Ubuntu Security Podcast

Ubuntu Security Podcast

By Ubuntu Security TeamTechnology
Download on the App Store

Ubuntu Security Podcast episodes

  • Episode 123
    Overview

    Is npm audit more harm than good? Plus this week we look at security

    updates for DjVuLibre, libuv, PHP and more.

    This week in Ubuntu Security Updates

    8 unique CVEs addressed

    [USN-4905-2] X.Org X Server vulnerability [00:42]
    • 1 CVEs addressed in Trusty ESM (14.04 ESM)
      • CVE-2021-3472
      • Episode 112 - Local user (X client) could crash the server via Xinput
      • extension and ChangeFeedbackControl request - integer underflow -> heap
        buffer overflow
        [USN-5005-1] DjVuLibre vulnerability [01:26]
        • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
          • CVE-2021-3630
          • OOB write via crafted djvu file -> crash -> DoS, RCE
          • [USN-5007-1] libuv vulnerability [01:53]
            • 1 CVEs addressed in Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
              • CVE-2021-22918
              • Async event handling library - used by nodejs and others - supports async
              • handling TCP/UDP sockets, DNS resolution, file system operations etc
              • OOB read when converting strings to ASCII -> can be triggered via calls
              • to uv_getaddrinfo() which are done by clients who handle TCP/UDP sockets
                async (ie nodejs, Julia,, BIND etc)
                [USN-5006-1] PHP vulnerabilities [03:04]
                • 5 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                  • CVE-2021-21705
                  • CVE-2021-21704
                  • CVE-2021-21702
                  • CVE-2020-7071
                  • CVE-2020-7068
                  • UAF in PHAR archive handling - generally these are trusted so low impact
                  • mishandling of URLs with embedded passwords - unspecified impact but
                  • could misparse the URL and cause unwanted behaviour
                  • Mishandling of XML when processing SOAP server responses -> NULL ptr
                  • deref (so malicious server could trigger a crash) -> DoS
                  • Ability to bypass Sever Side Request Forgery (SSRF) protections in
                  • FILTER_VALIDATE_URL
                    Goings on in Ubuntu Security Community
                    npm audit broken by design? [04:13]
                    • https://overreacted.io/npm-audit-broken-by-design/
                    • Ubuntu Security Podcast on break for next 2 weeks [07:56]
                      Get in contact
                      • #ubuntu-security on the Libera.Chat IRC network
                      • ubuntu-hardened mailing list
                      • Security section on discourse.ubuntu.com
                      • @ubuntu_sec on twitter
                      • 9 min
                      • Episode 122
                        Overview

                        This week we look at some new Linux kernel security features including the

                        Landlock LSM and Core Scheduling plus we cover security updates for
                        RabbitMQ, Ceph, Thunderbird and more.

                        This week in Ubuntu Security Updates

                        46 unique CVEs addressed

                        [USN-5004-1] RabbitMQ vulnerabilities [00:44]
                        • 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                          • CVE-2021-22116
                          • CVE-2019-11287
                          • AMQP server written in Erlang
                          • Possible to cause the server to consume excessive memory by sending large
                          • values in the X-Reason HTTP header - resource exhaustion - DoS
                          • Possible infinite loop - failed to perform sufficient validation - DoS
                          • [USN-4998-1] Ceph vulnerabilities [01:38]
                            • 7 CVEs addressed in Focal (20.04 LTS), Groovy (20.10)
                              • CVE-2021-3531
                              • CVE-2021-3524
                              • CVE-2021-3509
                              • CVE-2021-20288
                              • CVE-2020-27839
                              • CVE-2020-27781
                              • CVE-2020-25678
                              • May log passwords in clear
                              • Exposure of user credentials to unprivileged users in particular
                              • configurations
                              • 2 different XSS in ceph-dashboard
                              • Possible to authenticate as another user since could reuse session keys
                              • Crash radosgw through malicious GET requests with crafted swift URLs ->
                              • DoS
                                [USN-4995-2] Thunderbird vulnerabilities [02:22]
                                • 20 CVEs addressed in Bionic (18.04 LTS)
                                  • CVE-2021-29957
                                  • CVE-2021-29956
                                  • CVE-2021-29949
                                  • CVE-2021-29948
                                  • CVE-2021-24002
                                  • CVE-2021-23995
                                  • CVE-2021-23993
                                  • CVE-2021-23992
                                  • CVE-2021-23991
                                  • CVE-2021-23984
                                  • CVE-2021-29967
                                  • CVE-2021-29946
                                  • CVE-2021-29945
                                  • CVE-2021-23999
                                  • CVE-2021-23998
                                  • CVE-2021-23994
                                  • CVE-2021-23987
                                  • CVE-2021-23982
                                  • CVE-2021-23981
                                  • CVE-2021-23961
                                  • Episode 121
                                  • 78.11.0
                                  • [USN-5000-2] Linux kernel (KVM) vulnerabilities [02:48]
                                    • 15 CVEs addressed in Focal (20.04 LTS)
                                      • CVE-2021-3506
                                      • CVE-2021-33034
                                      • CVE-2021-32399
                                      • CVE-2021-31829
                                      • CVE-2021-23134
                                      • CVE-2021-23133
                                      • CVE-2020-26147
                                      • CVE-2020-26145
                                      • CVE-2020-26141
                                      • CVE-2020-26139
                                      • CVE-2020-24588
                                      • CVE-2020-24587
                                      • CVE-2020-24586
                                      • CVE-2021-33200
                                      • CVE-2021-3609
                                      • Episode 121
                                      • KVM kernel for 20.04 LTS
                                      • 2 high priority privesc issues fixed - CAN BCM UAFs, eBPF OOB write -
                                      • plus various others too
                                        [USN-4997-2] Linux kernel (KVM) vulnerabilities
                                        • 17 CVEs addressed in Hirsute (21.04)
                                          • CVE-2021-3543
                                          • CVE-2021-3506
                                          • CVE-2021-33034
                                          • CVE-2021-32399
                                          • CVE-2021-31829
                                          • CVE-2021-31440
                                          • CVE-2021-23134
                                          • CVE-2021-23133
                                          • CVE-2020-26147
                                          • CVE-2020-26145
                                          • CVE-2020-26141
                                          • CVE-2020-26139
                                          • CVE-2020-24588
                                          • CVE-2020-24587
                                          • CVE-2020-24586
                                          • CVE-2021-33200
                                          • CVE-2021-3609
                                          • Goings on in Ubuntu Security Community
                                            Landlock released in 5.13 kernel [03:49]
                                            • Allows unprivileged processes to sandbox themselves - currently only
                                            • supports file paths - so can specify read/write of files/dirs etc
                                            • Took 34 revisions of the patch set and it evolved significantly over
                                            • time - was originally based on attaching BPF programs to LSM hooks but
                                              given how fraught unprivileged BPF has been this was NACKd and instead
                                              went with a new approach based on a custom API with brand new system
                                              calls to support it
                                            • API is quite low-level compared to say how AppArmor policy is specified
                                            • so will be interesting to see if there becomes a liblandlock in the
                                              future to make this kind of thing easier (cf. libseccomp for doing
                                              seccomp BPF programs etc)
                                            • https://lwn.net/Articles/859908/
                                            • https://landlock.io/
                                            • Core Scheduling merged for 5.14 kernel [06:43]
                                              • SMT siblings share lots of microarchitectural state like L1D cache etc -
                                              • various micro-arch attacks could only be mitigated across different SMT
                                                cores - so processes which shared the same core could snoop on each other
                                                (eg. L1TF - in the context of virtualisation, a malicious guest VM could
                                                snoop on the L1D contents of another VM on the same SMT core) - so the
                                                only option was to disable SMT which brings a big performance hit
                                              • Solution is core scheduling - ie. make the schedular aware of and respect
                                              • SMT threads on the same core
                                              • Tag processes via cgroups - this defines the trust boundaries - processes
                                              • in the same tagged cgroup share a trust boundary and can be scheduled on
                                                sibling SMT cores - and by default all processes are in the same group
                                              • Uses prctl() to allow setting / copying these - and can only set these on
                                              • processes which you can ptrace
                                              • https://lwn.net/Articles/820321/
                                              • https://www.phoronix.com/scan.php?page=news_item&px=Core-Scheduling-Linux-Close
                                              • Get in contact
                                                • #ubuntu-security on the Libera.Chat IRC network
                                                • ubuntu-hardened mailing list
                                                • Security section on discourse.ubuntu.com
                                                • @ubuntu_sec on twitter
                                                • 11 min
                                                • Episode 121
                                                  Overview

                                                  Ubuntu One opens up two-factor authentication for all, plus we cover

                                                  security updates for Nettle, libxml2, GRUB2, the Linux kernel and more.

