Overview
Alex and Camila discuss security update management strategies after a recent
outage at Datadog was attributed to a security update for systemd on Ubuntu,
plus we look at security vulnerabilities in the Linux kernel, OpenStack,
Synapse, OpenJDK and more.
This week in Ubuntu Security Updates
[USN-6069-1] Linux kernel (Raspberry Pi) vulnerability (01:01)
1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)CVE-2023-1829 5.4 raspi in 20.04 / 18.04 HWE[USN-6058-1] Linux kernel vulnerability from Episode 194UAF in Traffic-Control Index (TCINDEX) filter from April this year - fixsimply removes this classifier from the kernel
[USN-6070-1] Linux kernel vulnerabilities (01:37)
2 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)CVE-2023-1872 CVE-2023-1829 5.15 raspi in 22.04, Azure FDE in 20.04TCINDEX UAF plus UAF in io_uring[USN-6071-1] Linux kernel (OEM) vulnerabilities (01:58)
12 CVEs addressed in Jammy (22.04 LTS)CVE-2023-26545 CVE-2023-23455 CVE-2023-1859 CVE-2022-4662 CVE-2022-4095 CVE-2022-40307 CVE-2022-3586 CVE-2022-3303 CVE-2022-2590 CVE-2023-0386 CVE-2023-0468 CVE-2023-1829 5.17UAFs in TCINDEX, io_uring, logic issue in OverlayFS([USN-6057-1] Linux kernel
(Intel IoTG) vulnerabilities from Episode 194), race-condition in handling
of handling of copy-on-write read-only shared memory mappings - unpriv user
could then get write on these read-only mappings -> privesc
[USN-6072-1] Linux kernel (OEM) vulnerabilities (02:31)
6 CVEs addressed in Jammy (22.04 LTS)CVE-2023-26545 CVE-2023-23455 CVE-2023-1859 CVE-2023-0386 CVE-2023-0468 CVE-2023-1829 6.0UAFs in TCINDEX, io_uring, logic issue in OverlayFS[USN-6079-1] Linux kernel vulnerabilities (02:49)
25 CVEs addressed in Jammy (22.04 LTS), Kinetic (22.10)CVE-2023-1118 CVE-2023-32269 CVE-2023-26544 CVE-2023-23455 CVE-2023-23454 CVE-2023-2162 CVE-2023-21106 CVE-2023-21102 CVE-2023-1652 CVE-2023-1513 CVE-2023-1078 CVE-2023-1075 CVE-2023-1074 CVE-2023-1073 CVE-2023-0459 CVE-2023-0458 CVE-2023-0394 CVE-2023-0210 CVE-2022-48424 CVE-2022-48423 CVE-2022-4842 CVE-2022-4129 CVE-2022-3707 CVE-2022-36280 CVE-2022-27672 5.19 22.10 / 22.04 Azure[USN-6080-1] Linux kernel vulnerabilities (02:55)
10 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)CVE-2023-1118 CVE-2023-32269 CVE-2023-2162 CVE-2023-20938 CVE-2023-1513 CVE-2023-1078 CVE-2023-1075 CVE-2023-0459 CVE-2022-3707 CVE-2022-27672 5.15 22.04 / 20.04 HWE[USN-6081-1] Linux kernel vulnerabilities (03:02)
5 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS)CVE-2023-1118 CVE-2023-32269 CVE-2023-2162 CVE-2023-1513 CVE-2023-0459 4.15 18.04 GA / 16.04 AWS (Ubuntu Pro)[USN-6073-1, USN-6073-2, USN-6073-3, USN-6073-4] Cinder, Glance Store, Nova, os-brick vulnerability (03:14)
1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Kinetic (22.10), Lunar (23.04)CVE-2023-2088 Inconsistency between Cinder (block storage service of OpenStack) and Nova(compute / virtual server provisioning) could result in storage volumes being
attached to the wrong compute instances - would happen when trying to detach a
volume from an instance
Lots of interacting components, all need a consistent view of the system etc[USN-6073-5] Nova regression
Affecting Focal (20.04 LTS)Above update meant that in some circumstances Nova would be unable to detachvolumes from instances
[USN-6074-1] Firefox vulnerabilities (04:15)
