Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Canonical has published Linux kernel updates for all of its supported Ubuntu releases to address several security vulnerabilities discovered in the upstream Linux kernels that could lead to privilege escalation attacks, the execurtion of arbitrary code, the exposure of sensitive information and system crash. Update now! . The new Ubuntu kernel security updates are available for Ubuntu 21.04 (Hirsute Hippo), Ubuntu 20.10 (Groovy Gorilla), Ubuntu 20.04 LTS (Focal Fossa), Ubuntu 18.04 LTS (Bionic Beaver), as well as as for the ESM (Extended Security Maintenance) branches of Ubuntu 16.04 and Ubuntu 14.04. Patched in these kernel updates is CVE-2021-33909 , a 7-years-old privilege escalation flaw discovered by Qualys Research Labs in Linux kernel’s file system layer, which could allow an unprivileged user to create, mount, and then delete a large directory structure of over 1GB in size. This flaw affected all supported Ubuntu releases. The link for this article located at 9 to 5 Linux is no longer available. . Canonical's latest kernel revisions tackle numerous vulnerabilities in multiple Ubuntu variants, enhancing both security measures and system stability.. Ubuntu Kernel Updates, Privilege Escalation Fixes, Security Enhancements, System Stability. . Brittany Day
Canonical has released a new Linux kernel security update for its Ubuntu 20.10 (Groovy Gorilla) and Ubuntu 20.04 LTS (Focal Fossa) systems to address a single security vulnerability that could allow a local attacker to crash the system by causing a denial of service (DoS) or run programs as an administrator (root). . The vulnerability (CVE-2021-26708) was discovered by Alexander Popov as multiple race conditions in Linux kernel’s AF_VSOCK implementation, which could allow a local attacker to crash the system by causing a denial of service or run programs as an administrator (root). This security issue affects all Ubuntu 20.10 and Ubuntu 20.04 LTS systems running the Linux 5.8 kernel on all supported architectures, including 64-bit, Raspberry Pi (V8) systems, OEM systems, cloud environments (KVM), as well as Amazon Web Services (AWS), Google Cloud Platform (GCP), Oracle Cloud, and Microsoft Azure Cloud systems. The link for this article located at 9 to 5 Linux is no longer available. . This patch resolves a vulnerability in the kernel that enables local malicious users to compromise and destabilize Ubuntu installations.. Ubuntu Update,Kernal Security Patch,Denial Of Service Attack,Local Exploit,System Crash. . Brittany Day
Canonical has published a new security advisory today where the company behind the popular Ubuntu Linux operating system apologizes for a regression introduced by the latest Intel microcode firmware update. . On November 12th, 2019, Canonical publishedimportant kernel security updatesfor all supportedUbuntuLinux releases to address two flaws (CVE-2019-11135 and CVE-2019-11139) discovered by various security researchers in Intel processors using Transactional Synchronization Extensions (TSX), as well as on certain Intel Xeon processors. While the first vulnerability could allow a local attacker to expose sensitive information, such as memory contents that were previously stored in microarchitectural buffers, the second issue could allow a local privileged attacker to cause a denial of service (system crash). The intel-microcode version that caused the regression was 3.20191112. The link for this article located at Softpedia News is no longer available. . Canonical has issued a new security advisory highlighting a microcode regression in Intel processors, impacting Ubuntu systems with Skylake architecture. Canonical Updates, Ubuntu Security, Intel Microcode Issues, Skylake CPUs, Kernel Patches. . Brittany Day
Are you an Ubuntu user? Canonical has released a new batch of Linux kernel security updates for all of its supported Ubuntu Linux releases to address the latest Intel CPU vulnerabilities, as well as other important flaws. Learn more: . Asannouncedthe other day, Canonical was quick to respond to the latest security vulnerabilities affecting Intel CPU microarchitectures, so they now published Linux kernel updates to mitigate them. These are CVE-2019-11135 , CVE-2018-12207 , CVE-2019-0154 , and CVE-2019-0155 , which could allow local attackers to either expose sensitive information or possibly elevate privileges or cause a denial of service. On top of these security issues affecting Intel CPUs, the new Linux kernel security updates also address three vulnerabilities ( CVE-2019-15791 , CVE-2019-15792 , and CVE-2019-15793 ) discovered by Google Project Zero's Jann Horn in the shiftfs implementation, which could allow a local attacker to either execute arbitrary code, cause a denial of service (system crash), or bypass DAC permissions. The link for this article located at Softpedia News is no longer available. . Canonical addresses Intel CPU vulnerabilities with kernel updates. Protect sensitive data against potential exploits.. ubuntu, canonical, released, batch, linux, kernel, security, updates. . Brittany Day