                                                  This week in Ubuntu Security Updates

                                                  73 unique CVEs addressed

                                                  [USN-4989-2] BlueZ vulnerabilities [00:57]
                                                  • 2 CVEs addressed in Xenial ESM (16.04 ESM)
                                                    • CVE-2020-27153
                                                    • CVE-2020-26558
                                                    • Episode 120 - bluetooth spec issue around pairing takeover plus a
                                                    • possible double-free in gattool that is likely quite hard to exploit due
                                                      to time window race between the two free() calls
                                                      [USN-4990-1] Nettle vulnerabilities [01:27]
                                                      • 2 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                        • CVE-2018-16869
                                                        • CVE-2021-3580
                                                        • Low level crypto library used by lots of packages - chrony, dnsmasq,
                                                        • lighttpd, qemu, squid, supertuxkart
                                                        • Last covered just a few weeks ago in Episode 112 - is someone taking a
                                                        • closer look at this library?
                                                        • Bleichenbacher type side-channel base on a padding oracle attack in
                                                        • endian conversion of RSA decrypted PKCS#1 v1.5 data - requires to run a
                                                          process on the same physical core as the victim - but could then allow
                                                          the plaintext to be extracted
                                                        • RSA algo possible crash which is able to be triggered on decryption of
                                                        • manipulated ciphertext
                                                        • Changes required for both of these are too intrusive to backport for the
                                                        • older releases (e.g. 16.04 ESM) so suggest to upgrade to a newer Ubuntu
                                                          release if you are using nettle on these older releases and are concerned
                                                          about possible attacks
                                                          [USN-4991-1] libxml2 vulnerabilities [03:08]
                                                          • 8 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                            • CVE-2021-3541
                                                            • CVE-2021-3537
                                                            • CVE-2021-3518
                                                            • CVE-2021-3516
                                                            • CVE-2021-3517
                                                            • CVE-2020-24977
                                                            • CVE-2019-20388
                                                            • CVE-2017-8872
                                                            • Crafted XML could possibly trigger crash -> DoS or RCE
                                                            • [USN-4992-1] GRUB 2 vulnerabilities [03:33]
                                                              • 6 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10)
                                                                • CVE-2021-20233
                                                                • CVE-2021-20225
                                                                • CVE-2020-27779
                                                                • CVE-2020-27749
                                                                • CVE-2020-25632
                                                                • CVE-2020-14372
                                                                • Episode 106 - BootHole 2021 updates published to the security pocket
                                                                • Vulns included the ability to load ACPI tables, UAF in rmmod, buffer
                                                                • overflow in command-line parser, cutmem command boot locking bypass, heap
                                                                  buffer overflow in option parser and menu rendering OOB write -> RCE —>@@
                                                                  all could lead to a bypass of secure boot protections
                                                                • Includes one grub - ie. same grub efi binary used across all recent
                                                                • Ubuntu releases
                                                                • https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypass2021
                                                                • [USN-4993-1] Dovecot vulnerabilities [05:13]
                                                                  • 2 CVEs addressed in Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                    • CVE-2021-33515
                                                                    • CVE-2021-29157
                                                                    • STARTTLS plaintext command injection vuln via SMTP, plus if a local
                                                                    • attacker could write files to the disk, they could supply their own keys
                                                                      to validate their own supplied JSON Web Token and hence login as any
                                                                      other user and then access their emails if using OAUTH2
                                                                      [USN-4994-1, USN-4994-2] Apache HTTP Server vulnerabilities [05:58]
                                                                      • 5 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                        • CVE-2021-30641
                                                                        • CVE-2021-26691
                                                                        • CVE-2021-26690
                                                                        • CVE-2020-35452
                                                                        • CVE-2020-13950
                                                                        • Various DoS issues where under certain configurations an attacker could
                                                                        • issue particular requests and trigger various crashes in Apache
                                                                          [USN-4996-1, USN-4996-2] OpenEXR vulnerabilities [06:16]
                                                                          • 5 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
                                                                            • CVE-2021-3605
                                                                            • CVE-2021-3598
                                                                            • CVE-2021-26260
                                                                            • CVE-2021-23215
                                                                            • CVE-2021-20296
                                                                            • Usual mix of issues for a library which is written in memory unsafe
                                                                            • language and handling complex image formats etc
                                                                            • Courtesy of OSS-Fuzz
                                                                            • [USN-4995-1] Thunderbird vulnerabilities [06:48]
                                                                              • 20 CVEs addressed in Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                • CVE-2021-29957
                                                                                • CVE-2021-29956
                                                                                • CVE-2021-29949
                                                                                • CVE-2021-29948
                                                                                • CVE-2021-24002
                                                                                • CVE-2021-23995
                                                                                • CVE-2021-23993
                                                                                • CVE-2021-23992
                                                                                • CVE-2021-23991
                                                                                • CVE-2021-23984
                                                                                • CVE-2021-29967
                                                                                • CVE-2021-29946
                                                                                • CVE-2021-29945
                                                                                • CVE-2021-23999
                                                                                • CVE-2021-23998
                                                                                • CVE-2021-23994
                                                                                • CVE-2021-23987
                                                                                • CVE-2021-23982
                                                                                • CVE-2021-23981
                                                                                • CVE-2021-23961
                                                                                • 78.11.0 - usual mix of untrusted content/web framework issues inherited
                                                                                • from Firefox, plus fixes for OpenPGP key handling, message signature
                                                                                  TOCTTOU-type condition due to writing out signatures to disk that then
                                                                                  could be replaced before being verified, UX issue in display of inline
                                                                                  signed/encrypted messages with additional unprotected parts
                                                                                  [USN-4997-1] Linux kernel vulnerabilities [08:22]
                                                                                  • 17 CVEs addressed in Hirsute (21.04)
                                                                                    • CVE-2021-3543
                                                                                    • CVE-2021-3506
                                                                                    • CVE-2021-33034
                                                                                    • CVE-2021-32399
                                                                                    • CVE-2021-31829
                                                                                    • CVE-2021-31440
                                                                                    • CVE-2021-23134
                                                                                    • CVE-2021-23133
                                                                                    • CVE-2020-26147
                                                                                    • CVE-2020-26145
                                                                                    • CVE-2020-26141
                                                                                    • CVE-2020-26139
                                                                                    • CVE-2020-24588
                                                                                    • CVE-2020-24587
                                                                                    • CVE-2020-24586
                                                                                    • CVE-2021-33200
                                                                                    • CVE-2021-3609
                                                                                    • 5.11
                                                                                    • Basically the same set of fixes for all kernels, including a couple quite
                                                                                    • interesting ones:
                                                                                      • eBPF verifier bypass provides OOB write primitive, could allow a local
                                                                                      • attacker to perform code execution in the kernel -> privesc
                                                                                      • Race condition in CAN BCM networking protocol -> various UAFs -> code
                                                                                      • execution as well
                                                                                      • Plus others -> Wifi FragAttack fixes, other eBPF verifier fixes, SCTP
                                                                                      • race condition -> UAF etc
                                                                                        [USN-4999-1] Linux kernel vulnerabilities [09:51]
                                                                                        • 17 CVEs addressed in Focal (20.04 LTS), Groovy (20.10)
                                                                                          • CVE-2021-31829
                                                                                          • CVE-2021-31440
                                                                                          • CVE-2021-29155
                                                                                          • CVE-2021-23133
                                                                                          • CVE-2020-26147
                                                                                          • CVE-2020-26145
                                                                                          • CVE-2020-26141
                                                                                          • CVE-2020-26139
                                                                                          • CVE-2020-25673
                                                                                          • CVE-2020-25672
                                                                                          • CVE-2020-25671
                                                                                          • CVE-2020-25670
                                                                                          • CVE-2020-24588
                                                                                          • CVE-2020-24587
                                                                                          • CVE-2020-24586
                                                                                          • CVE-2021-33200
                                                                                          • CVE-2021-3609
                                                                                          • 5.8 (groovy, focal hwe)
                                                                                          • [USN-5000-1] Linux kernel vulnerabilities [10:08]
                                                                                            • 15 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                              • CVE-2021-3506
                                                                                              • CVE-2021-33034
                                                                                              • CVE-2021-32399
                                                                                              • CVE-2021-31829
                                                                                              • CVE-2021-23134
                                                                                              • CVE-2021-23133
                                                                                              • CVE-2020-26147
                                                                                              • CVE-2020-26145
                                                                                              • CVE-2020-26141
                                                                                              • CVE-2020-26139
                                                                                              • CVE-2020-24588
                                                                                              • CVE-2020-24587
                                                                                              • CVE-2020-24586
                                                                                              • CVE-2021-33200
                                                                                              • CVE-2021-3609
                                                                                              • 5.4 (focal, bionic hwe)
                                                                                              • [USN-5001-1] Linux kernel (OEM) vulnerabilities
                                                                                                • 15 CVEs addressed in Focal (20.04 LTS)
                                                                                                  • CVE-2021-3543
                                                                                                  • CVE-2021-3506
                                                                                                  • CVE-2021-33034
                                                                                                  • CVE-2021-32399
                                                                                                  • CVE-2021-31440
                                                                                                  • CVE-2021-23134
                                                                                                  • CVE-2021-23133
                                                                                                  • CVE-2020-26147
                                                                                                  • CVE-2020-26145
                                                                                                  • CVE-2020-26141
                                                                                                  • CVE-2020-26139
                                                                                                  • CVE-2020-24588
                                                                                                  • CVE-2020-24587
                                                                                                  • CVE-2020-24586
                                                                                                  • CVE-2021-3609
                                                                                                  • 5.10
                                                                                                  • [USN-5002-1] Linux kernel (HWE) vulnerability [10:23]
                                                                                                    • 1 CVEs addressed in Bionic (18.04 LTS)
                                                                                                      • CVE-2021-3609
                                                                                                      • 5.3
                                                                                                      • CAN BCM
                                                                                                      • [USN-5003-1] Linux kernel vulnerabilities [10:35]
                                                                                                        • 3 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
                                                                                                          • CVE-2021-23133
                                                                                                          • CVE-2021-3600
                                                                                                          • CVE-2021-3609
                                                                                                          • 4.15 (bionic, xenial esm hwe, trusty esm azure)
                                                                                                          • CAN BCM and eBPF verifier OOB write
                                                                                                          • Goings on in Ubuntu Security Community
                                                                                                            2FA coming to Ubuntu One [11:04]
                                                                                                            • https://ubuntu.com/blog/two-factor-authentication-coming-to-ubuntu-one
                                                                                                            • Used for access to discourse.ubuntu.com, Launchpad, ubuntuforums,
                                                                                                            • publishers on the Snap Store etc
                                                                                                            • Allows to use a phone / desktop TOTP app as second factor, or Yubikey
                                                                                                            • TOTP etc
                                                                                                            • Has actually been supported since 2014 but only available to a beta
                                                                                                            • testing group plus for all Canonical employees, due to challenges in
                                                                                                              account recovery
                                                                                                              • Since Ubuntu One purposefully doesn’t store any real identifying
                                                                                                              • information (name, email, username) we can’t easily verify account
                                                                                                                holders if they lose the 2FA device
                                                                                                              • The intent is to be robust even in the event that a users email address
                                                                                                              • is compromised
                                                                                                              • Now have a comprehensive code recovery experience including printable
                                                                                                              • backup codes and mechanisms in place to encourage users to exercise
                                                                                                                backup codes so that users can feel confident in using these if they need
                                                                                                                to (ie where did I put my backup codes again..?)
                                                                                                                Get in contact
                                                                                                                • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                • ubuntu-hardened mailing list
                                                                                                                • Security section on discourse.ubuntu.com
                                                                                                                • @ubuntu_sec on twitter
                                                                                                                • 15 min
                                                                                                                • Episode 120
                                                                                                                  Overview

                                                                                                                  In this week’s episode we look at how to get media coverage for your shiny

                                                                                                                  new vulnerability, plus we cover security updates for ExifTool,
                                                                                                                  ImageMagick, BlueZ and more.

