Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 9 articles for you...
172

Ubuntu 14.04 LTS USN-6211-1 Critical: Azure Kernel Regression Fix

The system could show undesired warning messages in certain conditions.. =========================================================================Ubuntu Security Notice USN-6211-1 July 07, 2023 linux-azure regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS (Available with Ubuntu Pro) Summary: The system could show undesired warning messages in certain conditions. Software Description: - linux-azure: Linux kernel for Microsoft Azure Cloud systems Details: USN-6130-1 fixed vulnerabilities in the Linux kernel. Unfortunately, that update introduced a spurious warning in the IPv6 subsystem. This update removes the undesired warning message. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS (Available with Ubuntu Pro): linux-image-4.15.0-1167-azure 4.15.0-1167.182~14.04.1 linux-image-azure 4.15.0.1167.133 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2020279 . An important patch tackling backward compatibility problems in Ubuntu's Azure kernel, promoting reliable performance and correct notifications.. Ubuntu Azure Kernel Update, Linux Security Advisory, Critical Kernel Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 07, 2023 Critical Ubuntu
172

Ubuntu 18.04 & 16.04 USN-6191-1 Moderate Kernel Regression Fix

The system could show undesired warning messages in certain conditions.. =========================================================================Ubuntu Security Notice USN-6191-1 June 29, 2023 linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-dell300x, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: The system could show undesired warning messages in certain conditions. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-azure-4.15: Linux kernel for Microsoft Azure Cloud systems - linux-dell300x: Linux kernel for Dell 300x platforms - linux-gcp-4.15: Linux kernel for Google Cloud Platform (GCP) systems - linux-kvm: Linux kernel for cloud environments - linux-oracle: Linux kernel for Oracle Cloud systems - linux-raspi2: Linux kernel for Raspberry Pi systems - linux-snapdragon: Linux kernel for Qualcomm Snapdragon processors - linux-aws-hwe: Linux kernel for Amazon Web Services (AWS-HWE) systems - linux-azure: Linux kernel for Microsoft Azure Cloud systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-hwe: Linux hardware enablement (HWE) kernel Details: USN-6081-1, USN-6084-1, USN-6092-1 and USN-6095-1 fixed vulnerabilities in the Linux kernel. Unfortunately, that update introduced a spurious warning in the IPv6 subsystem. This update removes the undesired warning message. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: linux-image-4.15.0-1067-dell300x 4.15.0-1067.72 linux-image-4.15.0-1121-oracle 4.15.0-1121.132 linux-image-4.15.0-1134-raspi2 4.15.0-1134.142 linux-image-4.15.0-1142-kvm 4.15.0-1142.147 linux-image-4.15.0-1151-gcp 4.15.0-1151.167 linux-image-4.15.0-1152-snapdragon 4.15.0-1152.162 linux-image-4.15.0-1158-aws 4.15.0-1158.171 linux-image-4.15.0-1167-azure 4.15.0-1167.182 linux-image-4.15.0-213-generic 4.15.0-213.224 linux-image-4.15.0-213-generic-lpae 4.15.0-213.224 linux-image-4.15.0-213-lowlatency 4.15.0-213.224 linux-image-aws-lts-18.04 4.15.0.1158.156 linux-image-azure-lts-18.04 4.15.0.1167.135 linux-image-dell300x 4.15.0.1067.66 linux-image-gcp-lts-18.04 4.15.0.1151.165 linux-image-generic 4.15.0.213.196 linux-image-generic-lpae 4.15.0.213.196 linux-image-kvm 4.15.0.1142.133 linux-image-lowlatency 4.15.0.213.196 linux-image-oracle-lts-18.04 4.15.0.1121.126 linux-image-raspi2 4.15.0.1134.129 linux-image-snapdragon 4.15.0.1152.151 linux-image-virtual 4.15.0.213.196 Ubuntu 16.04 LTS (Available with Ubuntu Pro): linux-image-4.15.0-1121-oracle 4.15.0-1121.132~16.04.1 linux-image-4.15.0-1152-gcp 4.15.0-1152.168~16.04.1 linux-image-4.15.0-1158-aws 4.15.0-1158.171~16.04.1 linux-image-4.15.0-1167-azure 4.15.0-1167.182~16.04.1 linux-image-4.15.0-213-generic 4.15.0-213.224~16.04.1 linux-image-4.15.0-213-lowlatency 4.15.0-213.224~16.04.1 linux-image-aws-hwe 4.15.0.1158.141 linux-image-azure 4.15.0.1167.151 linux-image-gcp 4.15.0.1152.142 linux-image-generic-hwe-16.04 4.15.0.213.198 linux-image-gke 4.15.0.1152.142 linux-image-lowlatency-hwe-16.04 4.15.0.213.198 linux-image-oem 4.15.0.213.198 linux-image-oracle 4.15.0.1121.102 linux-image-virtual-hwe-16.04 4.15.0.213.198 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to anunavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2020279 Package Information: https://launchpad.net/ubuntu/+source/linux/4.15.0-213.224 https://launchpad.net/ubuntu/+source/linux-aws/4.15.0-1158.171 https://launchpad.net/ubuntu/+source/linux-azure-4.15/4.15.0-1167.182 https://launchpad.net/ubuntu/+source/linux-dell300x/4.15.0-1067.72 https://launchpad.net/ubuntu/+source/linux-gcp-4.15/4.15.0-1151.167 https://launchpad.net/ubuntu/+source/linux-kvm/4.15.0-1142.147 https://launchpad.net/ubuntu/+source/linux-oracle/4.15.0-1121.132 https://launchpad.net/ubuntu/+source/linux-raspi2/4.15.0-1134.142 https://launchpad.net/ubuntu/+source/linux-snapdragon/4.15.0-1152.162 . Upgrade your Ubuntu installations to fix the kernel regression problem leading to unwanted notification alerts in the 18.04 and 16.04 LTS versions.. Ubuntu Kernel Issue, System Bug Fix, Security Update. . LinuxSecurity.com Team