Sun Microsystems has issued a security update intended for computers running Sun Solaris 10 operating system. The update patches a security vulnerability that could cause kernel panic by sending one false ICMP request. The vendor does not disclose the conditions required for the attack to occur, but in its security advisory, Sun suggest testing whether a system responds to ICMP echo requests using a normal ping utility. . The link for this article located at ITObserver is no longer available. . An essential security patch for Sun Solaris 10 resolves a kernel crash flaw triggered by a harmful ICMP message.. Sun Solaris, ICMP request, Kernel panic, Security update. . LinuxSecurity.com Team
A newly discovered security hole in Linux, published on an open source website, has raised questions about how Linux security issues should be handled. The vulnerability could allow malicious users to bring down Linux machines with just 24 lines of code, which are available from several open source websites and internet news groups. . . .. A newly discovered security hole in Linux, published on an open source website, has raised questions about how Linux security issues should be handled. The vulnerability could allow malicious users to bring down Linux machines with just 24 lines of code, which are available from several open source websites and internet news groups. The lines of C code, dubbed "evil.c", can crash several versions of the Linux kernel, including 2.4.2 and 2.6 variations, locking whole systems, said a bulletin by ¯yvind S¾ther of linuxreviews .org, one of the websites that has published the code. The availability of the source code will focus attention on how open source security should be co-ordinated, according to Graham Taylor, principal analyst at Ovum. "At the moment there is no central point of co-ordination for Linux security, which could lead to anarchic support," he said. The link for this article located at computerweekly.com is no longer available. . The recent identification of a vulnerability in the Linux operating system has raised alarms regarding the effectiveness of collaboration in resolving security threats.. Linux Kernel Risk, Open Source Vulnerability, System Stability Threat. . LinuxSecurity.com Team
"The program works on any normal user account, and root access is not required," Sæther reported. "This exploit has been reported used to take down several 'lame free-shell providers' servers. [Running code you know will damage a system intentionally and hacking in general] is illegal in most parts of the world and strongly discouraged." . . .. A Linux bug was recently uncovered by a young Norwegian programmer that, when exploited by a simple C program, could crash most Linux 2.4 or 2.6 distributions running on an x86 architecture. "Using this exploit to crash Linux systems requires the (ab)user to have shell access or other means of uploading and running the program--like cgi-bin and FTP access," reports the discoverer, Øyvind Sæther. "The program works on any normal user account, and root access is not required," Sæther reported. "This exploit has been reported used to take down several 'lame free-shell providers' servers. [Running code you know will damage a system intentionally and hacking in general] is illegal in most parts of the world and strongly discouraged." The link for this article located at eWeek is no longer available. . An issue discovered in the Linux kernel by a developer can be leveraged to bring down x86 systems without requiring administrative privileges.. Linux Bug, User Account Exploit, System Crash. . LinuxSecurity.com Team
A bug lets a simple C program crash the kernel, effectively locking the whole system. It affects both 2.4.2x and 2.6.x kernels on the x86 architecture, and does not require root access. . . .. This bug is confirmed to be present when the code is compiled with GCC version 3.0, 3.1, 3.2, 3.3 and 3.3.2 and used on Linux kernel versions 2.4.2x and 2.6.x on x86 and amd64 systems. The Crashing Kernels Minor numbers are versions verified, this is just the top the iceberg: * Linux 2.6.x o 2.6.7-rc2 o 2.6.6 (vanilla) o 2.6.6-rc1 SMP (varified by blaise) o 2.6.6 SMP (verified by riven) o 2.6.5-gentoo (verified by RatiX) o 2.6.5-mm6 - (verified by Mariux) o 2.6.5 (fedora core 2 vanilla) * Linux 2.4.2x o 2.4.26 vanilla o 2.4.26, grsecurity 2.0 config o 2.4.26-rc1 vanilla o 2.4.26-gentoo-r1 o 2.4.22 o 2.4.22-1.2188 Fedora FC1 Kernel o 2.4.18-bf2.4 (debian woody vanilla) The link for this article located at linuxreviews.org is no longer available. . A newly discovered vulnerability enables straightforward C applications to cause system failures on certain Linux distributions and hardware configurations.. Kernel Exploit, GCC Bug, Linux Kernel Issue, System Security, X86 Systems. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.