                                                                                                                  This week in Ubuntu Security Updates

                                                                                                                  49 unique CVEs addressed

                                                                                                                  [USN-4986-2] rpcbind vulnerability [00:44]
                                                                                                                  • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM)
                                                                                                                    • CVE-2017-8779
                                                                                                                    • Episode 119 (bionic) - memory leak on crafted requests
                                                                                                                    • [USN-4986-3, USN-4986-4] rpcbind regression [01:11]
                                                                                                                      • Affecting Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
                                                                                                                      • Original fix missed follow-up patches to correct problems in the upstream
                                                                                                                      • fix - required multiple other bits to work correctly
                                                                                                                        [USN-4971-2] libwebp vulnerabilities [01:34]
                                                                                                                        • 10 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM)
                                                                                                                          • CVE-2020-36331
                                                                                                                          • CVE-2020-36330
                                                                                                                          • CVE-2020-36329
                                                                                                                          • CVE-2020-36328
                                                                                                                          • CVE-2018-25014
                                                                                                                          • CVE-2018-25013
                                                                                                                          • CVE-2018-25012
                                                                                                                          • CVE-2018-25011
                                                                                                                          • CVE-2018-25010
                                                                                                                          • CVE-2018-25009
                                                                                                                          • Episode 118
                                                                                                                          • [USN-4987-1] ExifTool vulnerability [01:50]
                                                                                                                            • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                              • CVE-2021-22204
                                                                                                                              • Was originally reported to gitlab via hackerone as exiftool is used on
                                                                                                                              • image uploads to redact image metadata etc - they coordinated the fix
                                                                                                                                with exiftool upstream. RCE when parsing a malicious DjVu image - uses
                                                                                                                                perl to parse DjVu and in doing so it eval’s certain constructs without
                                                                                                                                properly validating them
                                                                                                                                [USN-4988-1] ImageMagick vulnerabilities [03:17]
                                                                                                                                • 34 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10)
                                                                                                                                  • CVE-2021-20176
                                                                                                                                  • CVE-2020-27776
                                                                                                                                  • CVE-2020-27775
                                                                                                                                  • CVE-2020-27774
                                                                                                                                  • CVE-2020-27773
                                                                                                                                  • CVE-2020-27772
                                                                                                                                  • CVE-2020-27771
                                                                                                                                  • CVE-2020-27770
                                                                                                                                  • CVE-2020-27769
                                                                                                                                  • CVE-2020-27768
                                                                                                                                  • CVE-2020-27767
                                                                                                                                  • CVE-2020-27766
                                                                                                                                  • CVE-2020-27765
                                                                                                                                  • CVE-2020-27764
                                                                                                                                  • CVE-2020-27763
                                                                                                                                  • CVE-2020-27762
                                                                                                                                  • CVE-2020-27761
                                                                                                                                  • CVE-2020-27760
                                                                                                                                  • CVE-2020-27759
                                                                                                                                  • CVE-2020-27758
                                                                                                                                  • CVE-2020-27757
                                                                                                                                  • CVE-2020-27756
                                                                                                                                  • CVE-2020-27755
                                                                                                                                  • CVE-2020-27754
                                                                                                                                  • CVE-2020-27753
                                                                                                                                  • CVE-2020-27751
                                                                                                                                  • CVE-2020-27750
                                                                                                                                  • CVE-2020-25676
                                                                                                                                  • CVE-2020-25675
                                                                                                                                  • CVE-2020-25674
                                                                                                                                  • CVE-2020-25666
                                                                                                                                  • CVE-2020-25665
                                                                                                                                  • CVE-2020-19667
                                                                                                                                  • CVE-2017-14528
                                                                                                                                  • every ~30 weeks we seem to have another ImageMagick update - so that time again ;)
                                                                                                                                  • DoS, RCE etc
                                                                                                                                  • [USN-4989-1] BlueZ vulnerabilities [03:56]
                                                                                                                                    • 3 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                      • CVE-2021-3588
                                                                                                                                      • CVE-2020-27153
                                                                                                                                      • CVE-2020-26558
                                                                                                                                      • 1 bluetooth core specification issue - during pairing a nearby attacker
                                                                                                                                      • could interpose on the pairing process and hence complete the pairing
                                                                                                                                        instead of the intended device
                                                                                                                                      • 2 issues in bluez code itself
                                                                                                                                        • double free (UAF) + OOB read
                                                                                                                                        • Goings on in Ubuntu Security Community
                                                                                                                                          How to get media coverage for your Linux vulnerabilities [04:48]
                                                                                                                                          • In Episode 119 covered an update for polkit - the following day Github
                                                                                                                                          • published a blog post with significant details of the vuln - then we saw
                                                                                                                                            a heap of media coverage
                                                                                                                                            • https://www.theregister.com/2021/06/11/linux_polkit_package_patched/
                                                                                                                                            • https://www.zdnet.com/article/nasty-linux-systemd-root-level-security-bug-revealed-and-patched/
                                                                                                                                            • Why did this vuln get so much coverage when lots of others don’t?
                                                                                                                                              • Great technical detail from a reputable and popular source (github)
                                                                                                                                              • Very clearly written and easy to understand
                                                                                                                                                • Is a simple logic error that can be triggered via a race-condition in
                                                                                                                                                • a privileged daemon
                                                                                                                                                • PoC can be implemented as a 1 line bash invocation so is also simple
                                                                                                                                                • to understand
                                                                                                                                                • c.f. a complicated memory corruption vuln or similar (ie no need to
                                                                                                                                                • understand memory management, heap grooming etc etc)
                                                                                                                                                • Or give it a cool name and logo
                                                                                                                                                  • heartbleed was one of the first to do this and this likely helped it
                                                                                                                                                  • get noticed and patched (plus fame/notoriety for the researchers)
                                                                                                                                                  • Since then we have seen many (shellshock, stagefright, dirty cow,
                                                                                                                                                  • spectre, meltdown, boothole etc) but not all vulns that get names/logos
                                                                                                                                                    are created equal - impact / exploitability varies greatly - so a name
                                                                                                                                                    and a logo doesn’t necessarily mean a vuln is critical
                                                                                                                                                    Get in contact
                                                                                                                                                    • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                    • ubuntu-hardened mailing list
                                                                                                                                                    • Security section on discourse.ubuntu.com
                                                                                                                                                    • @ubuntu_sec on twitter
                                                                                                                                                    • 11 min
                                                                                                                                                    • Episode 119
                                                                                                                                                      Overview

                                                                                                                                                      This week we cover security updates for the Linux kernel, PolicyKit, Intel

                                                                                                                                                      Microcode and more, plus we look at a report of an apparent malicious snap
                                                                                                                                                      in the Snap Store and some of the mechanics behind snap confinement.

                                                                                                                                                      This week in Ubuntu Security Updates

                                                                                                                                                      42 unique CVEs addressed

                                                                                                                                                      [USN-4979-1] Linux kernel vulnerabilities [01:04]
                                                                                                                                                      • 13 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS)
                                                                                                                                                        • CVE-2021-3483
                                                                                                                                                        • CVE-2021-3428
                                                                                                                                                        • CVE-2021-33033
                                                                                                                                                        • CVE-2021-31916
                                                                                                                                                        • CVE-2021-29647
                                                                                                                                                        • CVE-2021-28972
                                                                                                                                                        • CVE-2021-28971
                                                                                                                                                        • CVE-2021-28964
                                                                                                                                                        • CVE-2021-28660
                                                                                                                                                        • CVE-2020-25673
                                                                                                                                                        • CVE-2020-25672
                                                                                                                                                        • CVE-2020-25671
                                                                                                                                                        • CVE-2020-25670
                                                                                                                                                        • 4.15 based kernel
                                                                                                                                                        • integer overflow in ext4 extent handling -> could be triggered by
                                                                                                                                                        • mounting an malicious ext4 image -> crash (DoS)
                                                                                                                                                        • reference counting error in firewire packet sniffer driver - UAF
                                                                                                                                                        • NFC LLCP issues above
                                                                                                                                                        • [USN-4982-1] Linux kernel vulnerabilities [02:23]
                                                                                                                                                          • 13 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                            • CVE-2021-3483
                                                                                                                                                            • CVE-2021-31916
                                                                                                                                                            • CVE-2021-29647
                                                                                                                                                            • CVE-2021-29264
                                                                                                                                                            • CVE-2021-28972
                                                                                                                                                            • CVE-2021-28971
                                                                                                                                                            • CVE-2021-28964
                                                                                                                                                            • CVE-2021-28950
                                                                                                                                                            • CVE-2021-28688
                                                                                                                                                            • CVE-2020-25673
                                                                                                                                                            • CVE-2020-25672
                                                                                                                                                            • CVE-2020-25671
                                                                                                                                                            • CVE-2020-25670
                                                                                                                                                            • 5.4 based kernel
                                                                                                                                                            • [USN-4984-1] Linux kernel vulnerabilities [02:39]
                                                                                                                                                              • 13 CVEs addressed in Focal (20.04 LTS), Groovy (20.10)
                                                                                                                                                                • CVE-2021-3483
                                                                                                                                                                • CVE-2021-33033
                                                                                                                                                                • CVE-2021-31916
                                                                                                                                                                • CVE-2021-30002
                                                                                                                                                                • CVE-2021-29647
                                                                                                                                                                • CVE-2021-28972
                                                                                                                                                                • CVE-2021-28971
                                                                                                                                                                • CVE-2021-28964
                                                                                                                                                                • CVE-2021-28952
                                                                                                                                                                • CVE-2021-28950
                                                                                                                                                                • CVE-2021-28688
                                                                                                                                                                • CVE-2021-28660
                                                                                                                                                                • CVE-2021-28038
                                                                                                                                                                • 5.8 based kernel
                                                                                                                                                                • [USN-4977-1] Linux kernel vulnerabilities
                                                                                                                                                                  • 6 CVEs addressed in Hirsute (21.04)
                                                                                                                                                                    • CVE-2021-3501
                                                                                                                                                                    • CVE-2021-29155
                                                                                                                                                                    • CVE-2020-25673
                                                                                                                                                                    • CVE-2020-25672
                                                                                                                                                                    • CVE-2020-25671
                                                                                                                                                                    • CVE-2020-25670
                                                                                                                                                                    • 5.11 based kernel
                                                                                                                                                                    • OOB write in KVM VMX implementation (crash -> DoS, RCE)
                                                                                                                                                                    • eBPF Spectre side-channel attack - info leak
                                                                                                                                                                    • NFC LLCP (logical link control protocol) - allows to multiplex a single
                                                                                                                                                                    • connection between two NFC devices
                                                                                                                                                                      • infinite loop on error condition -> DoS
                                                                                                                                                                      • memory leak
                                                                                                                                                                      • reference count mishandling -> crash -> DoS
                                                                                                                                                                      • [USN-4983-1] Linux kernel (OEM) vulnerabilities [03:32]
                                                                                                                                                                        • 4 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                          • CVE-2021-3501
                                                                                                                                                                          • CVE-2021-31829
                                                                                                                                                                          • CVE-2021-29155
                                                                                                                                                                          • CVE-2021-33200
                                                                                                                                                                          • 5.10 based kernel
                                                                                                                                                                          • OOB write in KVM VMX implementation (crash -> DoS, RCE)
                                                                                                                                                                          • eBPF Spectre side-channel attacks - verifier fails to stop loading of eBPF
                                                                                                                                                                          • programs which could cause speculative loads -> info leak
                                                                                                                                                                          • eBPF pointer limit error - OOB read/write - crash / RCE
                                                                                                                                                                          • [USN-4978-1] Firefox vulnerabilities [03:40]
                                                                                                                                                                            • 5 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                              • CVE-2021-29960
                                                                                                                                                                              • CVE-2021-29967
                                                                                                                                                                              • CVE-2021-29966
                                                                                                                                                                              • CVE-2021-29961
                                                                                                                                                                              • CVE-2021-29959
                                                                                                                                                                              • 89.0 upstream release
                                                                                                                                                                                • not only the new visual UI PLUS enhanced private browsing mode via
                                                                                                                                                                                • “Total Cookie Protection” - confines cookies to the site where they
                                                                                                                                                                                  were created to avoid tracking across sites - PLUS a bunch of security
                                                                                                                                                                                  fixes including
                                                                                                                                                                                  • cached the last filename of a printed file even in private browsing
                                                                                                                                                                                  • mode - would then surface this next time you choose to print a file
                                                                                                                                                                                  • Various memory safety issues - RCE / crash etc
                                                                                                                                                                                  • [USN-4980-1] polkit vulnerability [04:43]
                                                                                                                                                                                    • 1 CVEs addressed in Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                      • CVE-2021-3560
                                                                                                                                                                                      • Daemons often use policykit to ask whether a user’s application is
                                                                                                                                                                                      • permitted to perform an action - to do this, they send the DBus name of
                                                                                                                                                                                        the process to polkit and it looks up the resulting uid/pid via an
                                                                                                                                                                                        internal function polkit_system_bus_name_get_creds_sync() - logic error
                                                                                                                                                                                        within policykit when looking if the process in question were to
                                                                                                                                                                                        disconnect from DBus at the right time, policykit would return an error
                                                                                                                                                                                        but also a boolean TRUE value indicating success (depends on how the
                                                                                                                                                                                        daemon interpreted this value with an associated error). This could then
                                                                                                                                                                                        allow an application which was not privileged to be able to perform more
                                                                                                                                                                                        privileged actions. Fixed to actually return FALSE in this case and avoid
                                                                                                                                                                                        any potential confusion.
                                                                                                                                                                                        [USN-4981-1] Squid vulnerabilities [06:11]
                                                                                                                                                                                        • 7 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                          • CVE-2021-33620
                                                                                                                                                                                          • CVE-2021-31808
                                                                                                                                                                                          • CVE-2021-31807
                                                                                                                                                                                          • CVE-2021-31806
                                                                                                                                                                                          • CVE-2021-28662
                                                                                                                                                                                          • CVE-2021-28652
                                                                                                                                                                                          • CVE-2021-28651
                                                                                                                                                                                          • All DoS issues - memory leaks, OOB reads etc, able to be triggered by
                                                                                                                                                                                          • remote attackers
                                                                                                                                                                                            [USN-4969-3] DHCP regression [06:28]
                                                                                                                                                                                            • Affecting Hirsute (21.04)
                                                                                                                                                                                            • Episode 118 - update for 21.04 only introduced a regression where valid
                                                                                                                                                                                            • config files would be seen as invalid and rejected and hence
                                                                                                                                                                                              isc-dhcp-server would fail to start - actually caused as a result of the
                                                                                                                                                                                              newer toolchain used in 21.04 - has stricter aliasing checking and so
                                                                                                                                                                                              would treat certain operations introduced in this change as UB and change
                                                                                                                                                                                              code-flow as a result. Fixed by disabling this stricter aliasing checking
                                                                                                                                                                                              in the build to restore the original behaviour.
                                                                                                                                                                                              [USN-4937-2] GNOME Autoar regression [07:22]
                                                                                                                                                                                              • Episode 115
                                                                                                                                                                                              • Affecting Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                              • upstream regression where when extracting an archive, only an empty
                                                                                                                                                                                              • directory would be created if an archive contained a file of the same
                                                                                                                                                                                                name as the archive itself - fixed to avoid creating this directory first
                                                                                                                                                                                                so that files would then actually get created as expected
                                                                                                                                                                                                [USN-4985-1] Intel Microcode vulnerabilities [07:48]
                                                                                                                                                                                                • 5 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                  • CVE-2020-24513
                                                                                                                                                                                                  • CVE-2020-24512
                                                                                                                                                                                                  • CVE-2020-24511
                                                                                                                                                                                                  • CVE-2017-5715
                                                                                                                                                                                                  • CVE-2021-24489
                                                                                                                                                                                                  • Latest intel-microcode release from upstream, fixes a number of security
                                                                                                                                                                                                  • issues for particular processors PLUS potential stability issues that
                                                                                                                                                                                                    have been seen in previous microcode releases (processor would hang if
                                                                                                                                                                                                    tried to load a too new microcode version compared to the one contained
                                                                                                                                                                                                    within the BIOS)
                                                                                                                                                                                                    • potential cross-domain issue with Intel VT-d (priv esc) plus a fix for
                                                                                                                                                                                                    • an issue which would result in EIBRS (Spectre) mitigations not being
                                                                                                                                                                                                      applied, cache-lines not being flushed properly and a speculative
                                                                                                                                                                                                      execution issue specific to Atom processors via micro-arch buffers.
                                                                                                                                                                                                      [USN-4986-1] rpcbind vulnerability [09:02]
                                                                                                                                                                                                      • 1 CVEs addressed in Bionic (18.04 LTS)
                                                                                                                                                                                                        • CVE-2017-8779
                                                                                                                                                                                                        • DoS since would fail to free memory allocated during particular
                                                                                                                                                                                                        • requests - could then be made to crash by allocating too much memory
                                                                                                                                                                                                          Goings on in Ubuntu Security Community
                                                                                                                                                                                                          odrive-unofficial snap investigation [09:20]
                                                                                                                                                                                                          • https://twitter.com/XHaughin/status/1400743600464355331
                                                                                                                                                                                                          • The magic behind snap interfaces [12:36]
                                                                                                                                                                                                            • https://ubuntu.com/blog/the-magic-behind-snap-interfaces
                                                                                                                                                                                                            • Get in contact
                                                                                                                                                                                                              • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                              • ubuntu-hardened mailing list
                                                                                                                                                                                                              • Security section on discourse.ubuntu.com
                                                                                                                                                                                                              • @ubuntu_sec on twitter
                                                                                                                                                                                                              • 15 min
                                                                                                                                                                                                              • Episode 118
                                                                                                                                                                                                                Overview