Calendar%202 Jun 29, 2023 Ubuntu
172

Ubuntu 20.04 LTS: USN-5091-3 Critical Kernel Azure Regression: DoS Issue

USN-5091-1 introduced a regression in the Linux kernel for Microsoft Azure cloud systems.. =========================================================================Ubuntu Security Notice USN-5091-3 October 15, 2021 linux-azure, linux-azure-5.4 regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: USN-5091-1 introduced a regression in the Linux kernel for Microsoft Azure cloud systems. Software Description: - linux-azure: Linux kernel for Microsoft Azure Cloud systems - linux-azure-5.4: Linux kernel for Microsoft Azure cloud systems Details: USN-5091-1 fixed vulnerabilities in Linux 5.4-based kernels. Unfortunately, for Linux kernels intended for use within Microsoft Azure environments, that update introduced a regression that could cause the kernel to fail to boot in large Azure instance types. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Ofek Kirzner, Adam Morrison, Benedict Schlueter, and Piotr Krysiuk discovered that the BPF verifier in the Linux kernel missed possible mispredicted branches due to type confusion, allowing a side-channel attack. An attacker could use this to expose sensitive information. (CVE-2021-33624) It was discovered that the tracing subsystem in the Linux kernel did not properly keep track of per-cpu ring buffer state. A privileged attacker could use this to cause a denial of service. (CVE-2021-3679) Alexey Kardashevskiy discovered that the KVM implementation for PowerPC systems in the Linux kernel did not properly validate RTAS arguments in some situations. An attacker in a guest vm could use this to cause a denial of service (host OS crash) or possibly execute arbitrary code. (CVE-2021-37576) It was discovered that the Virtio console implementation in the Linux kernel did not properly validate input lengths in some situations. A local attacker could possiblyuse this to cause a denial of service (system crash). (CVE-2021-38160) Michael Wakabayashi discovered that the NFSv4 client implementation in the Linux kernel did not properly order connection setup operations. An attacker controlling a remote NFS server could use this to cause a denial of service on the client. (CVE-2021-38199) It was discovered that the MAX-3421 host USB device driver in the Linux kernel did not properly handle device removal events. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2021-38204) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: linux-image-5.4.0-1061-azure 5.4.0-1061.64 linux-image-azure-lts-20.04 5.4.0.1061.59 Ubuntu 18.04 LTS: linux-image-5.4.0-1061-azure 5.4.0-1061.64~18.04.1 linux-image-azure 5.4.0.1061.41 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-5091-3 https://ubuntu.com/security/notices/USN-5091-1 https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1940564 Package Information: https://launchpad.net/ubuntu/+source/linux-azure/5.4.0-1061.64 https://launchpad.net/ubuntu/+source/linux-azure-5.4/5.4.0-1061.64~18.04.1 . Tackling performance challenges in the Linux kernel for AWS. Enhance your system resilience now!. Linux Kernel Update, Azure Security Patch, Denial of Service Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 14, 2021 Critical Ubuntu
172

