocol; - Asynchronous Transfer Mode (ATM) subsystem; - Bluetooth subsystem; - Networking core; - IPv4 networking; - Netfilter; - Network trafficcontrol; - SMC sockets; - Sun RPC protocol; - SoC Audio for Freescale CPUs drivers; (CVE-2025-21959, CVE-2025-21996, CVE-2024-46821, CVE-2025-38575, CVE-2025-22045, CVE-2025-21970, CVE-2025-21956, CVE-2025-21994, CVE-2025-23136, CVE-2025-39735, CVE-2025-23138, CVE-2025-22020, CVE-2025-21957, CVE-2025-22063, CVE-2025-21975, CVE-2025-22050, CVE-2024-53144, CVE-2025-21991, CVE-2025-22035, CVE-2024-42230, CVE-2025-22007, CVE-2025-22071, CVE-2025-22060, CVE-2025-22079, CVE-2025-21999, CVE-2025-22081, CVE-2025-22021, CVE-2025-21964, CVE-2024-56664, CVE-2024-56608, CVE-2025-38152, CVE-2025-21992, CVE-2024-56551, CVE-2025-22089, CVE-2025-22075, CVE-2024-53168, CVE-2022-49728, CVE-2022-49636, CVE-2025-22010, CVE-2025-38637, CVE-2025-22004, CVE-2025-21963, CVE-2025-22086, CVE-2025-22097, CVE-2025-21962, CVE-2025-22014, CVE-2024-46753, CVE-2025-22073, CVE-2025-22018, CVE-2025-22044, CVE-2025-21941, CVE-2025-39728, CVE-2025-22055, CVE-2025-37785, CVE-2025-22025, CVE-2025-22066, CVE-2023-53034, CVE-2025-22008, CVE-2025-22054, CVE-2025-37937, CVE-2025-37889, CVE-2025-22005, CVE-2025-21968, CVE-2024-58093, CVE-2024-36945, CVE-2025-21981, CVE-2025-22056, CVE-2024-46812) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.15.0-1091-azure 5.15.0-1091.100~20.04.1 Available with Ubuntu Pro linux-image-azure 5.15.0.1091.100~20.04.1 Available with Ubuntu Pro linux-image-azure-cvm 5.15.0.1091.100~20.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manuallyuninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7598-1 CVE-2022-49636, CVE-2022-49728, CVE-2023-53034, CVE-2024-36945, CVE-2024-42230, CVE-2024-46753, CVE-2024-46812, CVE-2024-46821, CVE-2024-53144, CVE-2024-53168, CVE-2024-56551, CVE-2024-56608, CVE-2024-56664, CVE-2024-58093, CVE-2024-8805, CVE-2025-21941, CVE-2025-21956, CVE-2025-21957, CVE-2025-21959, CVE-2025-21962, CVE-2025-21963, CVE-2025-21964, CVE-2025-21968, CVE-2025-21970, CVE-2025-21975, CVE-2025-21981, CVE-2025-21991, CVE-2025-21992, CVE-2025-21994, CVE-2025-21996, CVE-2025-21999, CVE-2025-22004, CVE-2025-22005, CVE-2025-22007, CVE-2025-22008, CVE-2025-22010, CVE-2025-22014, CVE-2025-22018, CVE-2025-22020, CVE-2025-22021, CVE-2025-22025, CVE-2025-22035, CVE-2025-22044, CVE-2025-22045, CVE-2025-22050, CVE-2025-22054, CVE-2025-22055, CVE-2025-22056, CVE-2025-22060, CVE-2025-22063, CVE-2025-22066, CVE-2025-22071, CVE-2025-22073, CVE-2025-22075, CVE-2025-22079, CVE-2025-22081, CVE-2025-22086, CVE-2025-22089, CVE-2025-22097, CVE-2025-23136, CVE-2025-23138, CVE-2025-37785, CVE-2025-37889, CVE-2025-37937, CVE-2025-38152, CVE-2025-38575, CVE-2025-38637, CVE-2025-39728, CVE-2025-39735 . Urgent security notice for Linux kernel in Ubuntu 20.04 highlights multiple flaws and necessitates prompt response.. Linux kernel vulnerabilities, Ubuntu security fix, Azure kernel update. . Severity: Critical. LinuxSecurity.com Team
Fix improper access control vulnerability Resolves: CVE-2025-48734. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-3eb7c0066f 2025-06-22 01:13:34.506386+00:00 -------------------------------------------------------------------------------- Name : apache-commons-beanutils Product : Fedora 41 Version : 1.9.4 Release : 39.fc41 URL : https://commons.apache.org/proper/commons-beanutils/ Summary : Java utility methods for accessing and modifying the properties of arbitrary JavaBeans Description : The scope of this package is to create a package of Java utility methods for accessing and modifying the properties of arbitrary JavaBeans. No dependencies outside of the JDK are required, so the use of this package is very lightweight. -------------------------------------------------------------------------------- Update Information: Fix improper access control vulnerability Resolves: CVE-2025-48734 -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 13 2025 Mikolaj Izdebski - 1.9.4-39 - Fix improper access control vulnerability * Thu Jan 16 2025 Fedora Release Engineering - 1.9.4-38 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Mon