                                                                                                                                                                                                                This week we look at DMCA notices sent against Ubuntu ISOs plus security

                                                                                                                                                                                                                updates for nginx, DHCP, Lasso, Django, Dnsmasq and more.

                                                                                                                                                                                                                This week in Ubuntu Security Updates

                                                                                                                                                                                                                24 unique CVEs addressed

                                                                                                                                                                                                                [USN-4967-1, USN-4967-2] nginx vulnerability [00:50]
                                                                                                                                                                                                                • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                  • CVE-2021-23017
                                                                                                                                                                                                                  • 1 byte buffer overflow, able to be trigged by a crafted DNS response -
                                                                                                                                                                                                                  • UDP so could possibly be more easily forged than TCP (less state) -
                                                                                                                                                                                                                    crash, RCE
                                                                                                                                                                                                                    [USN-4968-1, USN-4968-2] LZ4 vulnerability [01:27]
                                                                                                                                                                                                                    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                      • CVE-2021-3520
                                                                                                                                                                                                                      • integer overflow -> OOB write -> crash, RCE - crafted lz4 archive
                                                                                                                                                                                                                      • [USN-4969-1, USN-4969-2] DHCP vulnerability [01:52]
                                                                                                                                                                                                                        • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                          • CVE-2021-25217
                                                                                                                                                                                                                          • Crafted lease file could trigger an OOB read - could be triggered against
                                                                                                                                                                                                                          • both dhclient and dhcpd - DoS. In case of dhcpd could also cause that
                                                                                                                                                                                                                            lease to be deleted (and the one that follows it in the lease database).
                                                                                                                                                                                                                            ISC claim impact is LESS is using compiler hardening
                                                                                                                                                                                                                            (stack-protector-strong) - since in this case will trigger an abort - but
                                                                                                                                                                                                                            if not used it will keep running…
                                                                                                                                                                                                                            [USN-4970-1] GUPnP vulnerability [03:15]
                                                                                                                                                                                                                            • 1 CVEs addressed in Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                              • CVE-2021-33516
                                                                                                                                                                                                                              • DNS rebinding attack - able to be exploited by a remote web server -
                                                                                                                                                                                                                              • cause the local web browser into triggering actions against local UPnP
                                                                                                                                                                                                                                services that use gupnp library as it would not check that the Host
                                                                                                                                                                                                                                header specified the expected IP address. Could then be used for data
                                                                                                                                                                                                                                exfil / tampering etc.
                                                                                                                                                                                                                              • Can be mitigated against by using a DNS resolver that prevents DNS
                                                                                                                                                                                                                              • rebinding
                                                                                                                                                                                                                                [USN-4971-1] libwebp vulnerabilities [04:11]
                                                                                                                                                                                                                                • 11 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                  • CVE-2020-36332
                                                                                                                                                                                                                                  • CVE-2020-36331
                                                                                                                                                                                                                                  • CVE-2020-36330
                                                                                                                                                                                                                                  • CVE-2020-36329
                                                                                                                                                                                                                                  • CVE-2020-36328
                                                                                                                                                                                                                                  • CVE-2018-25014
                                                                                                                                                                                                                                  • CVE-2018-25013
                                                                                                                                                                                                                                  • CVE-2018-25012
                                                                                                                                                                                                                                  • CVE-2018-25011
                                                                                                                                                                                                                                  • CVE-2018-25010
                                                                                                                                                                                                                                  • CVE-2018-25009
                                                                                                                                                                                                                                  • Google’s image format to relace both jpg/png and be faster (like vp8
                                                                                                                                                                                                                                  • video codec using predictive encoding - uses neighboring pixels to
                                                                                                                                                                                                                                    predict values in a block and then encodes only the difference)
                                                                                                                                                                                                                                  • C library :( - memory unsafe
                                                                                                                                                                                                                                  • OOB reads, heap buffer overflow, UAF, excessive memory allocation etc
                                                                                                                                                                                                                                    • DoS, RCE etc
                                                                                                                                                                                                                                    • [USN-4972-1] PostgreSQL vulnerabilities [05:05]
                                                                                                                                                                                                                                      • 3 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                        • CVE-2021-32029
                                                                                                                                                                                                                                        • CVE-2021-32028
                                                                                                                                                                                                                                        • CVE-2021-32027
                                                                                                                                                                                                                                        • Thanks to Christian Ehrhardt from the Ubuntu Server team for preparing
                                                                                                                                                                                                                                        • these updates
                                                                                                                                                                                                                                        • Latest upstream point-releases
                                                                                                                                                                                                                                          • 10.17 - 18.04
                                                                                                                                                                                                                                          • 12.7 - 20.04 LTS, 20.10
                                                                                                                                                                                                                                          • 13.3 - 21.04
                                                                                                                                                                                                                                          • [USN-4973-1] Python vulnerability [05:44]
                                                                                                                                                                                                                                            • 1 CVEs addressed in Focal (20.04 LTS), Groovy (20.10)
                                                                                                                                                                                                                                              • CVE-2021-29921
                                                                                                                                                                                                                                              • ipaddress library in the python stdlib mishandled leading zero characters
                                                                                                                                                                                                                                              • in octets of an IP address - could allow bypass of access controls that
                                                                                                                                                                                                                                                are based on IP addresses. Now treats leading zeros as invalid input
                                                                                                                                                                                                                                                (before would try and treat them as octal… but could end up confused as
                                                                                                                                                                                                                                                a result)
                                                                                                                                                                                                                                                [USN-4974-1] Lasso vulnerability [06:40]
                                                                                                                                                                                                                                                • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                  • CVE-2021-28091
                                                                                                                                                                                                                                                  • SAML protocol library
                                                                                                                                                                                                                                                  • Reported by Akamai (uses Lasso in their Enterprise Application Access
                                                                                                                                                                                                                                                  • product) - and coordinated between affected distros and vendors etc
                                                                                                                                                                                                                                                  • Could allow unauthenticated access to applications that use SAMLv2
                                                                                                                                                                                                                                                  • (Security Assertion Markup Language v2) for authentication
                                                                                                                                                                                                                                                  • If a SAML response contained both a signed and valid assertion, plus
                                                                                                                                                                                                                                                  • additional unsigned assertions appened to this, these unsigned assertions
                                                                                                                                                                                                                                                    would be treated as valid as well.
                                                                                                                                                                                                                                                  • So could allow an authenticated user to take their own signed SAML
                                                                                                                                                                                                                                                  • assertion and append assertions for other users to the end to then
                                                                                                                                                                                                                                                    impersonate those other users.
                                                                                                                                                                                                                                                  • https://blogs.akamai.com/2021/06/saml-implementation-vulnerability-impacting-some-akamai-services.html
                                                                                                                                                                                                                                                  • [USN-4975-1] Django vulnerabilities [08:19]
                                                                                                                                                                                                                                                    • 3 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                      • CVE-2021-33571
                                                                                                                                                                                                                                                      • CVE-2021-33203
                                                                                                                                                                                                                                                      • CVE-2021-32052
                                                                                                                                                                                                                                                      • URLValidator failed to properly handle newlines, tabs - could be used to
                                                                                                                                                                                                                                                      • inject other headers into responses etc
                                                                                                                                                                                                                                                      • Paths not properly sanitized in the admindocs module - could be used to
                                                                                                                                                                                                                                                      • probe for the existence of files or possibly obtain their contents
                                                                                                                                                                                                                                                      • Leading zeros in IPv4 addresses - basically identical to the Python issue
                                                                                                                                                                                                                                                      • above
                                                                                                                                                                                                                                                        [USN-4976-1] Dnsmasq vulnerability [08:56]
                                                                                                                                                                                                                                                        • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                          • CVE-2021-3448
                                                                                                                                                                                                                                                          • Failed to properly randomise source port (ie used a fixed port) when
                                                                                                                                                                                                                                                          • forwarding queries when configured to use a specific server for a given
                                                                                                                                                                                                                                                            network interface - could then allow a remote attacker to more easily
                                                                                                                                                                                                                                                            perform cache poisoning attacks (ie just need to guess the transmission
                                                                                                                                                                                                                                                            ID once know the source port to get a forged reply accepted)
                                                                                                                                                                                                                                                            • Very similar to the issues that were discovered back in 2008 by Dan
                                                                                                                                                                                                                                                            • Kaminsky - the whole reason source port randomisation was introduced as
                                                                                                                                                                                                                                                              part of the DNS protocol
                                                                                                                                                                                                                                                              Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                              Ubuntu user’s DMCA violation [09:58]
                                                                                                                                                                                                                                                              • Last week was reported that a user downloading Ubuntu 20.04.2 iso via
                                                                                                                                                                                                                                                              • bittorrent received a DMCA violation notice from their ISP (Comcast)
                                                                                                                                                                                                                                                              • Clearly absurd given Ubuntu is free (beer & freedom/libre)
                                                                                                                                                                                                                                                              • Also the hash of the iso in question was legit too
                                                                                                                                                                                                                                                              • Sent by “OpSec Online Antipiracy” not Canonical
                                                                                                                                                                                                                                                              • OpSec responded saying their notice sending program was “spoofed” by
                                                                                                                                                                                                                                                              • unknown parties across multiple streaming platforms
                                                                                                                                                                                                                                                              • Not clear then if the user spoofed it directly or if someone else spoofed
                                                                                                                                                                                                                                                              • the notice and sent it to the user…
                                                                                                                                                                                                                                                              • Still being investigated by OpSec apparently - our legal team is also
                                                                                                                                                                                                                                                              • looking into it as well
                                                                                                                                                                                                                                                              • Not the first time this sort of thing has happened - back in 2016
                                                                                                                                                                                                                                                              • Paramount Pictures used the DMCA to send a takedown request to Google to
                                                                                                                                                                                                                                                                remove a search result linking to the Ubuntu 12.04.2 alternate ISO at
                                                                                                                                                                                                                                                                extratorrent.cc - this was listed as apparently being a link to the
                                                                                                                                                                                                                                                                Transformers: Age of Extinction movie…
                                                                                                                                                                                                                                                                • Google did follow through on this - likely an automated system due to
                                                                                                                                                                                                                                                                • the sheer volume of such requests they get per day (3 million p/d
                                                                                                                                                                                                                                                                  pirate URLs to be removed from search results)
                                                                                                                                                                                                                                                                  Get in contact
                                                                                                                                                                                                                                                                  • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                  • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                  • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                  • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                  • 14 min
                                                                                                                                                                                                                                                                  • Episode 117
                                                                                                                                                                                                                                                                    Overview

