Have you heard about the Universal Serial Bus (USB) - a portable, flexible, and modular framework for fuzz testing USB drivers? It can be used to identify vulnerabilities in the USB driver stacks of widely used operating systems, including Linux. . The Universal Serial Bus (USB) connects external devices to a host. This interface exposes the OS kernels and device drivers to attacks by malicious devices. To help detect such vulnerabilities, EPFL researchers have come up with a new security tool called USBFuzz to identify vulnerabilities in the USB driver stacks of widely used operating systems, including Linux, Windows, and macOS. . Explore USBGuard, a utility aimed at detecting weaknesses in USB driver frameworks across operating systems such as Windows.. USB Security, Bug Detection Tool, Fuzz Testing Framework, Linux Security. . LinuxSecurity.com Team
Canonical has released the first Linux kernel security update for all of its supported Ubuntu Linux releases to address more than 30 security vulnerabilities. Learn more about this update and its implications for Ubuntu users: . AffectingUbuntu19.10 and Ubuntu 18.04 LTS systems using Linux kernel 5.3, the new security update addresses two heap-based buffer overflows in the Marvell WiFi-Ex and Marvell Libertas WLAN drivers, as well as flaws in the Fujitsu ES network device driver, Broadcom V3D DRI driver, Mellanox Technologies Innova driver, and Mellanox Technologies ConnectX driver. Additionally, issues were resolved in Linux kernel's Intel WiMAX 2400 driver, Geschwister Schneider USB CAN interface driver, netlink-based 802.11 configuration interface, event tracing subsystem, the driver for memoryless force-feedback input devices, Microchip CAN BUS Analyzer driver, PEAK-System Technik USB driver, ALSA timer implementation, and DesignWare USB3 controller driver. The link for this article located at Softpedia News is no longer available. . Several Ubuntu versions have been issued essential kernel updates correcting over 30 vulnerabilities linked to hardware drivers and memory buffer overflows.. Ubuntu Kernel Update, Linux Security, Driver Vulnerabilities, Canonical Security, Heap Overflow Fixes. . LinuxSecurity.com Team
Serious security bugs in key parts of the latest Linux code have been fixed, but some small glitches have been introduced, according to a recent scan. In December, Coverity looked at version 2.6.9 of the Linux kernel, the heart of the open-source operating system, and found six critical defects in the core file system and networking code. In July, the code analysis company scanned the latest version of the Linux kernel, version 2.6.12, and found no such programming errors, Coverity CEO Seth Hallem said. . However, 1,008 defects were discovered in other parts of version 2.6.12. These coding problems, which could indicate security flaws, rest mainly in drivers, Hallem said. That's a slight increase compared with the earlier analysis, when 985 total defects were found, according to San Francisco-based Coverity. The link for this article located at ZDNet India is no longer available. . Latest assessments show that although essential flaws in the Linux kernel have been addressed, fresh issues have surfaced, leading to worries.. Linux Kernel Defects, Code Analysis, Open Source Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.