Ubuntu Security Podcast

Ubuntu Security Podcast

By Ubuntu Security TeamTechnology
Download on the App Store

Ubuntu Security Podcast episodes

  • Episode 233
    Overview

    This week we take a look at the recent Crowdstrike outage and what we can learn

    from it compared to the testing and release process for security updates in
    Ubuntu, plus we cover details of vulnerabilities in poppler, phpCAS, EDK II,
    Python, OpenJDK and one package with over 300 CVE fixes in a single update.

    This week in Ubuntu Security Updates

    462 unique CVEs addressed

    [USN-6915-1] poppler vulnerability (01:35)
    • 1 CVEs addressed in Jammy (22.04 LTS), Noble (24.04 LTS)
      • CVE-2024-6239
      • Installed by default in Ubuntu due to use by cups
      • PDF document format describes a Catalog which has a tree of destinations -
      • essentially hyperlinks within the document. These can be either a page number
        etc or a named location within the document. If open a crafted document with a
        missing name property for a destination - name would then be NULL and would
        trigger a NULL ptr deref -> crash -> DoS
        [USN-6913-1] phpCAS vulnerability (02:26)
        • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
          • CVE-2022-39369
          • Authentication library for PHP to allow PHP applications to authenticates
          • users against a Central Authentication Server (ie. SSO).
          • When used for SSO, a client who is trying to use a web application gets
          • directed to the CAS. The CAS then authenticates the user and returns a service
            ticket - the client then needs to validate this ticket with the CAS since it
            could have possibly been injected via the application. To do this, pass the
            ticket along with its own service identifier to CAS - and if this succeeds is
            provided with the details of which user was authenticated etc.
          • For clients, previously would use HTTP headers to determine where the CAS
          • server was to authenticate the ticket. Since these can be manipulated by a
            malicious application, could essentially redirect the client to send the
            ticket to the attacker who could then use that to impersonate the client and
            login as the user.
          • Fix requires a refactor to include an additional API parameter which specifies
          • either a fixed CAS server for the client to use, or a mechanism to
            auto-discover this in a secure way - either way, applications using phpCAS now
            need to be updated.
            [USN-6914-1] OCS Inventory vulnerability
            • 1 CVEs addressed in Jammy (22.04 LTS)
              • CVE-2022-39369
              • Same as above since has an embedded copy of phpCAS
              • [USN-6916-1] Lua vulnerabilities (04:44)
                • 2 CVEs addressed in Jammy (22.04 LTS)
                  • CVE-2022-33099
                  • CVE-2022-28805
                  • Heap buffer over-read and a possible heap buffer over-flow via recursive error
                  • handling - looks like both require to be interpreting malicious code
                    [USN-6920-1] EDK II vulnerabilities (05:04)
                    • 5 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                      • CVE-2019-0160
                      • CVE-2018-3613
                      • CVE-2018-12183
                      • CVE-2018-12182
                      • CVE-2017-5731
                      • UEFI firmware implementation in qemu etc
                      • Various missing bounds checks -> stack and heap buffer overflows -> DoS or
                      • code execution in BIOS context -> privilege escalation within VM
                        [USN-6928-1] Python vulnerabilities (05:49)
                        • 2 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                          • CVE-2024-4032
                          • CVE-2024-0397
                          • Memory race in the ssl module - can call into various functions to get
                          • certificate information at the same time as certs are loaded if happening to
                            be doing a TLS handshake with a certificate directory configured - all via
                            different threads. Python would then possibly return inconsistent results
                            leading to various issues
                          • Occurs since ssl module is implemented in C to interface with openssl and did
                          • not properly lock access to the certificate store
                            [USN-6929-1, USN-6930-1] OpenJDK 8 and OpenJDK 11 vulnerabilities (06:52)
                            • 6 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS)
                              • CVE-2024-21147
                              • CVE-2024-21145
                              • CVE-2024-21144
                              • CVE-2024-21140
                              • CVE-2024-21138
                              • CVE-2024-21131
                              • Latest upstream releases of OpenJDK 8 and 11
                              • 8u422-b05-1, 11.0.24+8
                              • Fixes various issues in the Hotspot and Concurrency components
                              • [USN-6931-1, USN-6932-1] OpenJDK 17 and OpenJDK 21 vulnerabilities (07:11)
                                • 5 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS)
                                  • CVE-2024-21147
                                  • CVE-2024-21145
                                  • CVE-2024-21140
                                  • CVE-2024-21138
                                  • CVE-2024-21131
                                  • Latest upstream releases of OpenJDK 17 and 21
                                  • 17.0.12+7, 21.0.4+7
                                  • Fixes the same issues in the Hotspot component
                                  • [USN-6934-1] MySQL vulnerabilities (07:29)
                                    • 15 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS)
                                      • CVE-2024-21185
                                      • CVE-2024-21179
                                      • CVE-2024-21177
                                      • CVE-2024-21173
                                      • CVE-2024-21171
                                      • CVE-2024-21165
                                      • CVE-2024-21163
                                      • CVE-2024-21162
                                      • CVE-2024-21142
                                      • CVE-2024-21134
                                      • CVE-2024-21130
                                      • CVE-2024-21129
                                      • CVE-2024-21127
                                      • CVE-2024-21125
                                      • CVE-2024-20996
                                      • Also latest upstream release
                                      • 8.0.39
                                      • Bug fixes, possible new features and incompatible changes - consult release
                                      • notes:
                                        • https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-38.html
                                        • https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-39.html
                                        • https://www.oracle.com/security-alerts/cpujul2024.html
                                        • [USN-6917-1] Linux kernel vulnerabilities (07:57)
                                          • 156 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                            • CVE-2024-35933
                                            • CVE-2024-35910
                                            • CVE-2024-27393
                                            • CVE-2024-27004
                                            • CVE-2024-27396
                                            • CVE-2024-36029
                                            • CVE-2024-26955
                                            • CVE-2024-35976
                                            • CVE-2024-26966
                                            • CVE-2024-26811
                                            • CVE-2024-35871
                                            • CVE-2023-52699
                                            • CVE-2024-35796
                                            • CVE-2024-35851
                                            • CVE-2024-35885
                                            • CVE-2024-35813
                                            • CVE-2024-35789
                                            • CVE-2024-35825
                                            • CVE-2024-26994
                                            • CVE-2024-35815
                                            • CVE-2024-27395
                                            • CVE-2024-26981
                                            • CVE-2024-35886
                                            • CVE-2024-26931
                                            • CVE-2024-35791
                                            • CVE-2024-35849
                                            • CVE-2024-35978
                                            • CVE-2024-35895
                                            • CVE-2024-35918
                                            • CVE-2024-35902
                                            • CVE-2024-26926
                                            • CVE-2024-35934
                                            • CVE-2024-35807
                                            • CVE-2024-35805
                                            • CVE-2024-36008
                                            • CVE-2024-26950
                                            • CVE-2024-26973
                                            • CVE-2024-35898
                                            • CVE-2024-35955
                                            • CVE-2024-36004
                                            • CVE-2024-36006
                                            • CVE-2024-35990
                                            • CVE-2024-35944
                                            • CVE-2024-36007
                                            • CVE-2024-35896
                                            • CVE-2024-35819
                                            • CVE-2024-26988
                                            • CVE-2024-35872
                                            • CVE-2024-36025
                                            • CVE-2024-26957
                                            • CVE-2024-35897
                                            • CVE-2024-27016
                                            • CVE-2024-35806
                                            • CVE-2024-35927
                                            • CVE-2022-48808
                                            • CVE-2024-35960
                                            • CVE-2024-27001
                                            • CVE-2024-35970
                                            • CVE-2024-35988
                                            • CVE-2024-36005
                                            • CVE-2024-35821
                                            • CVE-2024-35925
                                            • CVE-2024-26961
                                            • CVE-2024-35817
                                            • CVE-2024-26922
                                            • CVE-2024-26976
                                            • CVE-2024-35899
                                            • CVE-2024-35984
                                            • CVE-2024-26929
                                            • CVE-2024-27018
                                            • CVE-2024-35907
                                            • CVE-2024-35884
                                            • CVE-2023-52488
                                            • CVE-2024-35982
                                            • CVE-2024-26934
                                            • CVE-2024-26935
                                            • CVE-2024-35973
                                            • CVE-2024-26958
                                            • CVE-2024-27008
                                            • CVE-2024-35809
                                            • CVE-2024-26951