                                                                                                                                                                                                                                                                    This week we’re talking about moving IRC networks plus security updates for Pillow, Babel, Apport, X11 and more.

                                                                                                                                                                                                                                                                    This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                    24 unique CVEs addressed

                                                                                                                                                                                                                                                                    [USN-4963-1] Pillow vulnerabilities [00:55]
                                                                                                                                                                                                                                                                    • 6 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                      • CVE-2021-28678
                                                                                                                                                                                                                                                                      • CVE-2021-28677
                                                                                                                                                                                                                                                                      • CVE-2021-28676
                                                                                                                                                                                                                                                                      • CVE-2021-28675
                                                                                                                                                                                                                                                                      • CVE-2021-25288
                                                                                                                                                                                                                                                                      • CVE-2021-25287
                                                                                                                                                                                                                                                                      • Python image handling library - used by many other packages for their
                                                                                                                                                                                                                                                                      • image handling
                                                                                                                                                                                                                                                                      • All DoS issues via OOB read and similar so not critical
                                                                                                                                                                                                                                                                      • [USN-4962-1] Babel vulnerability [01:31]
                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                          • CVE-2021-20095
                                                                                                                                                                                                                                                                          • Internationalisation handling for python apps
                                                                                                                                                                                                                                                                          • Directory traversal flaw - could be exploited to load arbitrary locale
                                                                                                                                                                                                                                                                          • .dat files - these contain serialized Python objects - so hence can get
                                                                                                                                                                                                                                                                            arbitrary code execution as a result.
                                                                                                                                                                                                                                                                          • Could use relative path to specify a file outside the locate-data
                                                                                                                                                                                                                                                                          • directory
                                                                                                                                                                                                                                                                            [USN-4964-1] Exiv2 vulnerabilities [02:25]
                                                                                                                                                                                                                                                                            • 5 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                              • CVE-2021-29623
                                                                                                                                                                                                                                                                              • CVE-2021-32617
                                                                                                                                                                                                                                                                              • CVE-2021-29473
                                                                                                                                                                                                                                                                              • CVE-2021-29464
                                                                                                                                                                                                                                                                              • CVE-2021-29463
                                                                                                                                                                                                                                                                              • CLI util and library (C++) for reading+modifying metadata in image
                                                                                                                                                                                                                                                                              • files - more exiv2 - last only in Episode 115
                                                                                                                                                                                                                                                                              • OOB reads on metadata write
                                                                                                                                                                                                                                                                              • heap buffer overflow on m w
                                                                                                                                                                                                                                                                              • quadratic complexity algorithm on metadata write - DoS
                                                                                                                                                                                                                                                                              • stack info leak on m r
                                                                                                                                                                                                                                                                              • [USN-4965-1, USN-4965-2] Apport vulnerabilities [03:19]
                                                                                                                                                                                                                                                                                • 11 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                                  • CVE-2021-32557
                                                                                                                                                                                                                                                                                  • CVE-2021-32556
                                                                                                                                                                                                                                                                                  • CVE-2021-32555
                                                                                                                                                                                                                                                                                  • CVE-2021-32554
                                                                                                                                                                                                                                                                                  • CVE-2021-32553
                                                                                                                                                                                                                                                                                  • CVE-2021-32552
                                                                                                                                                                                                                                                                                  • CVE-2021-32551
                                                                                                                                                                                                                                                                                  • CVE-2021-32550
                                                                                                                                                                                                                                                                                  • CVE-2021-32549
                                                                                                                                                                                                                                                                                  • CVE-2021-32548
                                                                                                                                                                                                                                                                                  • CVE-2021-32547
                                                                                                                                                                                                                                                                                  • Seems it’s time for more Apport vulns - every quarter or so
                                                                                                                                                                                                                                                                                  • Arbitrary file read / write vulns discovered by Maik Münch
                                                                                                                                                                                                                                                                                  • Apport parses various details out of /proc and some of these can be
                                                                                                                                                                                                                                                                                  • crafted by the process, ie process name, current working dir etc - and
                                                                                                                                                                                                                                                                                    then goes to gather files etc - and so if can craft these details can get
                                                                                                                                                                                                                                                                                    it to read files which weren’t intended via symlinks etc (mitigated by
                                                                                                                                                                                                                                                                                    symlink protections in Ubuntu) - or from injection of data into say dpkg
                                                                                                                                                                                                                                                                                    queries to get it to include other files like /etc/passwd since this
                                                                                                                                                                                                                                                                                    operation happens as root by apport
                                                                                                                                                                                                                                                                                  • These end up in the crash dump and this can be read by the regular user
                                                                                                                                                                                                                                                                                  • Also when uploading via whoopsie, race condition where crash dump can be
                                                                                                                                                                                                                                                                                  • replaced by a symlink and then the crash dump will be written to the dest
                                                                                                                                                                                                                                                                                    of the symlink - file write vuln - but again mitigated by
                                                                                                                                                                                                                                                                                    symlink-restriction
                                                                                                                                                                                                                                                                                    [USN-4966-1, USN-4966-2] libx11 vulnerability [05:57]
                                                                                                                                                                                                                                                                                    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                                      • CVE-2021-31535
                                                                                                                                                                                                                                                                                      • When looking up a color, failed to properly validate it - app could then
                                                                                                                                                                                                                                                                                      • get extra X protocol requests sent to the X server - ie. could then
                                                                                                                                                                                                                                                                                        disable X server authorisation etc so remote attackers could connect to
                                                                                                                                                                                                                                                                                        the local X server and snoop on inputs etc
                                                                                                                                                                                                                                                                                        Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                        #ubuntu-hardened -> #ubuntu-security on Libera.Chat [06:45]
                                                                                                                                                                                                                                                                                        • LWN writeup https://lwn.net/Articles/857140/
                                                                                                                                                                                                                                                                                        • Volunteer staff resigned en masse after network was taken over by tech
                                                                                                                                                                                                                                                                                        • entrepreneur
                                                                                                                                                                                                                                                                                        • Ubuntu IRC council voted and approved a resolution to recommend moving
                                                                                                                                                                                                                                                                                        • Ubuntu IRC channels from freenode to Libera.Chat
                                                                                                                                                                                                                                                                                        • Community Council approved this so now all channels have moved to
                                                                                                                                                                                                                                                                                        • Libera.Chat
                                                                                                                                                                                                                                                                                        • Almost all of the old channels on freenode have now all been taken over
                                                                                                                                                                                                                                                                                        • by the new freenode staff
                                                                                                                                                                                                                                                                                        • irc.ubuntu.com now redirects to irc.libera.chat
                                                                                                                                                                                                                                                                                        • Finally took the opportunity to rename our channel - #ubuntu-security
                                                                                                                                                                                                                                                                                        • Come join us
                                                                                                                                                                                                                                                                                        • Get in contact
                                                                                                                                                                                                                                                                                          • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                          • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                          • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                          • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                          • 10 min
                                                                                                                                                                                                                                                                                          • Episode 116
                                                                                                                                                                                                                                                                                            Overview

                                                                                                                                                                                                                                                                                            With 60 CVEs fixed across MySQL, Django, Please and the Linux kernel this

                                                                                                                                                                                                                                                                                            week we take a look at some of these details, plus look at the recent
                                                                                                                                                                                                                                                                                            announcement of 1Password for Linux and some open positions on the team
                                                                                                                                                                                                                                                                                            too.