Jan 13 2025 Mikolaj Izdebski - 1.9.4-37 - Update upstream URL * Fri Nov 29 2024 Mikolaj Izdebski - 1.9.4-34 - Update javapackages test plan to f42 * Tue Sep 3 2024 Mikolaj Izdebski - 1.9.4-33 - Use %autosetup -C -------------------------------------------------------------------------------- References: [ 1 ] Bug #2369088 - CVE-2025-48734 apache-commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2369088 -------------------------------------------------------------------------------- This update can be installed with the"dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-3eb7c0066f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7385-1 March 27, 2025 linux-ibm vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-ibm: Linux kernel for IBM cloud systems Details: Michael Randrianantenaina discovered that the Bluetooth driver in the Linux Kernel contained an improper access control vulnerability. A nearby attacker could use this to connect a rougue device and possibly execute arbitrary code. (CVE-2024-8805) Attila Szász discovered that the HFS+ file system implementation in the Linux Kernel contained a heap overflow vulnerability. An attacker could use a specially crafted file system image that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2025-0927) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - ACPI drivers; - Drivers core; - ATA over ethernet (AOE) driver; - Network block device driver; - Ublk userspace block driver; - Compressed RAM block device driver; - TPM device driver; - CPU frequency scaling framework; - Hardware crypto device drivers; - DAX dirext access to differentiated memory framework; - ARM SCMI message protocol; - EFI core; - GPU drivers; - HID subsystem; - I2C subsystem; - I3C subsystem; - IIO subsystem; - InfiniBand drivers; - Input Device core drivers; - IOMMU subsystem; - IRQ chip drivers; -Mailbox framework; - Media drivers; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - STMicroelectronics network drivers; - NTB driver; - Virtio pmem driver; - Parport drivers; - PCI subsystem; - Alibaba DDR Sub-System Driveway PMU driver; - Pin controllers subsystem; - x86 platform drivers; - Powercap sysfs driver; - Remote Processor subsystem; - SCSI subsystem; - SuperH / SH-Mobile drivers; - Direct Digital Synthesis drivers; - Thermal drivers; - TTY drivers; - UFS subsystem; - USB Device Class drivers; - USB Gadget drivers; - USB Host Controller drivers; - TI TPS6598x USB Power Delivery controller driver; - vDPA drivers; - Virtio Host (VHOST) subsystem; - Framebuffer layer; - AFS file system; - BTRFS file system; - File systems infrastructure; - Ceph distributed file system; - Ext4 file system; - F2FS file system; - JFS file system; - Network file systems library; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NILFS2 file system; - NTFS3 file system; - SMB network file system; - BPF subsystem; - Network file system (NFS) superblock; - Virtio network driver; - Network traffic control; - Network sockets; - TCP network protocol; - User-space API (UAPI); - io_uring subsystem; - Perf events; - Kernel thread helper (kthread); - Padata parallel execution mechanism; - RCU subsystem; - Arbitrary resource management; - Static call mechanism; - Timer subsystem; - Tracing infrastructure; - Maple Tree data structure library; - Memory management; - Bluetooth subsystem; - Ethernet bridge; - CAN network layer; - Networking core; - Distributed Switch Architecture; - IPv4 networking; - IPv6 networking; - MAC80211 subsystem; - IEEE 802.15.4 subsystem; - Multipath TCP; - NCSI (Network ControllerSideband Interface) driver; - Netfilter; - Netlink; - RxRPC session sockets; - SCTP protocol; - TIPC protocol; - Unix domain sockets; - Wireless networking; - eXpress Data Path; - AudioScience HPI driver; - KVM