                                            • CVE-2024-35900
                                            • CVE-2024-35888
                                            • CVE-2024-26965
                                            • CVE-2024-26828
                                            • CVE-2024-35935
                                            • CVE-2024-35857
                                            • CVE-2024-26642
                                            • CVE-2024-26989
                                            • CVE-2024-35893
                                            • CVE-2024-35877
                                            • CVE-2024-27009
                                            • CVE-2024-35785
                                            • CVE-2024-35905
                                            • CVE-2024-27020
                                            • CVE-2024-35901
                                            • CVE-2024-26956
                                            • CVE-2024-26977
                                            • CVE-2024-26969
                                            • CVE-2024-26810
                                            • CVE-2024-26813
                                            • CVE-2024-35930
                                            • CVE-2024-26970
                                            • CVE-2024-26687
                                            • CVE-2024-27015
                                            • CVE-2024-35847
                                            • CVE-2024-26999
                                            • CVE-2024-35940
                                            • CVE-2024-35890
                                            • CVE-2024-26814
                                            • CVE-2024-35958
                                            • CVE-2024-35804
                                            • CVE-2024-26629
                                            • CVE-2024-26974
                                            • CVE-2023-52880
                                            • CVE-2024-26937
                                            • CVE-2024-35922
                                            • CVE-2024-35854
                                            • CVE-2024-27013
                                            • CVE-2024-35853
                                            • CVE-2024-27000
                                            • CVE-2024-35989
                                            • CVE-2024-35852
                                            • CVE-2024-35823
                                            • CVE-2024-36020
                                            • CVE-2024-36031
                                            • CVE-2024-26923
                                            • CVE-2024-26654
                                            • CVE-2024-26925
                                            • CVE-2024-35855
                                            • CVE-2024-35997
                                            • CVE-2024-35822
                                            • CVE-2024-27019
                                            • CVE-2024-35938
                                            • CVE-2024-35915
                                            • CVE-2024-35912
                                            • CVE-2024-35936
                                            • CVE-2024-35969
                                            • CVE-2024-27059
                                            • CVE-2024-26964
                                            • CVE-2024-27437
                                            • CVE-2024-26960
                                            • CVE-2024-35950
                                            • CVE-2024-26817
                                            • CVE-2024-26984
                                            • CVE-2024-26812
                                            • CVE-2024-35879
                                            • CVE-2024-26996
                                            • CVE-2024-26993
                                            • CVE-2024-25739
                                            • CVE-2024-24861
                                            • CVE-2024-24859
                                            • CVE-2024-24858
                                            • CVE-2024-24857
                                            • CVE-2024-23307
                                            • CVE-2022-38096
                                            • 5.15 - Azure + FDE (CVM)
                                            • [USN-6918-1] Linux kernel vulnerabilities
                                              • 180 CVEs addressed in Noble (24.04 LTS)
                                                • CVE-2024-24859
                                                • CVE-2024-24858
                                                • CVE-2024-24857
                                                • CVE-2024-35932
                                                • CVE-2024-35937
                                                • CVE-2024-27006
                                                • CVE-2024-35960
                                                • CVE-2024-27011
                                                • CVE-2024-35924
                                                • CVE-2024-35946
                                                • CVE-2024-35942
                                                • CVE-2024-35921
                                                • CVE-2024-35908
                                                • CVE-2024-26811
                                                • CVE-2024-27008
                                                • CVE-2024-35871
                                                • CVE-2024-36019
                                                • CVE-2024-35965
                                                • CVE-2024-35973
                                                • CVE-2024-26981
                                                • CVE-2024-27009
                                                • CVE-2024-27019
                                                • CVE-2024-36022
                                                • CVE-2024-35910
                                                • CVE-2024-35907
                                                • CVE-2024-35860
                                                • CVE-2024-35951
                                                • CVE-2024-26924
                                                • CVE-2024-26921
                                                • CVE-2024-35901
                                                • CVE-2024-35972
                                                • CVE-2024-35889
                                                • CVE-2024-27017
                                                • CVE-2024-35913
                                                • CVE-2024-35936
                                                • CVE-2024-36025
                                                • CVE-2024-35961
                                                • CVE-2024-35977
                                                • CVE-2024-35902
                                                • CVE-2024-26817
                                                • CVE-2024-26994
                                                • CVE-2023-52699
                                                • CVE-2024-35868
                                                • CVE-2024-35899
                                                • CVE-2024-35888
                                                • CVE-2024-26995
                                                • CVE-2024-35865
                                                • CVE-2024-26993
                                                • CVE-2024-35863
                                                • CVE-2024-35970
                                                • CVE-2024-35943
                                                • CVE-2024-35875
                                                • CVE-2024-35978
                                                • CVE-2024-27005
                                                • CVE-2024-35909
                                                • CVE-2024-35957
                                                • CVE-2024-35950
                                                • CVE-2024-26986
                                                • CVE-2024-36020
                                                • CVE-2024-35952
                                                • CVE-2024-26928
                                                • CVE-2024-35878
                                                • CVE-2024-35954
                                                • CVE-2024-26998
                                                • CVE-2024-36024
                                                • CVE-2024-26936
                                                • CVE-2024-27018
                                                • CVE-2024-35900
                                                • CVE-2024-35940
                                                • CVE-2024-35985
                                                • CVE-2024-35944
                                                • CVE-2024-35958
                                                • CVE-2024-35864
                                                • CVE-2024-35975
                                                • CVE-2024-27002
                                                • CVE-2024-36018
                                                • CVE-2024-35974
                                                • CVE-2024-26926
                                                • CVE-2024-35877
                                                • CVE-2024-35916
                                                • CVE-2024-35934
                                                • CVE-2024-35930
                                                • CVE-2024-35898
                                                • CVE-2024-35893
                                                • CVE-2024-35887
                                                • CVE-2024-35929
                                                • CVE-2024-26923
                                                • CVE-2024-35911
                                                • CVE-2024-35919
                                                • CVE-2024-26984
                                                • CVE-2024-27016
                                                • CVE-2024-35926
                                                • CVE-2024-35872
                                                • CVE-2024-35922
                                                • CVE-2024-27007
                                                • CVE-2024-35931
                                                • CVE-2024-36021
                                                • CVE-2024-35953
                                                • CVE-2024-27004
                                                • CVE-2024-27001
                                                • CVE-2024-27014
                                                • CVE-2024-35866
                                                • CVE-2024-27021
                                                • CVE-2024-35870
                                                • CVE-2024-35925
                                                • CVE-2024-35891
                                                • CVE-2024-26982
                                                • CVE-2024-35879
                                                • CVE-2024-35979
                                                • CVE-2024-35912
                                                • CVE-2024-35982
                                                • CVE-2024-27015
                                                • CVE-2024-26985
                                                • CVE-2024-35861
                                                • CVE-2024-35939
                                                • CVE-2024-27003
                                                • CVE-2024-35945
                                                • CVE-2024-35967
                                                • CVE-2024-35966
                                                • CVE-2024-26983
                                                • CVE-2024-35894
                                                • CVE-2024-35896