                                                                                                                                                                                                                                                                                            This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                            60 unique CVEs addressed

                                                                                                                                                                                                                                                                                            [USN-4952-1] MySQL vulnerabilities [00:58]
                                                                                                                                                                                                                                                                                            • 33 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                                              • CVE-2021-2308
                                                                                                                                                                                                                                                                                              • CVE-2021-2307
                                                                                                                                                                                                                                                                                              • CVE-2021-2305
                                                                                                                                                                                                                                                                                              • CVE-2021-2304
                                                                                                                                                                                                                                                                                              • CVE-2021-2301
                                                                                                                                                                                                                                                                                              • CVE-2021-2300
                                                                                                                                                                                                                                                                                              • CVE-2021-2299
                                                                                                                                                                                                                                                                                              • CVE-2021-2298
                                                                                                                                                                                                                                                                                              • CVE-2021-2293
                                                                                                                                                                                                                                                                                              • CVE-2021-2278
                                                                                                                                                                                                                                                                                              • CVE-2021-2232
                                                                                                                                                                                                                                                                                              • CVE-2021-2230
                                                                                                                                                                                                                                                                                              • CVE-2021-2226
                                                                                                                                                                                                                                                                                              • CVE-2021-2217
                                                                                                                                                                                                                                                                                              • CVE-2021-2215
                                                                                                                                                                                                                                                                                              • CVE-2021-2212
                                                                                                                                                                                                                                                                                              • CVE-2021-2208
                                                                                                                                                                                                                                                                                              • CVE-2021-2203
                                                                                                                                                                                                                                                                                              • CVE-2021-2201
                                                                                                                                                                                                                                                                                              • CVE-2021-2196
                                                                                                                                                                                                                                                                                              • CVE-2021-2194
                                                                                                                                                                                                                                                                                              • CVE-2021-2193
                                                                                                                                                                                                                                                                                              • CVE-2021-2180
                                                                                                                                                                                                                                                                                              • CVE-2021-2179
                                                                                                                                                                                                                                                                                              • CVE-2021-2172
                                                                                                                                                                                                                                                                                              • CVE-2021-2171
                                                                                                                                                                                                                                                                                              • CVE-2021-2170
                                                                                                                                                                                                                                                                                              • CVE-2021-2169
                                                                                                                                                                                                                                                                                              • CVE-2021-2166
                                                                                                                                                                                                                                                                                              • CVE-2021-2164
                                                                                                                                                                                                                                                                                              • CVE-2021-2162
                                                                                                                                                                                                                                                                                              • CVE-2021-2154
                                                                                                                                                                                                                                                                                              • CVE-2021-2146
                                                                                                                                                                                                                                                                                              • Latest upstream point releases - includes both security and bug fixes and
                                                                                                                                                                                                                                                                                              • possibly incompatible changes etc
                                                                                                                                                                                                                                                                                              • MySQL has been updated to 8.0.25 in Ubuntu 20.04 LTS, Ubuntu 20.10, and
                                                                                                                                                                                                                                                                                              • Ubuntu 21.04. Ubuntu 18.04 LTS has been updated to MySQL 5.7.34.
                                                                                                                                                                                                                                                                                                [USN-4932-2] Django vulnerability [01:37]
                                                                                                                                                                                                                                                                                                • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS)
                                                                                                                                                                                                                                                                                                  • CVE-2021-31542
                                                                                                                                                                                                                                                                                                  • Episode 114 - directory traversal via file upload
                                                                                                                                                                                                                                                                                                  • [USN-4953-1] AWStats vulnerabilities [01:56]
                                                                                                                                                                                                                                                                                                    • 3 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10)
                                                                                                                                                                                                                                                                                                      • CVE-2017-1000501
                                                                                                                                                                                                                                                                                                      • CVE-2020-35176
                                                                                                                                                                                                                                                                                                      • CVE-2020-29600
                                                                                                                                                                                                                                                                                                      • A-W-Stats - Advanced Web Statistics - log analyzer etc
                                                                                                                                                                                                                                                                                                      • Incomplete fix for old CVE-2017-1000501 - this itself was incomplete
                                                                                                                                                                                                                                                                                                      • too - hence CVE-2020-35176
                                                                                                                                                                                                                                                                                                        • Could be used to read an arbitrary file on the webserver via the config
                                                                                                                                                                                                                                                                                                        • parameter - and this could allow code execution as this was not
                                                                                                                                                                                                                                                                                                          sanitised properly
                                                                                                                                                                                                                                                                                                          [USN-4954-1] GNU C Library vulnerabilities [03:00]
                                                                                                                                                                                                                                                                                                          • 2 CVEs addressed in Xenial (16.04 LTS)
                                                                                                                                                                                                                                                                                                            • CVE-2009-5155
                                                                                                                                                                                                                                                                                                            • CVE-2020-6096
                                                                                                                                                                                                                                                                                                            • ARMv7 specific issue - memcpy() undefined behaviour if a negative length
                                                                                                                                                                                                                                                                                                            • were specified
                                                                                                                                                                                                                                                                                                            • DoS (assertion failure + abort) via crafted regex - so should not be
                                                                                                                                                                                                                                                                                                            • passing untrusted regular expressions to posix regex implementation
                                                                                                                                                                                                                                                                                                              [USN-4628-3] Intel Microcode vulnerabilities [04:08]
                                                                                                                                                                                                                                                                                                              • 3 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                • CVE-2020-8698
                                                                                                                                                                                                                                                                                                                • CVE-2020-8696
                                                                                                                                                                                                                                                                                                                • CVE-2020-8695
                                                                                                                                                                                                                                                                                                                • Episode 96 - RAPL side-channel etc - corresponding update for some Xeon
                                                                                                                                                                                                                                                                                                                • processors
                                                                                                                                                                                                                                                                                                                  [USN-4955-1] Please vulnerabilities [04:44]
                                                                                                                                                                                                                                                                                                                  • 3 CVEs addressed in Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                    • CVE-2021-31155
                                                                                                                                                                                                                                                                                                                    • CVE-2021-31154
                                                                                                                                                                                                                                                                                                                    • CVE-2021-31153
                                                                                                                                                                                                                                                                                                                    • sudo replacement written in rust
                                                                                                                                                                                                                                                                                                                    • Code analysis by Matthias Gerstner @ SuSE -
                                                                                                                                                                                                                                                                                                                      • arbitrary file existence test and open (eg could open /dev/zero and
                                                                                                                                                                                                                                                                                                                      • consume memory -> OOM)
                                                                                                                                                                                                                                                                                                                      • unsafe permissions for token directory - create world-writable - can
                                                                                                                                                                                                                                                                                                                      • allow an unprivileged user to get root privileges quite easily by
                                                                                                                                                                                                                                                                                                                        creating their own token as though they had authenticated
                                                                                                                                                                                                                                                                                                                      • pleaseedit uses predictable paths in /tmp - without symlink protections
                                                                                                                                                                                                                                                                                                                      • could allow a user to change ownership of arbitrary files as it would
                                                                                                                                                                                                                                                                                                                        follow symlinks
                                                                                                                                                                                                                                                                                                                      • rust is not a panacea - not all vulnerabilities are memory corruption and
                                                                                                                                                                                                                                                                                                                      • writing setuid root binaries is always going to be challenging
                                                                                                                                                                                                                                                                                                                        [LSN-0077-1] Linux kernel vulnerability [07:04]
                                                                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                          • CVE-2021-3492
                                                                                                                                                                                                                                                                                                                          • shiftfs specific vuln reported via ZDI (found by Vincent Dehors) - Ubuntu
                                                                                                                                                                                                                                                                                                                          • carry this as an out-of-tree patch so doesn’t affect upstream kernel
                                                                                                                                                                                                                                                                                                                            (used by LXD etc for UID mapping in containers)
                                                                                                                                                                                                                                                                                                                          • Failed to handle faults in copy_from_user() -> double-free or possible
                                                                                                                                                                                                                                                                                                                          • memory leak -> code execution/DoS
                                                                                                                                                                                                                                                                                                                            [USN-4956-1] Eventlet vulnerability [08:05]
                                                                                                                                                                                                                                                                                                                            • 1 CVEs addressed in Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                              • CVE-2021-21419
                                                                                                                                                                                                                                                                                                                              • Python eventlet (concurrent networking library)
                                                                                                                                                                                                                                                                                                                              • Used by a lot of other packages including openstack etc
                                                                                                                                                                                                                                                                                                                              • websocket peer could DoS via memory exhaustion by sending very large
                                                                                                                                                                                                                                                                                                                              • websocket frames
                                                                                                                                                                                                                                                                                                                                [USN-4957-1, USN-4957-2] DjVuLibre vulnerabilities [08:31]
                                                                                                                                                                                                                                                                                                                                • 5 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                  • CVE-2021-3500
                                                                                                                                                                                                                                                                                                                                  • CVE-2021-32493
                                                                                                                                                                                                                                                                                                                                  • CVE-2021-32492
                                                                                                                                                                                                                                                                                                                                  • CVE-2021-32491
                                                                                                                                                                                                                                                                                                                                  • CVE-2021-32490
                                                                                                                                                                                                                                                                                                                                  • document format alternative to pdf - for storing scanned documents etc
                                                                                                                                                                                                                                                                                                                                  • c++ - memory corruption vulns
                                                                                                                                                                                                                                                                                                                                    • heap buffer overflow
                                                                                                                                                                                                                                                                                                                                    • oob write
                                                                                                                                                                                                                                                                                                                                    • stack buffer overflow
                                                                                                                                                                                                                                                                                                                                    • oob read
                                                                                                                                                                                                                                                                                                                                    • integer overflow
                                                                                                                                                                                                                                                                                                                                    • DoS/RCE
                                                                                                                                                                                                                                                                                                                                    • [USN-4958-1] Caribou vulnerability [09:27]
                                                                                                                                                                                                                                                                                                                                      • Affecting Focal (20.04 LTS), Groovy (20.10)
                                                                                                                                                                                                                                                                                                                                      • Caribou on-screen keyboard could crash if given crafted input - in some
                                                                                                                                                                                                                                                                                                                                      • cases, this would then cause the screensaver to crash -> unauthenticated
                                                                                                                                                                                                                                                                                                                                        access to a desktop session
                                                                                                                                                                                                                                                                                                                                        • Thanks to Fabio Fantoni and Joshua Peisach (itzswirlz) from the Ubuntu
                                                                                                                                                                                                                                                                                                                                        • community for preparing these updates
                                                                                                                                                                                                                                                                                                                                          [USN-4959-1] GStreamer Base Plugins vulnerability [10:11]
                                                                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10)
                                                                                                                                                                                                                                                                                                                                            • CVE-2021-3522
                                                                                                                                                                                                                                                                                                                                            • OOB read on crafted input since failed to properly check size -> DoS
                                                                                                                                                                                                                                                                                                                                            • [USN-4945-2] Linux kernel (Raspberry Pi) vulnerabilities [10:18]
                                                                                                                                                                                                                                                                                                                                              • 7 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                • CVE-2021-30002
                                                                                                                                                                                                                                                                                                                                                • CVE-2021-29650
                                                                                                                                                                                                                                                                                                                                                • CVE-2021-29265
                                                                                                                                                                                                                                                                                                                                                • CVE-2021-28660
                                                                                                                                                                                                                                                                                                                                                • CVE-2021-28375
                                                                                                                                                                                                                                                                                                                                                • CVE-2021-28038
                                                                                                                                                                                                                                                                                                                                                • CVE-2020-25639
                                                                                                                                                                                                                                                                                                                                                • Episode 115 - regular kernels for Ubuntu 20.04 / 18.04 LTS
                                                                                                                                                                                                                                                                                                                                                • Update also for the raspi specific kernel build
                                                                                                                                                                                                                                                                                                                                                • Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                  1Password for Linux officially released [10:43]
                                                                                                                                                                                                                                                                                                                                                  • Episode 86 (August 2020) - beta was announced
                                                                                                                                                                                                                                                                                                                                                  • Now officially released, includes integration with browser extension to
                                                                                                                                                                                                                                                                                                                                                  • stay unlocked across both, use of regular desktop authentication to
                                                                                                                                                                                                                                                                                                                                                    unlock as well - e.g. fingerprint / yubikey etc - both opt-in features.
                                                                                                                                                                                                                                                                                                                                                  • Great desktop integration, theme, clipboard, GNOME Keyring / KDE Wallet,
                                                                                                                                                                                                                                                                                                                                                  • kernel keyring, DBUS API, integration with system lock / idle etc
                                                                                                                                                                                                                                                                                                                                                  • Feature parity with Windows and MacOS clients PLUS extra features like
                                                                                                                                                                                                                                                                                                                                                  • Secure file attachment, Watchtower, item archiving / deletion, quick find
                                                                                                                                                                                                                                                                                                                                                    and more
                                                                                                                                                                                                                                                                                                                                                  • Uses kernel keyring to store the key used to establish the connection
                                                                                                                                                                                                                                                                                                                                                  • between the browser and the desktop client
                                                                                                                                                                                                                                                                                                                                                  • Backend and lots of underlying libs written in Rust - UI is React
                                                                                                                                                                                                                                                                                                                                                  • Native packages for Ubuntu (Debian. CentOS, Fedora, RHEL)
                                                                                                                                                                                                                                                                                                                                                  • Snap
                                                                                                                                                                                                                                                                                                                                                  • Hiring [13:56]
                                                                                                                                                                                                                                                                                                                                                    Linux Cryptography and Security Engineer
                                                                                                                                                                                                                                                                                                                                                    • https://canonical.com/careers/2612092/linux-cryptography-and-security-engineer-remote
                                                                                                                                                                                                                                                                                                                                                    • Security Engineer - Ubuntu
                                                                                                                                                                                                                                                                                                                                                      • https://canonical.com/careers/2925180/security-engineer-ubuntu-remote
                                                                                                                                                                                                                                                                                                                                                      • Get in contact
                                                                                                                                                                                                                                                                                                                                                        • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                        • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                        • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                        • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                        • 16 min
                                                                                                                                                                                                                                                                                                                                                        • Episode 115
                                                                                                                                                                                                                                                                                                                                                          Overview