core; (CVE-2024-49927, CVE-2024-47719, CVE-2024-49878, CVE-2024-50200, CVE-2024-50013, CVE-2024-50187, CVE-2024-49852, CVE-2024-49913, CVE-2024-50080, CVE-2024-49903, CVE-2024-47745, CVE-2024-50184, CVE-2024-50117, CVE-2024-49863, CVE-2024-49973, CVE-2024-47727, CVE-2024-53170, CVE-2024-49933, CVE-2024-49900, CVE-2024-50095, CVE-2024-49928, CVE-2024-49858, CVE-2024-47731, CVE-2024-49896, CVE-2024-53104, CVE-2024-49972, CVE-2024-49969, CVE-2024-50176, CVE-2024-47739, CVE-2024-49995, CVE-2024-49982, CVE-2024-50044, CVE-2024-49957, CVE-2024-47748, CVE-2024-47744, CVE-2024-49978, CVE-2024-49879, CVE-2024-49987, CVE-2024-49929, CVE-2024-49905, CVE-2024-47723, CVE-2024-53144, CVE-2024-50066, CVE-2024-47735, CVE-2024-50057, CVE-2024-49890, CVE-2024-49963, CVE-2024-49955, CVE-2024-49974, CVE-2024-50049, CVE-2024-47710, CVE-2024-47682, CVE-2024-47734, CVE-2024-47691, CVE-2024-49999, CVE-2024-50098, CVE-2024-47672, CVE-2024-50056, CVE-2024-49983, CVE-2024-50005, CVE-2024-50045, CVE-2024-49866, CVE-2024-49953, CVE-2024-47750, CVE-2024-49917, CVE-2024-50026, CVE-2024-50009, CVE-2024-47718, CVE-2024-50070, CVE-2024-47700, CVE-2024-49986, CVE-2024-49907, CVE-2024-49884, CVE-2024-50085, CVE-2024-50087, CVE-2024-49875, CVE-2024-47728, CVE-2024-49861, CVE-2024-49851, CVE-2024-49980, CVE-2024-49898, CVE-2024-47681, CVE-2024-49965, CVE-2024-49960, CVE-2024-50020, CVE-2024-50012, CVE-2024-50186, CVE-2024-49889, CVE-2024-50030, CVE-2024-50046, CVE-2024-50180, CVE-2024-49966, CVE-2024-49897, CVE-2024-49985, CVE-2024-49918, CVE-2024-47754, CVE-2024-50082, CVE-2024-47757, CVE-2024-47711, CVE-2024-47737, CVE-2024-47716, CVE-2024-50069, CVE-2024-47696, CVE-2024-50031, CVE-2024-50202, CVE-2024-47713, CVE-2024-49894, CVE-2024-49921, CVE-2024-50022, CVE-2024-49856,CVE-2024-47740, CVE-2024-49868, CVE-2024-49919, CVE-2024-47679, CVE-2024-47695, CVE-2024-47714, CVE-2024-49996, CVE-2024-50196, CVE-2024-49997, CVE-2024-49883, CVE-2024-49936, CVE-2024-49962, CVE-2024-47673, CVE-2024-56663, CVE-2024-49892, CVE-2024-47685, CVE-2024-50233, CVE-2024-49891, CVE-2024-47738, CVE-2024-49870, CVE-2024-49885, CVE-2024-50025, CVE-2024-50006, CVE-2024-49968, CVE-2024-47709, CVE-2024-47751, CVE-2024-50058, CVE-2024-50086, CVE-2024-50072, CVE-2024-50195, CVE-2024-56582, CVE-2024-50014, CVE-2024-49886, CVE-2024-47743, CVE-2024-50185, CVE-2024-50193, CVE-2024-49909, CVE-2024-50077, CVE-2024-49930, CVE-2024-49946, CVE-2024-50192, CVE-2024-50041, CVE-2024-47698, CVE-2024-50188, CVE-2024-49977, CVE-2024-47687, CVE-2024-49945, CVE-2024-50008, CVE-2024-49859, CVE-2024-50062, CVE-2024-49880, CVE-2024-47671, CVE-2024-49867, CVE-2024-49912, CVE-2024-56614, CVE-2024-49862, CVE-2024-50021, CVE-2024-47670, CVE-2024-49911, CVE-2024-49855, CVE-2024-47712, CVE-2024-50229, CVE-2024-50096, CVE-2024-49895, CVE-2024-47677, CVE-2024-49934, CVE-2024-53156, CVE-2024-49893, CVE-2024-49925, CVE-2024-50063, CVE-2024-49926, CVE-2024-50201, CVE-2024-50033, CVE-2024-50199, CVE-2024-49874, CVE-2024-47732, CVE-2024-50078, CVE-2024-49935, CVE-2024-49902, CVE-2024-49989, CVE-2024-47675, CVE-2024-50064, CVE-2024-50015, CVE-2024-41016, CVE-2024-49949, CVE-2024-50090, CVE-2024-49860, CVE-2024-50036, CVE-2024-50084, CVE-2024-50182, CVE-2024-50061, CVE-2024-47702, CVE-2024-47730, CVE-2024-49951, CVE-2024-49938, CVE-2024-50088, CVE-2024-50198, CVE-2024-49998, CVE-2024-49931, CVE-2024-49944, CVE-2024-50000, CVE-2024-49954, CVE-2024-47753, CVE-2024-49976, CVE-2024-50048, CVE-2024-49881, CVE-2024-50093, CVE-2024-50019, CVE-2024-50059, CVE-2024-50016, CVE-2024-50068, CVE-2024-49920, CVE-2024-50035, CVE-2024-50197, CVE-2024-47699, CVE-2024-49914, CVE-2024-50191, CVE-2024-50083, CVE-2024-47701, CVE-2024-49877, CVE-2024-50017, CVE-2024-49915, CVE-2024-50001, CVE-2024-49864, CVE-2024-50189,CVE-2024-50101, CVE-2024-47704, CVE-2024-50024, CVE-2024-50038, CVE-2024-49850, CVE-2024-50027, CVE-2024-49952, CVE-2024-50074, CVE-2024-50171, CVE-2024-53165, CVE-2024-47689, CVE-2024-49865, CVE-2024-49853, CVE-2024-47742, CVE-2024-49994, CVE-2024-50179, CVE-2024-47686, CVE-2024-49975, CVE-2024-49948, CVE-2024-50099, CVE-2024-50175, CVE-2024-50028, CVE-2024-49947, CVE-2024-47741, CVE-2024-49888, CVE-2024-50055, CVE-2024-47749, CVE-2024-49992, CVE-2024-47715, CVE-2024-49922, CVE-2024-47756, CVE-2024-50023, CVE-2024-47720, CVE-2024-50194, CVE-2024-47688, CVE-2024-49991, CVE-2024-47705, CVE-2024-49942, CVE-2024-50047, CVE-2024-49981, CVE-2024-49950, CVE-2024-47684, CVE-2024-50065, CVE-2024-49939, CVE-2024-47726, CVE-2024-47697, CVE-2024-49959, CVE-2024-47690, CVE-2024-50040, CVE-2024-50002, CVE-2024-50029, CVE-2024-47752, CVE-2024-49924, CVE-2024-50073, CVE-2024-47733, CVE-2024-50075, CVE-2024-49937, CVE-2024-47707, CVE-2024-47692, CVE-2024-47703, CVE-2024-49988, CVE-2024-50060, CVE-2024-50039, CVE-2024-49961, CVE-2024-50042, CVE-2024-50148, CVE-2024-47678, CVE-2024-49923, CVE-2024-49901, CVE-2024-47706, CVE-2024-49882, CVE-2024-47693, CVE-2024-49876, CVE-2024-47747, CVE-2024-49871, CVE-2024-50076, CVE-2024-50183, CVE-2024-50007, CVE-2024-49958, CVE-2024-50134) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS linux-image-6.8.0-1022-ibm 6.8.0-1022.22 linux-image-ibm 6.8.0-1022.22 linux-image-ibm-classic 6.8.0-1022.22 linux-image-ibm-lts-24.04 6.8.0-1022.22 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic,linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7385-1 CVE-2024-41016, CVE-2024-47670, CVE-2024-47671, CVE-2024-47672, CVE-2024-47673, CVE-2024-47675, CVE-2024-47677, CVE-2024-47678, CVE-2024-47679, CVE-2024-47681, CVE-2024-47682, CVE-2024-47684, CVE-2024-47685, CVE-2024-47686, CVE-2024-47687, CVE-2024-47688, CVE-2024-47689, CVE-2024-47690, CVE-2024-47691, CVE-2024-47692, CVE-2024-47693, CVE-2024-47695, CVE-2024-47696, CVE-2024-47697, CVE-2024-47698, CVE-2024-47699, CVE-2024-47700, CVE-2024-47701, CVE-2024-47702, CVE-2024-47703, CVE-2024-47704, CVE-2024-47705, CVE-2024-47706, CVE-2024-47707, CVE-2024-47709, CVE-2024-47710, CVE-2024-47711, CVE-2024-47712, CVE-2024-47713, CVE-2024-47714, CVE-2024-47715, CVE-2024-47716, CVE-2024-47718, CVE-2024-47719, CVE-2024-47720, CVE-2024-47723, CVE-2024-47726, CVE-2024-47727, CVE-2024-47728, CVE-2024-47730, CVE-2024-47731, CVE-2024-47732, CVE-2024-47733, CVE-2024-47734, CVE-2024-47735, CVE-2024-47737, CVE-2024-47738, CVE-2024-47739, CVE-2024-47740, CVE-2024-47741, CVE-2024-47742, CVE-2024-47743, CVE-2024-47744, CVE-2024-47745, CVE-2024-47747, CVE-2024-47748, CVE-2024-47749, CVE-2024-47750, CVE-2024-47751, CVE-2024-47752, CVE-2024-47753, CVE-2024-47754, CVE-2024-47756, CVE-2024-47757, CVE-2024-49850, CVE-2024-49851, CVE-2024-49852, CVE-2024-49853, CVE-2024-49855, CVE-2024-49856, CVE-2024-49858, CVE-2024-49859, CVE-2024-49860, CVE-2024-49861, CVE-2024-49862, CVE-2024-49863, CVE-2024-49864, CVE-2024-49865, CVE-2024-49866, CVE-2024-49867, CVE-2024-49868, CVE-2024-49870, CVE-2024-49871, CVE-2024-49874, CVE-2024-49875, CVE-2024-49876, CVE-2024-49877, CVE-2024-49878, CVE-2024-49879, CVE-2024-49880, CVE-2024-49881, CVE-2024-49882, CVE-2024-49883, CVE-2024-49884, CVE-2024-49885, CVE-2024-49886, CVE-2024-49888, CVE-2024-49889, CVE-2024-49890, CVE-2024-49891, CVE-2024-49892, CVE-2024-49893, CVE-2024-49894, CVE-2024-49895, CVE-2024-49896, CVE-2024-49897, CVE-2024-49898, CVE-2024-49900, CVE-2024-49901, CVE-2024-49902, CVE-2024-49903, CVE-2024-49905, CVE-2024-49907, CVE-2024-49909, CVE-2024-49911, CVE-2024-49912, CVE-2024-49913, CVE-2024-49914, CVE-2024-49915, CVE-2024-49917, CVE-2024-49918, CVE-2024-49919, CVE-2024-49920, CVE-2024-49921, CVE-2024-49922, CVE-2024-49923, CVE-2024-49924, CVE-2024-49925, CVE-2024-49926, CVE-2024-49927, CVE-2024-49928, CVE-2024-49929, CVE-2024-49930, CVE-2024-49931, CVE-2024-49933, CVE-2024-49934, CVE-2024-49935, CVE-2024-49936, CVE-2024-49937, CVE-2024-49938, CVE-2024-49939, CVE-2024-49942, CVE-2024-49944, CVE-2024-49945, CVE-2024-49946, CVE-2024-49947, CVE-2024-49948, CVE-2024-49949, CVE-2024-49950, CVE-2024-49951, CVE-2024-49952, CVE-2024-49953, CVE-2024-49954, CVE-2024-49955, CVE-2024-49957, CVE-2024-49958, CVE-2024-49959, CVE-2024-49960, CVE-2024-49961, CVE-2024-49962, CVE-2024-49963, CVE-2024-49965, CVE-2024-49966, CVE-2024-49968, CVE-2024-49969, CVE-2024-49972, CVE-2024-49973, CVE-2024-49974, CVE-2024-49975, CVE-2024-49976, CVE-2024-49977, CVE-2024-49978, CVE-2024-49980, CVE-2024-49981, CVE-2024-49982, CVE-2024-49983, CVE-2024-49985, CVE-2024-49986, CVE-2024-49987, CVE-2024-49988, CVE-2024-49989, CVE-2024-49991, CVE-2024-49992, CVE-2024-49994, CVE-2024-49995, CVE-2024-49996, CVE-2024-49997, CVE-2024-49998, CVE-2024-49999, CVE-2024-50000, CVE-2024-50001, CVE-2024-50002, CVE-2024-50005, CVE-2024-50006, CVE-2024-50007, CVE