                                                • CVE-2024-36027
                                                • CVE-2024-35895
                                                • CVE-2024-26987
                                                • CVE-2024-35873
                                                • CVE-2024-26996
                                                • CVE-2024-26991
                                                • CVE-2024-27013
                                                • CVE-2024-36026
                                                • CVE-2024-26922
                                                • CVE-2024-35897
                                                • CVE-2024-35917
                                                • CVE-2024-35968
                                                • CVE-2024-35890
                                                • CVE-2024-35904
                                                • CVE-2024-35867
                                                • CVE-2024-35933
                                                • CVE-2024-35918
                                                • CVE-2024-35920
                                                • CVE-2024-26997
                                                • CVE-2024-35981
                                                • CVE-2024-35963
                                                • CVE-2024-26989
                                                • CVE-2024-26999
                                                • CVE-2024-35892
                                                • CVE-2024-27010
                                                • CVE-2024-26992
                                                • CVE-2024-35935
                                                • CVE-2024-27022
                                                • CVE-2024-35971
                                                • CVE-2024-35956
                                                • CVE-2024-35862
                                                • CVE-2024-35969
                                                • CVE-2024-27012
                                                • CVE-2024-26990
                                                • CVE-2024-35885
                                                • CVE-2024-26925
                                                • CVE-2024-35905
                                                • CVE-2024-35914
                                                • CVE-2024-35884
                                                • CVE-2024-35927
                                                • CVE-2024-35882
                                                • CVE-2024-26980
                                                • CVE-2024-35964
                                                • CVE-2024-35955
                                                • CVE-2024-27020
                                                • CVE-2024-35980
                                                • CVE-2024-35903
                                                • CVE-2024-35976
                                                • CVE-2024-35886
                                                • CVE-2024-35883
                                                • CVE-2024-35959
                                                • CVE-2024-35915
                                                • CVE-2024-35880
                                                • CVE-2024-27000
                                                • CVE-2024-35938
                                                • CVE-2024-35869
                                                • CVE-2024-36023
                                                • CVE-2024-26988
                                                • 6.8 - Oracle
                                                • [USN-6919-1] Linux kernel vulnerabilities
                                                  • 304 CVEs addressed in Jammy (22.04 LTS)
                                                    • CVE-2024-35976
                                                    • CVE-2023-52880
                                                    • CVE-2024-35849
                                                    • CVE-2024-27073
                                                    • CVE-2024-35934
                                                    • CVE-2024-27038
                                                    • CVE-2024-26973
                                                    • CVE-2024-35853
                                                    • CVE-2024-27047
                                                    • CVE-2024-36007
                                                    • CVE-2024-27024
                                                    • CVE-2024-26750
                                                    • CVE-2024-26833
                                                    • CVE-2024-26960
                                                    • CVE-2024-26929
                                                    • CVE-2023-52488
                                                    • CVE-2024-27417
                                                    • CVE-2024-26922
                                                    • CVE-2024-26863
                                                    • CVE-2024-35890
                                                    • CVE-2024-27015
                                                    • CVE-2024-27395
                                                    • CVE-2024-26779
                                                    • CVE-2024-27419
                                                    • CVE-2024-27013
                                                    • CVE-2024-26981
                                                    • CVE-2024-26798
                                                    • CVE-2024-26895
                                                    • CVE-2024-35922
                                                    • CVE-2023-52699
                                                    • CVE-2024-26883
                                                    • CVE-2024-35871
                                                    • CVE-2024-27410
                                                    • CVE-2024-26884
                                                    • CVE-2024-26885
                                                    • CVE-2024-27074
                                                    • CVE-2024-26751
                                                    • CVE-2024-26857
                                                    • CVE-2024-26848
                                                    • CVE-2024-26901
                                                    • CVE-2024-35844
                                                    • CVE-2024-35809
                                                    • CVE-2024-26687
                                                    • CVE-2024-35988
                                                    • CVE-2024-26835
                                                    • CVE-2024-26764
                                                    • CVE-2024-27020
                                                    • CVE-2024-35907
                                                    • CVE-2024-35886
                                                    • CVE-2024-27077
                                                    • CVE-2024-26787
                                                    • CVE-2024-26950
                                                    • CVE-2024-26974
                                                    • CVE-2024-35905
                                                    • CVE-2024-27008
                                                    • CVE-2024-26744
                                                    • CVE-2024-35935
                                                    • CVE-2024-26988
                                                    • CVE-2024-26748
                                                    • CVE-2024-26776
                                                    • CVE-2024-26907
                                                    • CVE-2024-27053
                                                    • CVE-2024-35970
                                                    • CVE-2024-35950
                                                    • CVE-2024-35854
                                                    • CVE-2024-35822
                                                    • CVE-2024-26961
                                                    • CVE-2024-26733
                                                    • CVE-2024-26773
                                                    • CVE-2024-27390
                                                    • CVE-2024-35888
                                                    • CVE-2024-36029
                                                    • CVE-2024-26643
                                                    • CVE-2024-35821
                                                    • CVE-2024-35819
                                                    • CVE-2024-26809
                                                    • CVE-2024-35984
                                                    • CVE-2024-26851
                                                    • CVE-2024-35940
                                                    • CVE-2024-26654
                                                    • CVE-2024-35910
                                                    • CVE-2024-26891
                                                    • CVE-2024-26793
                                                    • CVE-2024-35938
                                                    • CVE-2024-26736
                                                    • CVE-2024-26583
                                                    • CVE-2024-26870
                                                    • CVE-2024-35828
                                                    • CVE-2024-35885
                                                    • CVE-2024-35958
                                                    • CVE-2024-26889
                                                    • CVE-2024-35899
                                                    • CVE-2024-26839
                                                    • CVE-2024-26894
                                                    • CVE-2024-26937
                                                    • CVE-2024-35925
                                                    • CVE-2024-35933
                                                    • CVE-2024-26771
                                                    • CVE-2024-26923
                                                    • CVE-2024-26852
                                                    • CVE-2024-26924
                                                    • CVE-2024-26872
                                                    • CVE-2024-26774
                                                    • CVE-2024-35930
                                                    • CVE-2024-27065
                                                    • CVE-2024-26993
                                                    • CVE-2024-27034
                                                    • CVE-2024-36020
                                                    • CVE-2024-26802
                                                    • CVE-2024-26976
                                                    • CVE-2022-48808
                                                    • CVE-2024-35847
                                                    • CVE-2024-26996
                                                    • CVE-2024-36025
                                                    • CVE-2023-52652
                                                    • CVE-2024-27403
                                                    • CVE-2023-52447
                                                    • CVE-2024-27037
                                                    • CVE-2024-27413
                                                    • CVE-2024-26749
                                                    • CVE-2024-26956
                                                    • CVE-2024-26958
                                                    • CVE-2024-26754
                                                    • CVE-2024-26812
                                                    • CVE-2024-26772
                                                    • CVE-2024-27436
                                                    • CVE-2024-27437