11 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)CVE-2023-32209 CVE-2023-32208 CVE-2023-32206 CVE-2023-32216 CVE-2023-32215 CVE-2023-32213 CVE-2023-32212 CVE-2023-32211 CVE-2023-32210 CVE-2023-32207 CVE-2023-32205 113.0[USN-6074-2] Firefox regressions (04:27)
11 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)CVE-2023-32209 CVE-2023-32208 CVE-2023-32206 CVE-2023-32216 CVE-2023-32215 CVE-2023-32213 CVE-2023-32212 CVE-2023-32211 CVE-2023-32210 CVE-2023-32207 CVE-2023-32205 113.0.1 from upstream[USN-6075-1] Thunderbird vulnerabilities (04:36)
7 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Jammy (22.04 LTS), Kinetic (22.10), Lunar (23.04)CVE-2023-32206 CVE-2023-32215 CVE-2023-32213 CVE-2023-32212 CVE-2023-32211 CVE-2023-32207 CVE-2023-32205 102.11.0[USN-6060-3] MySQL regression (05:02)
Affecting Focal (20.04 LTS), Jammy (22.04 LTS), Kinetic (22.10), Lunar (23.04)[USN-6060-1, USN-6060-2] MySQL vulnerabilities from Episode 194Latest upstream release 8.0.33 introduced a regression on 32-bit ARM (armhf) -would crash on startup - to fix, reverted an upstream commit which was
introduced to help with performance of atomic operations
[USN-6076-1] Synapse vulnerabilities (05:39)
7 CVEs addressed in Bionic (18.04 LTS)CVE-2018-16515 CVE-2019-5885 CVE-2018-12423 CVE-2019-11842 CVE-2018-10657 CVE-2018-12291 CVE-2019-18835 Matrix homeserverVarious issues - signature checking on APIs, failure to properly apply eventvisibility rules, DoS - exploited in the wild, insufficient randomness when
generating random IDs made them guessable, ability for unauthorised users to
hijack rooms, more predictable randomness which could allow remote attackers
to impersonate users, event spoofing due to improper signature validation -
some of these require to be the admin of a room or to have a malicious server
etc - but since Matrix is federated, this is not so implausible
[USN-6078-1] libwebp vulnerability (06:38)
1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Jammy (22.04 LTS), Kinetic (22.10), Lunar (23.04)CVE-2023-1999 Double free when handling crafted content[USN-6077-1] OpenJDK vulnerabilities (06:45)
7 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Jammy (22.04 LTS), Kinetic (22.10), Lunar (23.04)CVE-2023-21968 CVE-2023-21967 CVE-2023-21954 CVE-2023-21939 CVE-2023-21938 CVE-2023-21937 CVE-2023-21930 Latest upstream point releasesMost Ubuntu releases support more then 1 version of OpenJDK - this update isfor OpenJDK versions 20, 17, 11 and 8 across the various Ubuntu releases
[USN-6082-1] EventSource vulnerability (07:02)
1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Jammy (22.04 LTS)CVE-2022-1650 EventSource client for NodeJS - info leak - could leak cookies andauthorisation headers to third party applications - but should have been
sanitising headers to avoid this as per same-origin-policy
Goings on in Ubuntu Security Community
Datadog outage and management of security updates (07:32)
https://newsletter.pragmaticengineer.com/p/inside-the-datadog-outageAlex and Camila discuss a recent outage at Datadog on their Ubuntu systemsthat was triggered by a security update for systemd and the pros and cons of
automatic security updates plus other approaches which can be taken to allow
updates to be applied in a more controlled manner
https://ubuntu.com/blog/3-ways-to-apply-security-patches-in-linuxGet in contact
#ubuntu-security on the Libera.Chat IRC networkubuntu-hardened mailing listSecurity section on discourse.ubuntu.com@[email protected], @ubuntu_sec on twitter