Ubuntu 20.04 LTS: USN-4916-2 Critical: Kernel Memory Leak Fix

USN-4916-1 introduced a regression in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-4916-2 April 21, 2021 linux, linux-aws, linux-gke-5.3, linux-hwe, linux-kvm, linux-lts-xenial, linux-oem-5.6, linux-raspi2-5.3, linux-snapdragon regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 ESM Summary: USN-4916-1 introduced a regression in the Linux kernel. Software Description: - linux-oem-5.6: Linux kernel for OEM systems - linux-gke-5.3: Linux kernel for Google Container Engine (GKE) systems - linux-hwe: Linux hardware enablement (HWE) kernel - linux-raspi2-5.3: Linux kernel for Raspberry Pi (V8) systems - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-kvm: Linux kernel for cloud environments - linux-snapdragon: Linux kernel for Qualcomm Snapdragon processors- linux-lts-xenial: Linux hardware enablement kernel from Xenial for Trusty Details: USN-4916-1 fixed vulnerabilities in the Linux kernel. Unfortunately, the fix for CVE-2021-3493 introduced a memory leak in some situations. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that the overlayfs implementation in the Linux kernel did not properly validate the application of file system capabilities with respect to user namespaces. A local attacker could use this to gain elevated privileges. (CVE-2021-3493) Piotr Krysiuk discovered that the BPF JIT compiler for x86 in the Linux kernel did not properly validate computation of branch displacements in some situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-29154) Update instructions: The problem can be corrected by updating your system to the following packageversions: Ubuntu 20.04 LTS: linux-image-5.6.0-1055-oem 5.6.0-1055.59 linux-image-oem-20.04 5.6.0.1055.51 Ubuntu 18.04 LTS: linux-image-5.3.0-1040-raspi2 5.3.0-1040.42 linux-image-5.3.0-1043-gke 5.3.0-1043.46 linux-image-5.3.0-74-generic 5.3.0-74.70 linux-image-5.3.0-74-lowlatency 5.3.0-74.70 linux-image-gke-5.3 5.3.0.1043.26 linux-image-gkeop-5.3 5.3.0.74.131 linux-image-raspi2-hwe-18.04 5.3.0.1040.29 Ubuntu 16.04 LTS: linux-image-4.4.0-1093-kvm 4.4.0-1093.102 linux-image-4.4.0-1128-aws 4.4.0-1128.142 linux-image-4.4.0-1156-snapdragon 4.4.0-1156.166 linux-image-4.4.0-210-generic 4.4.0-210.242 linux-image-4.4.0-210-generic-lpae 4.4.0-210.242 linux-image-4.4.0-210-lowlatency 4.4.0-210.242 linux-image-4.4.0-210-powerpc-e500mc 4.4.0-210.242 linux-image-4.4.0-210-powerpc-smp 4.4.0-210.242 linux-image-4.4.0-210-powerpc64-emb 4.4.0-210.242 linux-image-4.4.0-210-powerpc64-smp 4.4.0-210.242 linux-image-aws 4.4.0.1128.133 linux-image-generic 4.4.0.210.216 linux-image-generic-lpae 4.4.0.210.216 linux-image-kvm 4.4.0.1093.91 linux-image-lowlatency 4.4.0.210.216 linux-image-powerpc-e500mc 4.4.0.210.216 linux-image-powerpc-smp 4.4.0.210.216 linux-image-powerpc64-emb 4.4.0.210.216 linux-image-powerpc64-smp 4.4.0.210.216 linux-image-snapdragon 4.4.0.1156.148 linux-image-virtual 4.4.0.210.216 Ubuntu 14.04 ESM: linux-image-4.4.0-1092-aws 4.4.0-1092.96 linux-image-4.4.0-210-generic 4.4.0-210.242~14.04.1 linux-image-4.4.0-210-generic-lpae 4.4.0-210.242~14.04.1 linux-image-4.4.0-210-lowlatency 4.4.0-210.242~14.04.1 linux-image-4.4.0-210-powerpc-e500mc 4.4.0-210.242~14.04.1 linux-image-4.4.0-210-powerpc-smp 4.4.0-210.242~14.04.1 linux-image-4.4.0-210-powerpc64-emb 4.4.0-210.242~14.04.1 linux-image-4.4.0-210-powerpc64-smp 4.4.0-210.242~14.04.1 linux-image-aws 4.4.0.1092.89 linux-image-generic-lpae-lts-xenial 4.4.0.210.183 linux-image-generic-lts-xenial 4.4.0.210.183 linux-image-lowlatency-lts-xenial 4.4.0.210.183 linux-image-powerpc-e500mc-lts-xenial 4.4.0.210.183 linux-image-powerpc-smp-lts-xenial 4.4.0.210.183 linux-image-powerpc64-emb-lts-xenial 4.4.0.210.183 linux-image-powerpc64-smp-lts-xenial 4.4.0.210.183 linux-image-virtual-lts-xenial 4.4.0.210.183 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4916-2 https://ubuntu.com/security/notices/USN-4916-1 https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1924611 Package Information: https://launchpad.net/ubuntu/+source/linux-oem-5.6/5.6.0-1055.59 https://launchpad.net/ubuntu/+source/linux-gke-5.3/5.3.0-1043.46 https://launchpad.net/ubuntu/+source/linux-hwe/5.3.0-74.70 https://launchpad.net/ubuntu/+source/linux-raspi2-5.3/5.3.0-1040.42 https://launchpad.net/ubuntu/+source/linux/4.4.0-210.242 https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1128.142 https://launchpad.net/ubuntu/+source/linux-kvm/4.4.0-1093.102 https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1156.166 . Tackling a significant setback in the Linux kernel impacting numerous Ubuntu distributions and providing solutions.. Ubuntu Kernel Update, Linux Security Notice, Memory Leak Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 21, 2021 Critical Ubuntu
172