                                                    • CVE-2024-35912
                                                    • CVE-2024-35805
                                                    • CVE-2024-26845
                                                    • CVE-2024-35990
                                                    • CVE-2024-35791
                                                    • CVE-2024-26906
                                                    • CVE-2024-27039
                                                    • CVE-2024-26915
                                                    • CVE-2024-26970
                                                    • CVE-2024-26782
                                                    • CVE-2024-26813
                                                    • CVE-2023-52645
                                                    • CVE-2024-26935
                                                    • CVE-2024-27076
                                                    • CVE-2024-35823
                                                    • CVE-2024-26743
                                                    • CVE-2024-26846
                                                    • CVE-2024-26811
                                                    • CVE-2024-26989
                                                    • CVE-2024-26642
                                                    • CVE-2024-26659
                                                    • CVE-2024-26766
                                                    • CVE-2024-27393
                                                    • CVE-2024-26859
                                                    • CVE-2024-35898
                                                    • CVE-2024-35893
                                                    • CVE-2023-52640
                                                    • CVE-2024-26795
                                                    • CVE-2024-27009
                                                    • CVE-2024-26791
                                                    • CVE-2024-27043
                                                    • CVE-2024-26934
                                                    • CVE-2024-27051
                                                    • CVE-2024-26804
                                                    • CVE-2024-26878
                                                    • CVE-2024-27030
                                                    • CVE-2024-27000
                                                    • CVE-2024-26777
                                                    • CVE-2024-35825
                                                    • CVE-2024-27415
                                                    • CVE-2024-27001
                                                    • CVE-2024-27004
                                                    • CVE-2024-26769
                                                    • CVE-2024-26816
                                                    • CVE-2024-35807
                                                    • CVE-2024-35900
                                                    • CVE-2024-35851
                                                    • CVE-2024-27052
                                                    • CVE-2024-26805
                                                    • CVE-2024-35804
                                                    • CVE-2024-35944
                                                    • CVE-2024-35895
                                                    • CVE-2024-26897
                                                    • CVE-2024-27045
                                                    • CVE-2024-26814
                                                    • CVE-2024-26801
                                                    • CVE-2024-26874
                                                    • CVE-2024-35982
                                                    • CVE-2024-35915
                                                    • CVE-2024-26820
                                                    • CVE-2024-26603
                                                    • CVE-2024-35997
                                                    • CVE-2024-26688
                                                    • CVE-2024-27054
                                                    • CVE-2024-26828
                                                    • CVE-2024-35857
                                                    • CVE-2023-52662
                                                    • CVE-2024-35989
                                                    • CVE-2024-36005
                                                    • CVE-2024-35785
                                                    • CVE-2024-27396
                                                    • CVE-2024-35884
                                                    • CVE-2023-52650
                                                    • CVE-2024-26882
                                                    • CVE-2024-26879
                                                    • CVE-2024-26898
                                                    • CVE-2024-27388
                                                    • CVE-2024-35879
                                                    • CVE-2024-35918
                                                    • CVE-2024-35978
                                                    • CVE-2024-26585
                                                    • CVE-2024-35872
                                                    • CVE-2023-52497
                                                    • CVE-2024-26778
                                                    • CVE-2024-26999
                                                    • CVE-2024-27046
                                                    • CVE-2023-52434
                                                    • CVE-2024-26862
                                                    • CVE-2024-26810
                                                    • CVE-2024-35796
                                                    • CVE-2024-35960
                                                    • CVE-2024-35969
                                                    • CVE-2024-26966
                                                    • CVE-2024-26856
                                                    • CVE-2024-35936
                                                    • CVE-2024-35955
                                                    • CVE-2024-26763
                                                    • CVE-2024-35806
                                                    • CVE-2024-27059
                                                    • CVE-2024-35855
                                                    • CVE-2024-36008
                                                    • CVE-2024-27075
                                                    • CVE-2023-52620
                                                    • CVE-2024-26931
                                                    • CVE-2024-35813
                                                    • CVE-2024-26788
                                                    • CVE-2024-27412
                                                    • CVE-2024-26861
                                                    • CVE-2024-36004
                                                    • CVE-2024-26951
                                                    • CVE-2024-26903
                                                    • CVE-2024-26584
                                                    • CVE-2024-35877
                                                    • CVE-2024-26792
                                                    • CVE-2024-27416
                                                    • CVE-2024-27432
                                                    • CVE-2024-26651
                                                    • CVE-2024-35852
                                                    • CVE-2024-35973
                                                    • CVE-2023-52656
                                                    • CVE-2024-26965
                                                    • CVE-2024-26969
                                                    • CVE-2024-26840
                                                    • CVE-2024-26817
                                                    • CVE-2024-27028
                                                    • CVE-2024-26752
                                                    • CVE-2024-27016
                                                    • CVE-2023-52641
                                                    • CVE-2024-35789
                                                    • CVE-2024-27078
                                                    • CVE-2024-26994
                                                    • CVE-2024-26629
                                                    • CVE-2024-26803
                                                    • CVE-2024-26977
                                                    • CVE-2024-35830
                                                    • CVE-2024-27019
                                                    • CVE-2024-26957
                                                    • CVE-2024-36006
                                                    • CVE-2024-35817
                                                    • CVE-2024-26601
                                                    • CVE-2024-35845
                                                    • CVE-2024-35897
                                                    • CVE-2024-27414
                                                    • CVE-2024-26855
                                                    • CVE-2024-26877
                                                    • CVE-2024-35829
                                                    • CVE-2024-35896
                                                    • CVE-2024-26875
                                                    • CVE-2024-27405
                                                    • CVE-2024-26747
                                                    • CVE-2023-52644
                                                    • CVE-2024-26881
                                                    • CVE-2024-26735
                                                    • CVE-2024-26843
                                                    • CVE-2024-26926
                                                    • CVE-2024-26880
                                                    • CVE-2024-26964
                                                    • CVE-2024-27044
                                                    • CVE-2024-26737
                                                    • CVE-2024-27431
                                                    • CVE-2024-26955
                                                    • CVE-2024-26790
                                                    • CVE-2024-26925
                                                    • CVE-2024-26838
                                                    • CVE-2024-26984
                                                    • CVE-2024-25739
                                                    • CVE-2024-24861
                                                    • CVE-2024-24859
                                                    • CVE-2024-24858
                                                    • CVE-2024-24857
                                                    • CVE-2024-23307
                                                    • CVE-2024-22099
                                                    • CVE-2024-21823
                                                    • CVE-2024-0841
                                                    • CVE-2023-7042
                                                    • CVE-2023-6270
                                                    • CVE-2022-38096
                                                    • 5.15 - Raspi
                                                    • [USN-6922-1] Linux kernel vulnerabilities
                                                      • 4 CVEs addressed in Jammy (22.04 LTS)
                                                        • CVE-2024-25739
                                                        • CVE-2024-24859
                                                        • CVE-2024-24858