-2024-50008, CVE-2024-50009, CVE-2024-50012, CVE-2024-50013, CVE-2024-50014, CVE-2024-50015, CVE-2024-50016, CVE-2024-50017, CVE-2024-50019, CVE-2024-50020, CVE-2024-50021, CVE-2024-50022, CVE-2024-50023, CVE-2024-50024, CVE-2024-50025, CVE-2024-50026, CVE-2024-50027, CVE-2024-50028, CVE-2024-50029, CVE-2024-50030, CVE-2024-50031, CVE-2024-50033, CVE-2024-50035, CVE-2024-50036, CVE-2024-50038, CVE-2024-50039, CVE-2024-50040, CVE-2024-50041, CVE-2024-50042, CVE-2024-50044, CVE-2024-50045, CVE-2024-50046, CVE-2024-50047, CVE-2024-50048, CVE-2024-50049, CVE-2024-50055, CVE-2024-50056, CVE-2024-50057, CVE-2024-50058, CVE-2024-50059, CVE-2024-50060, CVE-2024-50061, CVE-2024-50062, CVE-2024-50063, CVE-2024-50064, CVE-2024-50065, CVE-2024-50066, CVE-2024-50068, CVE-2024-50069, CVE-2024-50070, CVE-2024-50072, CVE-2024-50073, CVE-2024-50074, CVE-2024-50075, CVE-2024-50076, CVE-2024-50077, CVE-2024-50078, CVE-2024-50080, CVE-2024-50082, CVE-2024-50083, CVE-2024-50084, CVE-2024-50085, CVE-2024-50086, CVE-2024-50087, CVE-2024-50088, CVE-2024-50090, CVE-2024-50093, CVE-2024-50095, CVE-2024-50096, CVE-2024-50098, CVE-2024-50099, CVE-2024-50101, CVE-2024-50117, CVE-2024-50134, CVE-2024-50148, CVE-2024-50171, CVE-2024-50175, CVE-2024-50176, CVE-2024-50179, CVE-2024-50180, CVE-2024-50182, CVE-2024-50183, CVE-2024-50184, CVE-2024-50185, CVE-2024-50186, CVE-2024-50187, CVE-2024-50188, CVE-2024-50189, CVE-2024-50191, CVE-2024-50192, CVE-2024-50193, CVE-2024-50194, CVE-2024-50195, CVE-2024-50196, CVE-2024-50197, CVE-2024-50198, CVE-2024-50199, CVE-2024-50200, CVE-2024-50201, CVE-2024-50202, CVE-2024-50229, CVE-2024-50233, CVE-2024-53104, CVE-2024-53144, CVE-2024-53156, CVE-2024-53165, CVE-2024-53170, CVE-2024-56582, CVE-2024-56614, CVE-2024-56663, CVE-2024-8805, CVE-2025-0927 Package Information: https://launchpad.net/ubuntu/+source/linux-ibm/6.8.0-1022.22 . Significant updates for Ubuntu's Linux kernel address critical vulnerabilities to enhance system security.. security, linux, kernel, ============================================. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7384-1 March 27, 2025 linux-azure vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-azure: Linux kernel for Microsoft Azure Cloud systems Details: Michael Randrianantenaina discovered that the Bluetooth driver in the Linux Kernel contained an improper access control vulnerability. A nearby attacker could use this to connect a rougue device and possibly execute arbitrary code. (CVE-2024-8805) Attila Szász discovered that the HFS+ file system implementation in the Linux Kernel contained a heap overflow vulnerability. An attacker could use a specially crafted file system image that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2025-0927) It was discovered that the CIFS network file system implementation in the Linux kernel did not properly verify the target namespace when handling upcalls. An attacker could use this to expose sensitive information. (CVE-2025-2312) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - ACPI drivers; - Drivers core; - ATA over ethernet (AOE) driver; - Network block device driver; - Ublk userspace block driver; - Compressed RAM block device driver; - TPM device driver; - CPU frequency scaling framework; - Hardware crypto device drivers; - DAX dirext access to differentiated memory framework; - ARM SCMImessage protocol; - EFI core; - GPU drivers; - HID subsystem; - I2C subsystem; - I3C subsystem; - IIO subsystem; - InfiniBand drivers; - Input Device core drivers; - IOMMU subsystem; - IRQ chip drivers; - Mailbox framework; - Media drivers; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - STMicroelectronics network drivers; - NTB driver; - Virtio pmem driver; - Parport drivers; - PCI subsystem; - Alibaba DDR Sub-System Driveway PMU driver; - Pin controllers subsystem; - x86 platform drivers; - Powercap sysfs driver; - Remote Processor subsystem; - SCSI subsystem; - SuperH / SH-Mobile drivers; - Direct Digital Synthesis drivers; - Thermal drivers; - TTY drivers; - UFS subsystem; - USB Device Class drivers; - USB Gadget drivers; - USB Host Controller drivers; - TI TPS6598x USB