Ubuntu 20.04 LTS USN-4712-1 High: Kernel Access Denial Issue

USN-4576-1 introduced a regression in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-4712-1 January 28, 2021 linux regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS Summary: USN-4576-1 introduced a regression in the Linux kernel. Software Description: - linux: Linux kernel Details: USN-4576-1 fixed a vulnerability in the overlay file system implementation in the Linux kernel. Unfortunately, that fix introduced a regression that could incorrectly deny access to overlay files in some situations. This update fixes the problem. We apologize for the inconvenience. Original vulnerability details: Giuseppe Scrivano discovered that the overlay file system in the Linux kernel did not properly perform permission checks in some situations. A local attacker could possibly use this to bypass intended restrictions and gain read access to restricted files. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: linux-image-5.8.0-41-generic 5.8.0-41.46 linux-image-5.8.0-41-generic-64k 5.8.0-41.46 linux-image-5.8.0-41-generic-lpae 5.8.0-41.46 linux-image-5.8.0-41-lowlatency 5.8.0-41.46 linux-image-generic 5.8.0.41.45 linux-image-generic-64k 5.8.0.41.45 linux-image-generic-lpae 5.8.0.41.45 linux-image-lowlatency 5.8.0.41.45 linux-image-oem-20.04 5.8.0.41.45 linux-image-virtual 5.8.0.41.45 Ubuntu 20.04 LTS: linux-image-5.4.0-65-generic 5.4.0-65.73 linux-image-5.4.0-65-generic-lpae 5.4.0-65.73 linux-image-5.4.0-65-lowlatency 5.4.0-65.73 linux-image-generic 5.4.0.65.68 linux-image-generic-lpae 5.4.0.65.68 linux-image-lowlatency 5.4.0.65.68 linux-image-oem 5.4.0.65.68 linux-image-oem-osp1 5.4.0.65.68 linux-image-virtual 5.4.0.65.68 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4712-1 https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1900141, https://ubuntu.com/security/notices/USN-4576-1 Package Information: https://launchpad.net/ubuntu/+source/linux/5.8.0-41.46 https://launchpad.net/ubuntu/+source/linux/5.4.0-65.73 . Ubuntu addresses Linux kernel issues by upgrading specific software packages to improve overall system reliability and efficiency.. Ubuntu Kernel Fix, Linux Access Issue, Security Update. . LinuxSecurity.com Team