                                                        • CVE-2024-24857
                                                        • 6.5 - NVIDIA
                                                        • [USN-6923-1, USN-6923-2] Linux kernel vulnerabilities
                                                          • 6 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                            • CVE-2024-36016
                                                            • CVE-2024-27017
                                                            • CVE-2023-52752
                                                            • CVE-2024-26952
                                                            • CVE-2024-26886
                                                            • CVE-2024-25742
                                                            • 5.15 - generic, AWS, GCP, GKE, HWE, Intel-IOTG, KVM, LowLatency, NVIDIA, Oracle, IBM, Raspi
                                                            • [USN-6921-1, USN-6921-2] Linux kernel vulnerabilities
                                                              • 7 CVEs addressed in Noble (24.04 LTS)
                                                                • CVE-2024-36016
                                                                • CVE-2024-36008
                                                                • CVE-2024-35984
                                                                • CVE-2024-35992
                                                                • CVE-2024-35997
                                                                • CVE-2024-35990
                                                                • CVE-2024-25742
                                                                • 6.8 - generic, AWS, GCP, GKE, IBM, NVIDIA, OEM, Raspi, LowLatency
                                                                • [USN-6924-1, USN-6924-2] Linux kernel vulnerabilities
                                                                  • 7 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                    • CVE-2024-26583
                                                                    • CVE-2022-48655
                                                                    • CVE-2024-26907
                                                                    • CVE-2021-47131
                                                                    • CVE-2024-26585
                                                                    • CVE-2024-36016
                                                                    • CVE-2024-26584
                                                                    • 5.4 - generic, AWS, Azure, Bluefield, GCP, GKE, HWE, IBM, IOT, KVM, Raspi, Xilinx-ZynqMP
                                                                    • [USN-6925-1] Linux kernel vulnerability
                                                                      • 1 CVEs addressed in Trusty ESM (14.04 ESM)
                                                                        • CVE-2024-26882
                                                                        • 3.13 - generic, lowlatency, server, virtual
                                                                        • [USN-6926-1] Linux kernel vulnerabilities
                                                                          • 30 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                            • CVE-2023-52752
                                                                            • CVE-2023-52444
                                                                            • CVE-2024-26882
                                                                            • CVE-2023-52449
                                                                            • CVE-2024-26934
                                                                            • CVE-2024-26840
                                                                            • CVE-2024-36016
                                                                            • CVE-2024-27020
                                                                            • CVE-2023-52443
                                                                            • CVE-2024-26923
                                                                            • CVE-2024-26857
                                                                            • CVE-2024-36902
                                                                            • CVE-2024-35982
                                                                            • CVE-2024-26886
                                                                            • CVE-2024-35978
                                                                            • CVE-2023-52469
                                                                            • CVE-2024-26901
                                                                            • CVE-2024-26884
                                                                            • CVE-2023-52436
                                                                            • CVE-2024-35997
                                                                            • CVE-2023-52620
                                                                            • CVE-2024-35984
                                                                            • CVE-2024-27013
                                                                            • CVE-2023-52435
                                                                            • CVE-2024-25744
                                                                            • CVE-2024-25739
                                                                            • CVE-2024-24859
                                                                            • CVE-2024-24858
                                                                            • CVE-2024-24857
                                                                            • CVE-2023-46343
                                                                            • 4.15 - generic, AWS, HWE, GCP, KVM, Oracle
                                                                            • [USN-6927-1] Linux kernel vulnerabilities
                                                                              • 161 CVEs addressed in Focal (20.04 LTS)
                                                                                • CVE-2024-27008
                                                                                • CVE-2024-26951
                                                                                • CVE-2024-26970
                                                                                • CVE-2024-35815
                                                                                • CVE-2024-26828
                                                                                • CVE-2024-35898
                                                                                • CVE-2024-26999
                                                                                • CVE-2024-35938
                                                                                • CVE-2024-27016
                                                                                • CVE-2024-35825
                                                                                • CVE-2024-35950
                                                                                • CVE-2024-26969
                                                                                • CVE-2024-26643
                                                                                • CVE-2024-26924
                                                                                • CVE-2024-36025
                                                                                • CVE-2023-52752
                                                                                • CVE-2024-35936
                                                                                • CVE-2024-35847
                                                                                • CVE-2024-26964
                                                                                • CVE-2024-35857
                                                                                • CVE-2024-35854
                                                                                • CVE-2024-27437
                                                                                • CVE-2024-35851
                                                                                • CVE-2024-26654
                                                                                • CVE-2024-26629
                                                                                • CVE-2024-26988
                                                                                • CVE-2024-27001
                                                                                • CVE-2024-26956
                                                                                • CVE-2024-35990
                                                                                • CVE-2024-27020
                                                                                • CVE-2024-26996
                                                                                • CVE-2024-35817
                                                                                • CVE-2024-26950
                                                                                • CVE-2024-26810
                                                                                • CVE-2024-35893
                                                                                • CVE-2024-35852
                                                                                • CVE-2024-35895
                                                                                • CVE-2024-27009
                                                                                • CVE-2024-26687
                                                                                • CVE-2024-35821
                                                                                • CVE-2024-35944
                                                                                • CVE-2024-27015
                                                                                • CVE-2024-35822
                                                                                • CVE-2024-35823
                                                                                • CVE-2024-35890
                                                                                • CVE-2024-35973
                                                                                • CVE-2024-27013
                                                                                • CVE-2024-35912
                                                                                • CVE-2024-26817
                                                                                • CVE-2024-35935
                                                                                • CVE-2024-26989
                                                                                • CVE-2024-35877
                                                                                • CVE-2024-26926
                                                                                • CVE-2024-35849
                                                                                • CVE-2024-26993
                                                                                • CVE-2024-26974
                                                                                • CVE-2024-35791
                                                                                • CVE-2024-35910
                                                                                • CVE-2024-36008
                                                                                • CVE-2024-35988
                                                                                • CVE-2024-26813
                                                                                • CVE-2024-36006
                                                                                • CVE-2024-35879
                                                                                • CVE-2024-35789