                                                                                                                                                                                                                                                                                                                                                          This week we look at some details of the 90 unique CVEs addressed across the supported Ubuntu releases and more.

                                                                                                                                                                                                                                                                                                                                                          This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                          90 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                          [USN-4934-2] Exim vulnerabilities [00:41]
                                                                                                                                                                                                                                                                                                                                                          • 16 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS)
                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-27216
                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-28025
                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-28024
                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-28022
                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-28020
                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-28017
                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-28016
                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-28015
                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-28014
                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-28013
                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-28012
                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-28011
                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-28009
                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-28008
                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-28007
                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-28026
                                                                                                                                                                                                                                                                                                                                                            • Episode 114
                                                                                                                                                                                                                                                                                                                                                            • [USN-4937-1] GNOME Autoar vulnerability [01:00]
                                                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10)
                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-28650
                                                                                                                                                                                                                                                                                                                                                                • Directory traversal due to failure to properly handle symlinks (result of
                                                                                                                                                                                                                                                                                                                                                                • incomplete fix for previous CVE-2020-36241)
                                                                                                                                                                                                                                                                                                                                                                  [USN-4936-1] Thunderbird vulnerabilities [01:47]
                                                                                                                                                                                                                                                                                                                                                                  • 5 CVEs addressed in Focal (20.04 LTS), Groovy (20.10)
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-29950
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-23978
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-23973
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-23969
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-23968
                                                                                                                                                                                                                                                                                                                                                                    • 78.8.1
                                                                                                                                                                                                                                                                                                                                                                    • If used a PGP key but then a failure occurred, TB would keep the
                                                                                                                                                                                                                                                                                                                                                                    • decrypted key in memory - on Ubuntu we enable Yama ptrace restrictions
                                                                                                                                                                                                                                                                                                                                                                      (ptrace_scope) - so this means processes can only ptrace their
                                                                                                                                                                                                                                                                                                                                                                      descendents by default and hence even other user-level processes cannot
                                                                                                                                                                                                                                                                                                                                                                      dump the memory of another process to say extract this private key
                                                                                                                                                                                                                                                                                                                                                                    • Various other CVEs inherited from Firefox
                                                                                                                                                                                                                                                                                                                                                                    • [USN-4938-1] Unbound vulnerabilities [03:21]
                                                                                                                                                                                                                                                                                                                                                                      • 13 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2020-28935
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-25042
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-25041
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-25040
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-25039
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-25038
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-25037
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-25036
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-25035
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-25034
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-25033
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-25032
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-25031
                                                                                                                                                                                                                                                                                                                                                                        • Validating, recursive DNS resolver
                                                                                                                                                                                                                                                                                                                                                                        • Remote DoS, command injection, RCE, local file overwrite etc
                                                                                                                                                                                                                                                                                                                                                                        • [USN-4939-1] WebKitGTK vulnerabilities [03:48]
                                                                                                                                                                                                                                                                                                                                                                          • 3 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10)
                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-1871
                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-1844
                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-1788
                                                                                                                                                                                                                                                                                                                                                                            • 1 logic issue, 2 memory corruption bugs - all leading to possible RCE
                                                                                                                                                                                                                                                                                                                                                                            • [USN-4940-1] PyYAML vulnerability [04:12]
                                                                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Focal (20.04 LTS), Groovy (20.10)
                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-14343
                                                                                                                                                                                                                                                                                                                                                                                • RCE when processing untrusted YAML - due to incomplete fix for previous
                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-1747 - that CVE not specifically patched in Ubuntu as either the
                                                                                                                                                                                                                                                                                                                                                                                  versions of pyyaml were too old to be affected or were based on upstream
                                                                                                                                                                                                                                                                                                                                                                                  releases that had already patched it
                                                                                                                                                                                                                                                                                                                                                                                  [USN-4941-1] Exiv2 vulnerabilities [04:35]
                                                                                                                                                                                                                                                                                                                                                                                  • 4 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-3482
                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-29470
                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-29458
                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-29457
                                                                                                                                                                                                                                                                                                                                                                                    • EXIF/IPTC/XMP metadata manipulation tool
                                                                                                                                                                                                                                                                                                                                                                                    • Heap buffer overflow or OOB read when writing metadata - so not so likely
                                                                                                                                                                                                                                                                                                                                                                                    • to be triggered by applications that are just extracting metadata etc
                                                                                                                                                                                                                                                                                                                                                                                    • Heap buffer overflow for handling EXIF in JPG images
                                                                                                                                                                                                                                                                                                                                                                                    • [USN-4942-1] Firefox vulnerability [05:09]
                                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-29952
                                                                                                                                                                                                                                                                                                                                                                                        • 88.0.1
                                                                                                                                                                                                                                                                                                                                                                                        • Race condition on destruction of WebRender components -> UAF? -> possible RCE
                                                                                                                                                                                                                                                                                                                                                                                        • [USN-4943-1] XStream vulnerabilities [05:32]
                                                                                                                                                                                                                                                                                                                                                                                          • 14 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-21351
                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-21350
                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-21349
                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-21348
                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-21347
                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-21346
                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-21345
                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-21344
                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-21343
                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-21342
                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-21341
                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-26259
                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-26258
                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-26217
                                                                                                                                                                                                                                                                                                                                                                                            • Episode 102 - B+F - corresponding fixes for those 3 CVEs for G
                                                                                                                                                                                                                                                                                                                                                                                            • Also a heap of others - denial of service, arbitrary code execution,
                                                                                                                                                                                                                                                                                                                                                                                            • arbitrary file deletion and server-side forgery attacks
                                                                                                                                                                                                                                                                                                                                                                                              [USN-4944-1] MariaDB vulnerabilities [06:04]
                                                                                                                                                                                                                                                                                                                                                                                              • Affecting Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                              • Latest upstream point releases rolling in a large number of security fixes:
                                                                                                                                                                                                                                                                                                                                                                                                • Ubuntu 18.04 LTS has been updated to MariaDB 10.1.48.
                                                                                                                                                                                                                                                                                                                                                                                                • Ubuntu 20.04 LTS has been updated to MariaDB 10.3.29.
                                                                                                                                                                                                                                                                                                                                                                                                • Ubuntu 20.10 has been updated to MariaDB 10.3.29.
                                                                                                                                                                                                                                                                                                                                                                                                • Ubuntu 21.04 has been updated to MariaDB 10.5.10.
                                                                                                                                                                                                                                                                                                                                                                                                • Thanks to Otto Kekäläinen from the MariaDB foundation for contributing
                                                                                                                                                                                                                                                                                                                                                                                                • and preparing these updates
                                                                                                                                                                                                                                                                                                                                                                                                  [USN-4945-1] Linux kernel vulnerabilities [06:33]
                                                                                                                                                                                                                                                                                                                                                                                                  • 7 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-30002
                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-29650
                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-29265
                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-28660
                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-28375
                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-28038
                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2020-25639
                                                                                                                                                                                                                                                                                                                                                                                                    • 5.4 (standard kernel for 20.04 LTS, HWE for 18.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-4946-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                      • 9 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-30002
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-29650
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-29265
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-29264
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-28688
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-28038
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-26931
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-26930
                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-20292
                                                                                                                                                                                                                                                                                                                                                                                                        • 4.15 (standard kernel for 18.04 LTS, HWE for 16.04 ESM, Azure for 14.04
                                                                                                                                                                                                                                                                                                                                                                                                        • ESM)
                                                                                                                                                                                                                                                                                                                                                                                                          [USN-4947-1] Linux kernel (OEM) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                          • 5 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-30002
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-29650
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-29646
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-28375
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-35519
                                                                                                                                                                                                                                                                                                                                                                                                            • 5.6 (OEM for 20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-4948-1] Linux kernel (OEM) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                              • 21 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-3483
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-31916
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-29657
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-29650
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-29649
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-29647
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-29646
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-29266
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-29264
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-28972
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-28971
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-28964
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-28952
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-28951
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-28688
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-25672
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-25671
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-25670
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-3491
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-3490
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-3489
                                                                                                                                                                                                                                                                                                                                                                                                                • 5.10 (OEM for 20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                • 3 Pwn2Own vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                  • Ryota Shiga - eBPF ring buffer
                                                                                                                                                                                                                                                                                                                                                                                                                  • Manfred Paul - eBPF bounds tracking on bitwise operations
                                                                                                                                                                                                                                                                                                                                                                                                                  • Billy Jheng Bing-Jhong - io_uring
                                                                                                                                                                                                                                                                                                                                                                                                                    • All OOB writes + info leaks -> local priv esc + code execution as
                                                                                                                                                                                                                                                                                                                                                                                                                    • root
                                                                                                                                                                                                                                                                                                                                                                                                                      [USN-4949-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                      • 12 CVEs addressed in Focal (20.04 LTS), Groovy (20.10)
                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-29650
                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-29646
                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-29266
                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-29265
                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-29264
                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-28375
                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-26931
                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-26930
                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2020-25639
                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-3491
                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-3490
                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-3489
                                                                                                                                                                                                                                                                                                                                                                                                                        • 5.8 (standard kernel for 20.10, HWE for 20.04 ESM, Azure for 14.04
                                                                                                                                                                                                                                                                                                                                                                                                                        • ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                          [USN-4950-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                          • 3 CVEs addressed in Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-3491
                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-3490
                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2021-3489
                                                                                                                                                                                                                                                                                                                                                                                                                            • 5.11
                                                                                                                                                                                                                                                                                                                                                                                                                            • Plus CAN ISOTP race condition - discovered by a Norbert Slusarek (high
                                                                                                                                                                                                                                                                                                                                                                                                                            • school student in Germany) - local privilege escalation
                                                                                                                                                                                                                                                                                                                                                                                                                              • Introduced via recent broadcast mode support (normally a CAN socket
                                                                                                                                                                                                                                                                                                                                                                                                                              • registers a particular CAN ID to receive and only gets those frames -
                                                                                                                                                                                                                                                                                                                                                                                                                                was only in 5.11 kernel so only affected hirsute) - this support has
                                                                                                                                                                                                                                                                                                                                                                                                                                been removed from the hirsute kernel until a proper fix comes from
                                                                                                                                                                                                                                                                                                                                                                                                                                upstream
                                                                                                                                                                                                                                                                                                                                                                                                                                [USN-4951-1] Flatpak vulnerability [10:16]
                                                                                                                                                                                                                                                                                                                                                                                                                                • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2021-21381
                                                                                                                                                                                                                                                                                                                                                                                                                                  • File forwarding issue which could allow an attacker to get access to
                                                                                                                                                                                                                                                                                                                                                                                                                                  • files that are not normally provided by the permissions granted to an app
                                                                                                                                                                                                                                                                                                                                                                                                                                  • Use special tokens in the Exec line of the desktop file for an app could
                                                                                                                                                                                                                                                                                                                                                                                                                                  • trick flatpak runtime into providing access to a file as though this had
                                                                                                                                                                                                                                                                                                                                                                                                                                    been explicitly granted by the user
                                                                                                                                                                                                                                                                                                                                                                                                                                    • snapd generates desktop files so less likely to be affected by this
                                                                                                                                                                                                                                                                                                                                                                                                                                    • sort of issue - less untrusted input in general (but perhaps also less
                                                                                                                                                                                                                                                                                                                                                                                                                                      flexible)
                                                                                                                                                                                                                                                                                                                                                                                                                                      Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                      Hiring [11:47]
                                                                                                                                                                                                                                                                                                                                                                                                                                      Linux Cryptography and Security Engineer
                                                                                                                                                                                                                                                                                                                                                                                                                                      • https://canonical.com/careers/2612092/linux-cryptography-and-security-engineer-remote
                                                                                                                                                                                                                                                                                                                                                                                                                                      • Security Engineer - Ubuntu
                                                                                                                                                                                                                                                                                                                                                                                                                                        • https://canonical.com/careers/2925180/security-engineer-ubuntu-remote
                                                                                                                                                                                                                                                                                                                                                                                                                                        • Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                          • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                          • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                                                                          • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                                                                                          • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                          • 13 min
                                                                                                                                                                                                                                                                                                                                                                                                                                          • Episode 114
                                                                                                                                                                                                                                                                                                                                                                                                                                            Overview