Calendar%202 Jan 28, 2021 Ubuntu
172

Ubuntu 20.04 LTS USN-4658-2 Critical: Kernel Regression Fix

USN-4658-1 introduced a regression in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-4658-2 December 13, 2020 linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: USN-4658-1 introduced a regression in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-azure: Linux kernel for Microsoft Azure Cloud systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-kvm: Linux kernel for cloud environments - linux-oracle: Linux kernel for Oracle Cloud systems - linux-raspi: Linux kernel for Raspberry Pi (V8) systems - linux-aws-5.4: Linux kernel for Amazon Web Services (AWS) systems - linux-azure-5.4: Linux kernel for Microsoft Azure cloud systems - linux-gcp-5.4: Linux kernel for Google Cloud Platform (GCP) systems - linux-hwe-5.4: Linux hardware enablement (HWE) kernel - linux-oracle-5.4: Linux kernel for Oracle Cloud systems - linux-raspi-5.4: Linux kernel for Raspberry Pi (V8) systems Details: USN-4658-1 fixed vulnerabilities in the Linux kernel. Unfortunately, that update introduced a regression in the software raid10 driver when used with fstrim that could lead to data corruption. This update fixes the problem. Original advisory details: It was discovered that a race condition existed in the binder IPC implementation in the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-0423) Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen discovered that legacy pairing andsecure-connections pairing authentication in the Bluetooth protocol could allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. A physically proximate attacker could use this to impersonate a previously paired Bluetooth device. (CVE-2020-10135) It was discovered that a race condition existed in the perf subsystem of the Linux kernel, leading to a use-after-free vulnerability. An attacker with access to the perf subsystem could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-14351) It was discovered that the frame buffer implementation in the Linux kernel did not properly handle some edge cases in software scrollback. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-14390) It was discovered that the netfilter connection tracker for netlink in the Linux kernel did not properly perform bounds checking in some situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2020-25211) It was discovered that the Rados block device (rbd) driver in the Linux kernel did not properly perform privilege checks for access to rbd devices in some situations. A local attacker could use this to map or unmap rbd block devices. (CVE-2020-25284) It was discovered that the HDLC PPP implementation in the Linux kernel did not properly validate input in some situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-25643) It was discovered that the GENEVE tunnel implementation in the Linux kernel when combined with IPSec did not properly select IP routes in some situations. An attacker could use this to expose sensitive information (unencrypted network traffic). (CVE-2020-25645) Keyu Man discovered that the ICMP global rate limiter in the Linux kernel could be used to assist in scanning open UDP ports. A remote attacker could use to facilitate attackson UDP based services that depend on source port randomization. (CVE-2020-25705) It was discovered that the framebuffer implementation in the Linux kernel did not properly perform range checks in certain situations. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2020-28915) It was discovered that Power 9 processors could be coerced to expose information from the L1 cache in certain situations. A local attacker could use this to expose sensitive information. (CVE-2020-4788) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: linux-image-5.4.0-1025-raspi 5.4.0-1025.28 linux-image-5.4.0-1030-kvm 5.4.0-1030.31 linux-image-5.4.0-1032-aws 5.4.0-1032.33 linux-image-5.4.0-1032-gcp 5.4.0-1032.34 linux-image-5.4.0-1032-oracle 5.4.0-1032.34 linux-image-5.4.0-1034-azure 5.4.0-1034.35 linux-image-5.4.0-58-generic 5.4.0-58.64 linux-image-5.4.0-58-generic-lpae 5.4.0-58.64 linux-image-5.4.0-58-lowlatency 5.4.0-58.64 linux-image-aws 5.4.0.1032.33 linux-image-azure 5.4.0.1034.32 linux-image-gcp 5.4.0.1032.41 linux-image-generic 5.4.0.58.61 linux-image-generic-lpae 5.4.0.58.61 linux-image-gke 5.4.0.1032.41 linux-image-kvm 5.4.0.1030.28 linux-image-lowlatency 5.4.0.58.61 linux-image-oem 5.4.0.58.61 linux-image-oem-osp1 5.4.0.58.61 linux-image-oracle 5.4.0.1032.29 linux-image-raspi 5.4.0.1025.60 linux-image-raspi2 5.4.0.1025.60 linux-image-virtual 5.4.0.58.61 Ubuntu 18.04 LTS: linux-image-5.4.0-1025-raspi 5.4.0-1025.28~18.04.1 linux-image-5.4.0-1032-aws 5.4.0-1032.33~18.04.1 linux-image-5.4.0-1032-gcp 5.4.0-1032.34~18.04.1 linux-image-5.4.0-1033-oracle 5.4.0-1033.35 linux-image-5.4.0-1034-azure 5.4.0-1034.35~18.04.1 linux-image-5.4.0-58-generic 5.4.0-58.64~18.04.1 linux-image-5.4.0-58-generic-lpae 5.4.0-58.64~18.04.1 linux-image-5.4.0-58-lowlatency 5.4.0-58.64~18.04.1 linux-image-aws 5.4.0.1032.17 linux-image-azure 5.4.0.1034.16 linux-image-gcp 5.4.0.1032.20 linux-image-generic-hwe-18.04 5.4.0.58.64~18.04.53 linux-image-generic-lpae-hwe-18.04 5.4.0.58.64~18.04.53 linux-image-lowlatency-hwe-18.04 5.4.0.58.64~18.04.53 linux-image-oem 5.4.0.58.64~18.04.53 linux-image-oem-osp1 5.4.0.58.64~18.04.53 linux-image-oracle 5.4.0.1033.16 linux-image-raspi-hwe-18.04 5.4.0.1025.29 linux-image-snapdragon-hwe-18.04 5.4.0.58.64~18.04.53 linux-image-virtual-hwe-18.04 5.4.0.58.64~18.04.53 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4658-2 https://ubuntu.com/security/notices/USN-4658-1 https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1907262 Package Information: https://launchpad.net/ubuntu/+source/linux/5.4.0-58.64 https://launchpad.net/ubuntu/+source/linux-aws/5.4.0-1032.33 https://launchpad.net/ubuntu/+source/linux-azure/5.4.0-1034.35 https://launchpad.net/ubuntu/+source/linux-gcp/5.4.0-1032.34 https://launchpad.net/ubuntu/+source/linux-kvm/5.4.0-1030.31 https://launchpad.net/ubuntu/+source/linux-oracle/5.4.0-1032.34 https://launchpad.net/ubuntu/+source/linux-raspi/5.4.0-1025.28 https://launchpad.net/ubuntu/+source/linux-aws-5.4/5.4.0-1032.33~18.04.1 https://launchpad.net/ubuntu/+source/linux-azure-5.4/5.4.0-1034.35~18.04.1 https://launchpad.net/ubuntu/+source/linux-gcp-5.4/5.4.0-1032.34~18.04.1 https://launchpad.net/ubuntu/+source/linux-hwe-5.4/5.4.0-58.64~18.04.1 https://launchpad.net/ubuntu/+source/linux-oracle-5.4/5.4.0-1033.35 https://launchpad.net/ubuntu/+source/linux-raspi-5.4/5.4.0-1025.28~18.04.1 . Important patch released to fix security flaws in the Ubuntu kernel affecting device reliability and performance consistency. Please apply updates.. Linux Kernel Update, Ubuntu Security Advisory, Data Integrity Protection. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 13, 2020 Critical Ubuntu
172