                                                                                • CVE-2024-35969
                                                                                • CVE-2024-35925
                                                                                • CVE-2024-26984
                                                                                • CVE-2024-35871
                                                                                • CVE-2024-35853
                                                                                • CVE-2024-27004
                                                                                • CVE-2024-35899
                                                                                • CVE-2024-26931
                                                                                • CVE-2024-35934
                                                                                • CVE-2024-35796
                                                                                • CVE-2024-36020
                                                                                • CVE-2023-52699
                                                                                • CVE-2024-35930
                                                                                • CVE-2024-26957
                                                                                • CVE-2024-35804
                                                                                • CVE-2024-26922
                                                                                • CVE-2024-26814
                                                                                • CVE-2024-35900
                                                                                • CVE-2024-27395
                                                                                • CVE-2024-26642
                                                                                • CVE-2024-26960
                                                                                • CVE-2024-26935
                                                                                • CVE-2024-36005
                                                                                • CVE-2024-26981
                                                                                • CVE-2024-26934
                                                                                • CVE-2024-26976
                                                                                • CVE-2024-35806
                                                                                • CVE-2024-35915
                                                                                • CVE-2024-35922
                                                                                • CVE-2022-48808
                                                                                • CVE-2024-26973
                                                                                • CVE-2024-35933
                                                                                • CVE-2024-35785
                                                                                • CVE-2024-26937
                                                                                • CVE-2024-35918
                                                                                • CVE-2024-27000
                                                                                • CVE-2024-26977
                                                                                • CVE-2024-27393
                                                                                • CVE-2024-35984
                                                                                • CVE-2024-35970
                                                                                • CVE-2024-27019
                                                                                • CVE-2024-26955
                                                                                • CVE-2024-35888
                                                                                • CVE-2024-35976
                                                                                • CVE-2024-35982
                                                                                • CVE-2024-35805
                                                                                • CVE-2024-35960
                                                                                • CVE-2024-26812
                                                                                • CVE-2024-27017
                                                                                • CVE-2024-26966
                                                                                • CVE-2023-52880
                                                                                • CVE-2024-27396
                                                                                • CVE-2024-35809
                                                                                • CVE-2024-35997
                                                                                • CVE-2024-26958
                                                                                • CVE-2024-26961
                                                                                • CVE-2024-26923
                                                                                • CVE-2024-26811
                                                                                • CVE-2024-35813
                                                                                • CVE-2024-36029
                                                                                • CVE-2024-35896
                                                                                • CVE-2024-26965
                                                                                • CVE-2024-35885
                                                                                • CVE-2024-35855
                                                                                • CVE-2024-36007
                                                                                • CVE-2024-26929
                                                                                • CVE-2024-35897
                                                                                • CVE-2024-35905
                                                                                • CVE-2024-27018
                                                                                • CVE-2024-26886
                                                                                • CVE-2024-35884
                                                                                • CVE-2023-52488
                                                                                • CVE-2024-36016
                                                                                • CVE-2024-35872
                                                                                • CVE-2024-35819
                                                                                • CVE-2024-35907
                                                                                • CVE-2024-26952
                                                                                • CVE-2024-35940
                                                                                • CVE-2024-35989
                                                                                • CVE-2024-27059
                                                                                • CVE-2024-26925
                                                                                • CVE-2024-35955
                                                                                • CVE-2024-36004
                                                                                • CVE-2024-26994
                                                                                • CVE-2024-35807
                                                                                • CVE-2024-35886
                                                                                • CVE-2024-35978
                                                                                • CVE-2024-35958
                                                                                • CVE-2024-35902
                                                                                • CVE-2024-25742
                                                                                • CVE-2024-25739
                                                                                • CVE-2024-24861
                                                                                • CVE-2024-24859
                                                                                • CVE-2024-24858
                                                                                • CVE-2024-24857
                                                                                • CVE-2024-23307
                                                                                • CVE-2022-38096
                                                                                • 5.15 - GCP
                                                                                • Goings on in Ubuntu Security Community
                                                                                  Discussion of testing for security updates in light of CrowdStrike (11:20)
                                                                                  • Recent outage of over 8 million Windows machines running CrowdStrike Falcon
                                                                                    • https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/
                                                                                    • Initially very little information on what happened - CS have now released more
                                                                                    • details about the apparent testing that was done but clearly were never
                                                                                      actually testing the combination of Windows + Falcon + Rapid Response Content
                                                                                      otherwise would have observed this failure immediately
                                                                                    • Also clearly didn’t have any kind of staged/phased update process in place either
                                                                                      • If you want to read a good analysis of the response from CS,
                                                                                      • https://verse.systems/blog/post/2024-07-25-parsing-crowdstrikes-post/
                                                                                        • Toby Murray (full disclosure, my brother) - Associate Professor and
                                                                                        • Co-Lead of Computer Science Research Group at School of Computing and
                                                                                          Information Systems, University of Melbourne, Director, Defence Science
                                                                                          Institute (Vic & Tas)
                                                                                        • Future plans from CS now include gradual deployment of rules with “canaries” etc and then increased testing:
                                                                                          • Local dev testing, content update testing, stress, fuzz, fault-injection,
                                                                                          • stability and interface testing
                                                                                          • Toby (not surprisingly as an expert in formal software verification)
                                                                                          • advocates for a formal approach to validating rules and in-kernel code etc
                                                                                          • What can we learn from this for Ubuntu?