                                                                                                                                                                                                                                                                                                                                                                                                                                            This week we look at the response from the Linux Technical Advisory Board

                                                                                                                                                                                                                                                                                                                                                                                                                                            to the UMN Linux kernel incident, plus we cover the 21Nails Exim
                                                                                                                                                                                                                                                                                                                                                                                                                                            vulnerabilities as well as updates for Bind, Samba, OpenVPN and more.

                                                                                                                                                                                                                                                                                                                                                                                                                                            This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                                                                            40 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                                                                                            [USN-4928-1] GStreamer Good Plugins vulnerabilities [00:40]
                                                                                                                                                                                                                                                                                                                                                                                                                                            • 2 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2021-3498
                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2021-3497
                                                                                                                                                                                                                                                                                                                                                                                                                                              • UAF or heap corruption when handling crafted Matroska files - crash / RCE
                                                                                                                                                                                                                                                                                                                                                                                                                                              • [USN-4929-1] Bind vulnerabilities [01:18]
                                                                                                                                                                                                                                                                                                                                                                                                                                                • 3 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2021-25216
                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2021-25215
                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2021-25214
                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 2 possible crasher bugs (failed assertions) -> DoS, 1 buffer over-read or
                                                                                                                                                                                                                                                                                                                                                                                                                                                  • possible overflow -> crash / RCE
                                                                                                                                                                                                                                                                                                                                                                                                                                                    [USN-4930-1] Samba vulnerability [02:08]
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 1 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2021-20254
                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Failed to properly handle negative idmap cache entries - could then end
                                                                                                                                                                                                                                                                                                                                                                                                                                                      • up with incorrect group entries and as such could possibly allow a user
                                                                                                                                                                                                                                                                                                                                                                                                                                                        to access / modify files they should not have access to
                                                                                                                                                                                                                                                                                                                                                                                                                                                        [USN-4931-1] Samba vulnerabilities [02:51]
                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 4 CVEs addressed in Trusty ESM (14.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-20254
                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2020-14383
                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2020-14323
                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2020-14318
                                                                                                                                                                                                                                                                                                                                                                                                                                                          • negative idmap cache entries issue plus some older vulns (Episode 95)
                                                                                                                                                                                                                                                                                                                                                                                                                                                          • [LSN-0076-1] Linux kernel vulnerability [03:03]
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 2 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2021-29154
                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2021-3493
                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 2 local user privesc vulns fixed:
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • BPF JIT branch displacement issue (Episode 112)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Overlayfs / file system capabilities interaction
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-4918-3] ClamAV regression [03:52]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 3 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-1405
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-1404
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-1252
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Previous clamav update (back in April ) introduced a regression where clamdscan
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • would crash if called with –multiscan and –fdpass AND you had an
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ExcludePath configured in the configuration - backported the upstream
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      commit from the development branch to fix this
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [USN-4932-1] Django vulnerability [04:30]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-31542
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Directory traversal via uploaded files with crafted names
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-4933-1] OpenVPN vulnerabilities [04:47]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 2 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-15078
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2020-11810
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Race condition in handling of data packets could allow an attacker to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • inject a packet using a victim’s peer-id before the crypto channel is
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              properly initialised - could cause the victim’s connection to be dropped
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              (DoS) but doesn’t appear to expose any sensitive info etc
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Attackers could possibly bypass auth on control channel and hence leak info
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-4934-1] Exim vulnerabilities [05:39]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 21 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-27216
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28026
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28025
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28024
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28023
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28022
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28021
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28020
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28019
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28018
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28017
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28016
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28015
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28014
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28013
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28012
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28011
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28010
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28009
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28008
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-28007
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Qualsys - 21Nails - various vulns which could be chained together to get
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • full remote unauthenticated RCE and root privesc
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Full write-up
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Possibly 60% of internet mail servers run exim and 4 million are publicly
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • accessible
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Previously has been a target of Sandworm
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • In the process of preparing the updates for 16.04 / 14.04 ESM - expect to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • be available in the next day or 2 so most likely will already be out by
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    the time you are listening to this
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [USN-4935-1] NVIDIA graphics drivers vulnerabilities [07:58]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 2 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2021-1077
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2021-1076
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Not much detail from NVIDIA
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • improper access control -> DoS, infoleak or data corruption -> privesc etc
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • incorrect use of reference counting -> DoS (crash?) (UAF?)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Linux Technical Advisory Board response to UMN incident [08:56]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Covered in Episode 113
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • https://lore.kernel.org/lkml/202105051005.49BFABCE@keescook/
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Kees Cook (previously inaugural Tech Lead of Ubuntu Security Team) posted
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • to LKML the Tab’s report (various folks from across the Linux Kernel
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            community, including from Red Hat, Google, Canonical and others)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Detailed timeline of events, identification of the “hypocrite” commits in
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • question
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Recommendations going forward
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • UMN must improve quality of their submissions since even for a lot of
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • what were good-faith patches, they actually had issues and either
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              didn’t fix the purported issue or tried to fix a non-issue
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • TAB will create a best-practices document for all research groups when
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • working with the kernel or other open source projects
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Hiring [11:36]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              AppArmor Security Engineer
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • https://canonical.com/careers/2114847/apparmor-security-engineer-remote
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Linux Cryptography and Security Engineer
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • https://canonical.com/careers/2612092/linux-cryptography-and-security-engineer-remote
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Security Engineer - Ubuntu
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • https://canonical.com/careers/2925180/security-engineer-ubuntu-remote
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 13 min

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    About Ubuntu Security Podcast

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    From the publisher's feed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    A fortnightly podcast talking about the latest developments and updates from the Ubuntu Security team, including a summary of recent security vulnerabilities and fixes as well as a discussion on some…