Power Delivery controller driver; - vDPA drivers; - Virtio Host (VHOST) subsystem; - Framebuffer layer; - AFS file system; - BTRFS file system; - File systems infrastructure; - Ceph distributed file system; - Ext4 file system; - F2FS file system; - JFS file system; - Network file systems library; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NILFS2 file system; - NTFS3 file system; - SMB network file system; - BPF subsystem; - Network file system (NFS) superblock; - Virtio network driver; - Network traffic control; - Network sockets; - TCP network protocol; - User-space API (UAPI); - io_uring subsystem; - Perf events; - Kernel thread helper (kthread); - Padata parallel execution mechanism; - RCU subsystem; - Arbitrary resource management; - Static call mechanism; - Timer subsystem; - Tracing infrastructure; - Maple Tree data structure library; - Memory management; - Bluetooth subsystem; - Ethernetbridge; - CAN network layer; - Networking core; - Distributed Switch Architecture; - IPv4 networking; - IPv6 networking; - MAC80211 subsystem; - IEEE 802.15.4 subsystem; - Multipath TCP; - NCSI (Network Controller Sideband Interface) driver; - Netfilter; - Netlink; - RxRPC session sockets; - SCTP protocol; - TIPC protocol; - Unix domain sockets; - Wireless networking; - eXpress Data Path; - AudioScience HPI driver; - KVM core; (CVE-2024-49994, CVE-2024-47740, CVE-2024-49936, CVE-2024-47716, CVE-2024-47733, CVE-2024-50075, CVE-2024-49870, CVE-2024-50007, CVE-2024-49897, CVE-2024-49915, CVE-2024-47756, CVE-2024-47700, CVE-2024-49946, CVE-2024-50012, CVE-2024-47750, CVE-2024-49863, CVE-2024-50059, CVE-2024-50026, CVE-2024-49995, CVE-2024-50035, CVE-2024-47751, CVE-2024-50096, CVE-2024-50082, CVE-2024-50090, CVE-2024-50000, CVE-2024-47690, CVE-2024-47741, CVE-2024-49898, CVE-2024-47685, CVE-2024-50038, CVE-2024-49957, CVE-2024-47682, CVE-2024-50002, CVE-2024-47709, CVE-2024-50201, CVE-2024-49927, CVE-2024-50076, CVE-2024-56582, CVE-2024-47742, CVE-2024-47734, CVE-2024-50040, CVE-2024-49862, CVE-2024-49942, CVE-2024-50193, CVE-2024-49880, CVE-2024-50008, CVE-2024-49949, CVE-2024-50056, CVE-2024-50099, CVE-2024-50180, CVE-2024-50045, CVE-2024-49923, CVE-2024-49987, CVE-2024-49884, CVE-2024-50031, CVE-2024-47705, CVE-2024-47728, CVE-2024-49969, CVE-2024-50077, CVE-2024-50188, CVE-2024-49852, CVE-2024-49890, CVE-2024-47745, CVE-2024-50058, CVE-2024-50186, CVE-2024-47749, CVE-2024-56614, CVE-2024-50021, CVE-2024-50055, CVE-2024-47727, CVE-2024-47677, CVE-2024-49922, CVE-2024-50015, CVE-2024-50084, CVE-2024-47689, CVE-2024-50101, CVE-2024-47699, CVE-2024-49947, CVE-2024-49999, CVE-2024-49868, CVE-2024-50184, CVE-2024-50187, CVE-2024-47757, CVE-2024-49900, CVE-2024-47703, CVE-2024-49975, CVE-2024-47692, CVE-2024-49980, CVE-2024-49951, CVE-2024-49930, CVE-2024-49867, CVE-2024-49860, CVE-2024-50009, CVE-2024-50072,CVE-2024-50229, CVE-2024-49954, CVE-2024-50183, CVE-2024-49858, CVE-2024-49909, CVE-2024-49926, CVE-2024-47754, CVE-2024-50027, CVE-2024-50200, CVE-2024-50196, CVE-2024-50086, CVE-2024-47739, CVE-2024-49978, CVE-2024-49983, CVE-2024-49894, CVE-2024-49973, CVE-2024-49888, CVE-2024-49974, CVE-2024-47672, CVE-2024-49977, CVE-2024-47738, CVE-2024-49893, CVE-2024-49876, CVE-2024-49960, CVE-2024-49955, CVE-2024-47670, CVE-2024-47706, CVE-2024-49931, CVE-2024-47686, CVE-2024-49855, CVE-2024-49901, CVE-2024-47752, CVE-2024-47675, CVE-2024-47704, CVE-2024-47735, CVE-2024-47744, CVE-2024-50088, CVE-2024-50070, CVE-2024-47707, CVE-2024-50176, CVE-2024-50080, CVE-2024-50175, CVE-2024-47731, CVE-2024-49853, CVE-2024-49929, CVE-2024-49989, CVE-2024-49921, CVE-2024-49965, CVE-2024-49891, CVE-2024-50005, CVE-2024-47715, CVE-2024-50085, CVE-2024-50189, CVE-2024-47723, CVE-2024-50020, CVE-2024-49902, CVE-2024-47730, CVE-2024-53156, CVE-2024-49895, CVE-2024-49997, CVE-2024-50192, CVE-2024-49850, CVE-2024-50062, CVE-2024-50033, CVE-2024-49972, CVE-2024-49945, CVE-2024-50036, CVE-2024-50202, CVE-2024-50095, CVE-2024-49913, CVE-2024-50049, CVE-2024-50148, CVE-2024-49948, CVE-2024-49866, CVE-2024-49963, CVE-2024-49907, CVE-2024-50117, CVE-2024-49885, CVE-2024-49874, CVE-2024-50198, CVE-2024-49856, CVE-2024