                                                                                            • Formal methods might be tractable for a large company like CS who is
                                                                                            • developing a single, specific product like Falcon (particularly if they can
                                                                                              reduce the size of their kernel module), this is not the case for a Linux
                                                                                              distribution like Ubuntu which collates over 30,000 different open source
                                                                                              software projects
                                                                                              • over 4TB of source code across the various releases
                                                                                              • Instead have to take the pragmatic approach of thorough testing
                                                                                                • For regular SRUs - detailed review by SRU team including a thorough test
                                                                                                • plan, cross-package testing via Autopkgtest plus a minimum 7 day “soak”
                                                                                                  testing in the proposed pocket of the release before being pushed into the
                                                                                                  -updates pocket
                                                                                                • Once in -updates, Phased Updates implements the gradual deployment model -
                                                                                                • you can check the progress of various updates at
                                                                                                  https://ubuntu-archive-team.ubuntu.com/phased-updates.html
                                                                                                  • Watches for increased error reports via errors.ubuntu.com (captured via
                                                                                                  • apport/whoopsie) and if detected stops the release of the package to users
                                                                                                  • Compare that to the process for Security updates
                                                                                                    • Separate -security pocket in the archive which packages get published to
                                                                                                    • immediately
                                                                                                      • No standardised review by separate team
                                                                                                        • instead adhoc reviews within the security team
                                                                                                        • No documented test plan per update
                                                                                                          • instead thorough test procedures including:
                                                                                                            • checking for any changes in the build log (e.g. new compiler
                                                                                                            • warnings/errors) and comparing the difference between the generated
                                                                                                              binaries (e.g. new / changed / missing symbols - ABI breaks)
                                                                                                            • testing of the patched code including stepping through it with a
                                                                                                            • debugger
                                                                                                            • running any existing PoC or creating one if none exists and is
                                                                                                            • feasible
                                                                                                            • running any existing unit/integration tests within the package
                                                                                                            • (including dep8/autopkgtests)
                                                                                                            • test apt upgrade of the package is smooth
                                                                                                            • QA regression testing scripts - maintained by the security team,
                                                                                                            • implement various regression tests and system-level tests for
                                                                                                              different packages to exercise them in various different
                                                                                                              configurations
                                                                                                            • Cross-package testing via security-britney - instance of the autopkgtest
                                                                                                            • infrastructure that runs against the public Ubuntu Security Proposed PPA
                                                                                                              (and we have a similar internal instance for the different private PPAs we
                                                                                                              use for embargoed updates or ESM etc)
                                                                                                            • No phased updates - instead immediate updates via specific
                                                                                                            • security.ubuntu.com archive, combined with unattended-upgrades
                                                                                                              • designed to deliver security updates as soon as possible to remediate
                                                                                                              • issues
                                                                                                              • In general, I would argue that the process we have in place results in more
                                                                                                              • thorough testing for security updates - particularly checking for anything
                                                                                                                anomalous like new compiler warnings / symbols / unexpected changes in
                                                                                                                binaries etc as well as more thorough, standardised testing for packages
                                                                                                                through the QA Regression Testing repo scripts
                                                                                                              • However, the lack of phased/progressive updates combined with the separate
                                                                                                              • security.ubuntu.com archive and unattended-upgrades on by default, means any
                                                                                                                security update is delivered to Ubuntu users within 24 hours (on average) -
                                                                                                                BUT then any regression is also rolled out to all users in 24 hours as well
                                                                                                              • As such, kicking off discussions around possible changes to our deployment
                                                                                                              • strategy to potentially introduce some more guard rails on the deployment side
                                                                                                              • If you have any thoughts, please let us know
                                                                                                              • Get in contact
                                                                                                                • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                • ubuntu-hardened mailing list
                                                                                                                • Security section on discourse.ubuntu.com
                                                                                                                • @[email protected], @ubuntu_sec on twitter
                                                                                                                • 25 min
                                                                                                                • Episode 232
                                                                                                                  Overview

                                                                                                                  This week we deep-dive into one of the best vulnerabilities we’ve seen in a long

                                                                                                                  time regreSSHion - an unauthenticated, remote, root code-execution vulnerability
                                                                                                                  in OpenSSH. Plus we cover updates for Plasma Workspace, Ruby, Netplan,
                                                                                                                  FontForge, OpenVPN and a whole lot more.

                                                                                                                  This week in Ubuntu Security Updates

                                                                                                                  39 unique CVEs addressed

                                                                                                                  [USN-6843-1] Plasma Workspace vulnerability (01:23)
                                                                                                                  • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                    • CVE-2024-36041
                                                                                                                    • KDE Session Manager - used for restoring previously running applications at next boot
                                                                                                                    • Provides ability to clients to connect to it via Inter-Client Exchange (ICE)
                                                                                                                    • protocol - protocol within X for allowing X clients to interact with
                                                                                                                      one-another
                                                                                                                    • Since X supports remote clients, is important to authenticate connections - in
                                                                                                                    • this case KDE SM would authenticate to ensure the connection was coming from
                                                                                                                      the local machine - but this could then allow any local user to connect to
                                                                                                                      another users SM and hence use the session management features to set some
                                                                                                                      arbitrary application to be run when the session is restored - as that other
                                                                                                                      user
                                                                                                                      [USN-6852-1, USN-6852-2] Wget vulnerability (02:42)
                                                                                                                      • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                        • CVE-2024-38428
                                                                                                                        • mishandled semicolons in userinfo of a URL - this is the user@host:port
                                                                                                                        • combination - so would possibly then use a different hostname than the one the
                                                                                                                          user expected
                                                                                                                          [USN-6853-1] Ruby vulnerability (03:12)
                                                                                                                          • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                            • CVE-2024-27280
                                                                                                                            • Provides methods ungetbyte()/ungetc() to push-back characters on an IO
                                                                                                                            • stream - would possibly read beyond the end of the buffer - OOB read
                                                                                                                              [USN-6851-1] Netplan vulnerabilities (03:37)
                                                                                                                              • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                • CVE-2022-4968
                                                                                                                                • Two different issues
                                                                                                                                  • When configuring a Wireguard interface, would write the wireguard private
                                                                                                                                  • key into the netplan interface configuration - but would then leave this
                                                                                                                                    with world-readable permissions
                                                                                                                                  • This can either be specified as the filename to the private key OR the
                                                                                                                                  • private key itself - so if had chosen to specify the actual private key,
                                                                                                                                    this is now world-readable to any other user
                                                                                                                                    • Fixed to use restrictive permissions on the generated configuration files
                                                                                                                                    • and to fixup any existing ones as well
                                                                                                                                    • Failed to escape control characters in various backend files - a malicious
                                                                                                                                    • application that is able to create a netplan configuration could then abuse
                                                                                                                                      this to get code execution as netplan
                                                                                                                                      [USN-6851-2] Netplan regression
                                                                                                                                      • Affecting Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                      • Failed to properly do the permissions fixup on already existing files
                                                                                                                                      • [USN-6854-1] OpenSSL vulnerability (05:10)
                                                                                                                                        • 1 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                          • CVE-2022-40735
                                                                                                                                          • Related to a historical vulnerability - https://dheatattack.gitlab.io/ - CVE-2002-20001
                                                                                                                                          • DoS against Diffie-Hellman key exchange protocol - during key negotiation a
                                                                                                                                          • client can trigger expensive CPU calculations -> CPU-based DoS
                                                                                                                                            [USN-6856-1] FontForge vulnerabilities (05:50)
                                                                                                                                            • 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                              • CVE-2024-25082
                                                                                                                                              • CVE-2024-25081
                                                                                                                                              • Uses various external utilities to do things like decompress archive files etc