Ubuntu 20.04 LTS USN-4367-2: Critical Kernel Regression Fix

USN-4367-1 introduced a regression in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-4367-2 May 28, 2020 linux regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: USN-4367-1 introduced a regression in the Linux kernel. Software Description: - linux: Linux kernel Details: USN-4367-1 fixed vulnerabilities in the 5.4 Linux kernel. Unfortunately, that update introduced a regression in overlayfs. This update corrects the problem. We apologize for the inconvenience. Original advisory details: It was discovered that the btrfs implementation in the Linux kernel did not properly detect that a block was marked dirty in some situations. An attacker could use this to specially craft a file system image that, when unmounted, could cause a denial of service (system crash). (CVE-2019-19377) It was discovered that the linux kernel did not properly validate certain mount options to the tmpfs virtual memory file system. A local attacker with the ability to specify mount options could use this to cause a denial of service (system crash). (CVE-2020-11565) It was discovered that the block layer in the Linux kernel contained a race condition leading to a use-after-free vulnerability. A local attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2020-12657) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: linux-image-5.4.0-33-generic 5.4.0-33.37 linux-image-5.4.0-33-generic-lpae 5.4.0-33.37 linux-image-5.4.0-33-lowlatency 5.4.0-33.37 linux-image-generic 5.4.0.33.38 linux-image-generic-lpae 5.4.0.33.38 linux-image-lowlatency 5.4.0.33.38 linux-image-oem 5.4.0.33.38 linux-image-oem-osp1 5.4.0.33.38 linux-image-virtual 5.4.0.33.38 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4367-2 https://ubuntu.com/security/notices/USN-4367-1 https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1879690 Package Information: https://launchpad.net/ubuntu/+source/linux/5.4.0-33.37 . Uncover the kernel flaws in Ubuntu 20.04 LTS following USN-4367-1, which caused significant problems, and learn how these obstacles were addressed successfully.. Linux Kernel Update, Ubuntu Security Notice, Overlayfs Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 28, 2020 Critical Ubuntu
172