-49986, CVE-2024-49871, CVE-2024-50028, CVE-2024-49889, CVE-2024-50024, CVE-2024-47687, CVE-2024-50065, CVE-2024-49953, CVE-2024-47748, CVE-2024-47747, CVE-2024-47673, CVE-2024-49928, CVE-2024-50191, CVE-2024-50016, CVE-2024-53170, CVE-2024-49933, CVE-2024-50029, CVE-2024-50098, CVE-2024-49988, CVE-2024-49985, CVE-2024-50042, CVE-2024-50171, CVE-2024-50233, CVE-2024-49976, CVE-2024-49996, CVE-2024-49950, CVE-2024-49968, CVE-2024-50083, CVE-2024-49966, CVE-2024-49851, CVE-2024-50066, CVE-2024-49864, CVE-2024-50048, CVE-2024-50069, CVE-2024-50001, CVE-2024-50194, CVE-2024-47693, CVE-2024-49905, CVE-2024-50134, CVE-2024-49944, CVE-2024-50060, CVE-2024-49892, CVE-2024-49982, CVE-2024-49883,CVE-2024-49875, CVE-2024-47691, CVE-2024-47714, CVE-2024-47712, CVE-2024-50025, CVE-2024-50023, CVE-2024-47726, CVE-2024-50041, CVE-2024-49896, CVE-2024-50195, CVE-2024-47679, CVE-2024-47678, CVE-2024-49877, CVE-2024-47684, CVE-2024-47719, CVE-2024-49937, CVE-2024-53144, CVE-2024-47737, CVE-2024-49998, CVE-2024-49879, CVE-2024-50019, CVE-2024-50093, CVE-2024-50073, CVE-2024-50064, CVE-2024-50006, CVE-2024-47695, CVE-2024-49882, CVE-2024-50179, CVE-2024-49865, CVE-2024-47702, CVE-2024-50046, CVE-2024-49919, CVE-2024-47697, CVE-2024-50017, CVE-2024-50014, CVE-2024-49861, CVE-2024-50197, CVE-2024-49886, CVE-2024-49938, CVE-2024-49991, CVE-2024-49981, CVE-2024-56663, CVE-2024-49914, CVE-2024-49920, CVE-2024-47671, CVE-2024-49961, CVE-2024-47698, CVE-2024-49952, CVE-2024-47688, CVE-2024-50078, CVE-2024-50199, CVE-2024-49918, CVE-2024-50044, CVE-2024-50013, CVE-2024-47711, CVE-2024-49917, CVE-2024-50057, CVE-2024-47718, CVE-2024-49911, CVE-2024-49912, CVE-2024-53165, CVE-2024-50068, CVE-2024-50087, CVE-2024-47720, CVE-2024-49958, CVE-2024-49934, CVE-2024-49859, CVE-2024-47710, CVE-2024-49903, CVE-2024-49925, CVE-2024-50061, CVE-2024-41016, CVE-2024-47696, CVE-2024-47701, CVE-2024-49939, CVE-2024-49924, CVE-2024-49935, CVE-2024-50030, CVE-2024-50074, CVE-2024-47681, CVE-2024-47743, CVE-2024-49992, CVE-2024-49881, CVE-2024-50063, CVE-2024-47713, CVE-2024-50039, CVE-2024-50185, CVE-2024-49962, CVE-2024-50182, CVE-2024-50022, CVE-2024-49959, CVE-2024-50047, CVE-2024-53104, CVE-2024-49878, CVE-2024-47732, CVE-2024-47753) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS linux-image-6.8.0-1025-azure 6.8.0-1025.30 linux-image-6.8.0-1025-azure-fde 6.8.0-1025.30 linux-image-azure-fde-lts-24.04 6.8.0-1025.30 linux-image-azure-lts-24.04 6.8.0-1025.30 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABIchange the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7384-1 CVE-2024-41016, CVE-2024-47670, CVE-2024-47671, CVE-2024-47672, CVE-2024-47673, CVE-2024-47675, CVE-2024-47677, CVE-2024-47678, CVE-2024-47679, CVE-2024-47681, CVE-2024-47682, CVE-2024-47684, CVE-2024-47685, CVE-2024-47686, CVE-2024-47687, CVE-2024-47688, CVE-2024-47689, CVE-2024-47690, CVE-2024-47691, CVE-2024-47692, CVE-2024-47693, CVE-2024-47695, CVE-2024-47696, CVE-2024-47697, CVE-2024-47698, CVE-2024-47699, CVE-2024-47700, CVE-2024-47701, CVE-2024-47702, CVE-2024-47703, CVE-2024-47704, CVE-2024-47705, CVE-2024-47706, CVE-2024-47707, CVE-2024-47709, CVE-2024-47710, CVE-2024-47711, CVE-2024-47712, CVE-2024-47713, CVE-2024-47714, CVE-2024-47715, CVE-2024-47716, CVE-2024-47718, CVE-2024-47719, CVE-2024-47720, CVE-2024-47723, CVE-2024-47726, CVE-2024-47727, CVE-2024-47728, CVE-2024-47730, CVE-2024-47731, CVE-2024-47732, CVE-2024-47733, CVE-2024-47734, CVE-2024-47735, CVE-2024-47737, CVE-2024-47738, CVE-2024-47739, CVE-2024-47740, CVE-2024-47741, CVE-2024-47742, CVE-2024-47743, CVE-2024-47744, CVE-2024-47745, CVE-2024-47747, CVE-2024-47748, CVE-2024-47749, CVE-2024-47750, CVE-2024-47751, CVE-2024-47752, CVE-2024-47753, CVE-2024-47754, CVE-2024-47756, CVE-2024-47757, CVE-2024-49850, CVE-2024-49851, CVE-2024-49852, CVE-2024-49853, CVE-2024-49855, CVE-2024-49856, CVE-2024-49858, CVE-2024-49859, CVE-2024-49860, CVE-2024-49861, CVE-2024-49862, CVE-2024-49863, CVE-2024-49864, CVE-2024-49865, CVE-2024-49866, CVE-2024-49867, CVE-2024-49868, CVE-2024-49870, CVE-2024-49871,CVE-2024-49874, CVE-2024-49875, CVE-2024-49876, CVE-2024-49877, CVE-2024-