Ubuntu 18.04 LTS USN-3718-1: Fix for Moderate Boot Failures Now Available

A regression that caused boot failures was fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-3718-1 July 21, 2018 linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: A regression that caused boot failures was fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-azure: Linux kernel for Microsoft Azure Cloud systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-kvm: Linux kernel for cloud environments - linux-oem: Linux kernel for OEM processors Details: USN-3695-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04 LTS. Unfortunately, the fix for CVE-2018-1108 introduced a regression where insufficient early entropy prevented services from starting, leading in some situations to a failure to boot, This update addresses the issue. We apologize for the inconvenience. Original advisory details: Jann Horn discovered that the Linux kernel's implementation of random seed data reported that it was in a ready state before it had gathered sufficient entropy. An attacker could use this to expose sensitive information. (CVE-2018-1108) Wen Xu discovered that the ext4 file system implementation in the Linux kernel did not properly initialize the crc32c checksum driver. A local attacker could use this to cause a denial of service (system crash). (CVE-2018-1094) It was discovered that the cdrom driver in the Linux kernel contained an incorrect bounds check. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2018-10940) Wen Xu discovered that the ext4 file system implementation in the Linux kernel did not properly validate xattr sizes. A local attacker could use this to causea denial of service (system crash). (CVE-2018-1095) Jann Horn discovered that the 32 bit adjtimex() syscall implementation for 64 bit Linux kernels did not properly initialize memory returned to user space in some situations. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2018-11508) It was discovered that an information leak vulnerability existed in the floppy driver in the Linux kernel. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2018-7755) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: linux-image-4.15.0-1014-gcp 4.15.0-1014.14 linux-image-4.15.0-1016-aws 4.15.0-1016.16 linux-image-4.15.0-1016-kvm 4.15.0-1016.16 linux-image-4.15.0-1018-azure 4.15.0-1018.18 linux-image-4.15.0-29-generic 4.15.0-29.31 linux-image-4.15.0-29-generic-lpae 4.15.0-29.31 linux-image-4.15.0-29-lowlatency 4.15.0-29.31 linux-image-4.15.0-29-snapdragon 4.15.0-29.31 linux-image-aws 4.15.0.1016.16 linux-image-azure 4.15.0.1018.18 linux-image-gcp 4.15.0.1014.16 linux-image-generic 4.15.0.29.31 linux-image-generic-lpae 4.15.0.29.31 linux-image-gke 4.15.0.1014.16 linux-image-kvm 4.15.0.1016.16 linux-image-lowlatency 4.15.0.29.31 linux-image-oem 4.15.0.1012.14 linux-image-snapdragon 4.15.0.29.31 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform thisas well. References: https://ubuntu.com/security/notices/USN-3718-1 https://bugs.launchpad.net/ubuntu/+bug/1779827, https://ubuntu.com/security/notices/USN-3695-1 Package Information: https://launchpad.net/ubuntu/+source/linux/4.15.0-29.31 https://launchpad.net/ubuntu/+source/linux-aws/4.15.0-1016.16 https://launchpad.net/ubuntu/+source/linux-azure/4.15.0-1018.18 https://launchpad.net/ubuntu/+source/linux-gcp/4.15.0-1014.14 https://launchpad.net/ubuntu/+source/linux-kvm/4.15.0-1016.16 https://launchpad.net/ubuntu/+source/linux-oem/4.15.0-1012.15 . An update addressing the Linux kernel regression leading to boot issues in Ubuntu 20.04 LTS is now available, please implement it swiftly.. Ubuntu Kernel Update, Boot Failure Fix, Linux Kernel Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 21, 2018 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200