49878, CVE-2024-49879, CVE-2024-49880, CVE-2024-49881, CVE-2024-49882, CVE-2024-49883, CVE-2024-49884, CVE-2024-49885, CVE-2024-49886, CVE-2024-49888, CVE-2024-49889, CVE-2024-49890, CVE-2024-49891, CVE-2024-49892, CVE-2024-49893, CVE-2024-49894, CVE-2024-49895, CVE-2024-49896, CVE-2024-49897, CVE-2024-49898, CVE-2024-49900, CVE-2024-49901, CVE-2024-49902, CVE-2024-49903, CVE-2024-49905, CVE-2024-49907, CVE-2024-49909, CVE-2024-49911, CVE-2024-49912, CVE-2024-49913, CVE-2024-49914, CVE-2024-49915, CVE-2024-49917, CVE-2024-49918, CVE-2024-49919, CVE-2024-49920, CVE-2024-49921, CVE-2024-49922, CVE-2024-49923, CVE-2024-49924, CVE-2024-49925, CVE-2024-49926, CVE-2024-49927, CVE-2024-49928, CVE-2024-49929, CVE-2024-49930, CVE-2024-49931, CVE-2024-49933, CVE-2024-49934, CVE-2024-49935, CVE-2024-49936, CVE-2024-49937, CVE-2024-49938, CVE-2024-49939, CVE-2024-49942, CVE-2024-49944, CVE-2024-49945, CVE-2024-49946, CVE-2024-49947, CVE-2024-49948, CVE-2024-49949, CVE-2024-49950, CVE-2024-49951, CVE-2024-49952, CVE-2024-49953, CVE-2024-49954, CVE-2024-49955, CVE-2024-49957, CVE-2024-49958, CVE-2024-49959, CVE-2024-49960, CVE-2024-49961, CVE-2024-49962, CVE-2024-49963, CVE-2024-49965, CVE-2024-49966, CVE-2024-49968, CVE-2024-49969, CVE-2024-49972, CVE-2024-49973, CVE-2024-49974, CVE-2024-49975, CVE-2024-49976, CVE-2024-49977, CVE-2024-49978, CVE-2024-49980, CVE-2024-49981, CVE-2024-49982, CVE-2024-49983, CVE-2024-49985, CVE-2024-49986, CVE-2024-49987, CVE-2024-49988, CVE-2024-49989, CVE-2024-49991, CVE-2024-49992, CVE-2024-49994, CVE-2024-49995, CVE-2024-49996, CVE-2024-49997, CVE-2024-49998, CVE-2024-49999, CVE-2024-50000, CVE-2024-50001, CVE-2024-50002, CVE-2024-50005, CVE-2024-50006, CVE-2024-50007, CVE-2024-50008, CVE-2024-50009, CVE-2024-50012, CVE-2024-50013, CVE-2024-50014, CVE-2024-50015, CVE-2024-50016, CVE-2024-50017,CVE-2024-50019, CVE-2024-50020, CVE-2024-50021, CVE-2024-50022, CVE-2024-50023, CVE-2024-50024, CVE-2024-50025, CVE-2024-50026, CVE-2024-50027, CVE-2024-50028, CVE-2024-50029, CVE-2024-50030, CVE-2024-50031, CVE-2024-50033, CVE-2024-50035, CVE-2024-50036, CVE-2024-50038, CVE-2024-50039, CVE-2024-50040, CVE-2024-50041, CVE-2024-50042, CVE-2024-50044, CVE-2024-50045, CVE-2024-50046, CVE-2024-50047, CVE-2024-50048, CVE-2024-50049, CVE-2024-50055, CVE-2024-50056, CVE-2024-50057, CVE-2024-50058, CVE-2024-50059, CVE-2024-50060, CVE-2024-50061, CVE-2024-50062, CVE-2024-50063, CVE-2024-50064, CVE-2024-50065, CVE-2024-50066, CVE-2024-50068, CVE-2024-50069, CVE-2024-50070, CVE-2024-50072, CVE-2024-50073, CVE-2024-50074, CVE-2024-50075, CVE-2024-50076, CVE-2024-50077, CVE-2024-50078, CVE-2024-50080, CVE-2024-50082, CVE-2024-50083, CVE-2024-50084, CVE-2024-50085, CVE-2024-50086, CVE-2024-50087, CVE-2024-50088, CVE-2024-50090, CVE-2024-50093, CVE-2024-50095, CVE-2024-50096, CVE-2024-50098, CVE-2024-50099, CVE-2024-50101, CVE-2024-50117, CVE-2024-50134, CVE-2024-50148, CVE-2024-50171, CVE-2024-50175, CVE-2024-50176, CVE-2024-50179, CVE-2024-50180, CVE-2024-50182, CVE-2024-50183, CVE-2024-50184, CVE-2024-50185, CVE-2024-50186, CVE-2024-50187, CVE-2024-50188, CVE-2024-50189, CVE-2024-50191, CVE-2024-50192, CVE-2024-50193, CVE-2024-50194, CVE-2024-50195, CVE-2024-50196, CVE-2024-50197, CVE-2024-50198, CVE-2024-50199, CVE-2024-50200, CVE-2024-50201, CVE-2024-50202, CVE-2024-50229, CVE-2024-50233, CVE-2024-53104, CVE-2024-53144, CVE-2024-53156, CVE-2024-53165, CVE-2024-53170, CVE-2024-56582, CVE-2024-56614, CVE-2024-56663, CVE-2024-8805, CVE-2025-0927, CVE-2025-2312 Package Information: https://launchpad.net/ubuntu/+source/linux-azure/6.8.0-1025.30 . Critical updates for Ubuntu 24.04 LTS addressing multiple security issues in the Linux kernel for Azure.. security, linux, kernel,============================================. . Severity: Critical. LinuxSecurity.com Team
Several flaws have been discovered in HTCondor, a distributed workload management system, which allow users with only READ access to any daemon to use a different authentication method than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5144-1
Get the latest Linux and open source security news straight to your inbox.