                                                                                                                                              • However, would do this via the system() system-call - which spawns a shell -
                                                                                                                                              • so if a filename contained any shell metacharacters, could then just easily
                                                                                                                                                get arbitrary code execution
                                                                                                                                              • Changed to use the utility functions from glib that do not spawn a shell and
                                                                                                                                              • instead just exec() the expected command directly
                                                                                                                                                [USN-6857-1] Squid vulnerabilities (06:48)
                                                                                                                                                • 6 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                  • CVE-2024-25617
                                                                                                                                                  • CVE-2023-50269
                                                                                                                                                  • CVE-2023-49286
                                                                                                                                                  • CVE-2023-49285
                                                                                                                                                  • CVE-2022-41318
                                                                                                                                                  • CVE-2021-28651
                                                                                                                                                  • [USN-6566-2] SQLite vulnerability
                                                                                                                                                    • 1 CVEs addressed in Bionic ESM (18.04 ESM)
                                                                                                                                                      • CVE-2023-7104
                                                                                                                                                      • [USN-5615-3] SQLite vulnerability
                                                                                                                                                        • 3 CVEs addressed in Trusty ESM (14.04 ESM)
                                                                                                                                                          • CVE-2021-20223
                                                                                                                                                          • CVE-2020-35527
                                                                                                                                                          • CVE-2020-35525
                                                                                                                                                          • [USN-6855-1] libcdio vulnerability (06:58)
                                                                                                                                                            • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                              • CVE-2024-36600
                                                                                                                                                              • ISO file parser - used strcpy() instead of strncpy() so could be made to quite
                                                                                                                                                              • easily achieve buffer overflow and hence possible code-execution
                                                                                                                                                                [USN-6858-1] eSpeak NG vulnerabilities (07:33)
                                                                                                                                                                • 5 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                  • CVE-2023-49994
                                                                                                                                                                  • CVE-2023-49993
                                                                                                                                                                  • CVE-2023-49992
                                                                                                                                                                  • CVE-2023-49991
                                                                                                                                                                  • CVE-2023-49990
                                                                                                                                                                  • speech synthesiser - pass file to it and it will read it aloud
                                                                                                                                                                  • various buffer overflows when parsing different formats - found by a researcher via fuzzing
                                                                                                                                                                  • [USN-6844-2] CUPS regression (07:51)
                                                                                                                                                                    • Affecting Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                                    • [USN-6844-1] CUPS vulnerability from Episode 231
                                                                                                                                                                    • [USN-6860-1] OpenVPN vulnerabilities (07:57)
                                                                                                                                                                      • 2 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                                        • CVE-2024-5594
                                                                                                                                                                        • CVE-2024-28882
                                                                                                                                                                        • Client was able to keep the session alive even when the server had been
                                                                                                                                                                        • instructed to disconnect the client
                                                                                                                                                                        • Client was able to send junk/non-printable characters in the control channel
                                                                                                                                                                        • since would then get logged and possibly allow to corrupt the log file or
                                                                                                                                                                          cause high CPU load
                                                                                                                                                                          [USN-6862-1] Firefox vulnerabilities (08:27)
                                                                                                                                                                          • 13 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                            • CVE-2024-5696
                                                                                                                                                                            • CVE-2024-5695
                                                                                                                                                                            • CVE-2024-5694
                                                                                                                                                                            • CVE-2024-5688
                                                                                                                                                                            • CVE-2024-5701
                                                                                                                                                                            • CVE-2024-5700
                                                                                                                                                                            • CVE-2024-5699
                                                                                                                                                                            • CVE-2024-5698
                                                                                                                                                                            • CVE-2024-5697
                                                                                                                                                                            • CVE-2024-5693
                                                                                                                                                                            • CVE-2024-5691
                                                                                                                                                                            • CVE-2024-5690
                                                                                                                                                                            • CVE-2024-5689
                                                                                                                                                                            • 127.0.2
                                                                                                                                                                            • [USN-6859-1] OpenSSH vulnerability
                                                                                                                                                                              • 1 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                                                • CVE-2024-6387
                                                                                                                                                                                • Goings on in Ubuntu Security Community
                                                                                                                                                                                  Deep-dive into regreSSHion - Remote Unauthenticated Code Execution Vulnerablity in OpenSSH
                                                                                                                                                                                  • https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server
                                                                                                                                                                                  • https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt
                                                                                                                                                                                  • https://ubuntu.com/blog/ubuntu-regresshion-security-fix
                                                                                                                                                                                  • First notified late last week by Qualys of a pending update for OpenSSH which
                                                                                                                                                                                  • fixes a newly discovered unauthenticated remote code execution vulnerability -
                                                                                                                                                                                    as root - this is about as bad as it can get
                                                                                                                                                                                    • Exactly the kind of thing that “Jia Tan” spent all that time working on in
                                                                                                                                                                                    • xz-utils to try and achieve (xz-utils backdoor and Ubuntu from Episode 224)
                                                                                                                                                                                    • Qualys are quite specific to note that this only affects OpenSSH on glibc (so
                                                                                                                                                                                    • distros which use say musl are not affected) - due to the intricacies of the
                                                                                                                                                                                      vulnerablity and how they exploit it
                                                                                                                                                                                    • Also OpenSSH is quite carefully designed - employs privilege separation to try
                                                                                                                                                                                    • keep the privileged part as minimal as possible - but in this case, the vuln
                                                                                                                                                                                      is in this privielged part, hence why code execution as root
                                                                                                                                                                                    • OpenSSH developers released 9.8p1 on Monday this week which has some quite
                                                                                                                                                                                    • significant refactoring to help address this vuln - in particular it includes
                                                                                                                                                                                      functionality similar to fail2ban to penalise clients that appear to be
                                                                                                                                                                                      malicious AND it employs even more privilege separation than before
                                                                                                                                                                                    • Qualys are quite careful to say that they think OpenSSH is one of the most
                                                                                                                                                                                    • secure pieces of software in the world “near-flawless implementation” with
                                                                                                                                                                                      inspirational defense-in-depth - but clearly bugs still slip through
                                                                                                                                                                                    • In this case is a signal handler race condition
                                                                                                                                                                                      • Diversion - what are signals?
                                                                                                                                                                                        • signal (7)
                                                                                                                                                                                          • simple, asynchronous form of IPC which allows sending a single piece of information - the type of signal
                                                                                                                                                                                            • many different types - e.g. SIGSEGV for invalid memory access, or
                                                                                                                                                                                            • SIGFPE for a math error - or can be sent by other processes - SIGTERM
                                                                                                                                                                                              / SIGKILL / SIGINT
                                                                                                                                                                                            • process can then set itself up so that a particular signal handler
                                                                                                                                                                                            • function of its choosing is invoked for a given signal
                                                                                                                                                                                            • when a signal is sent to a process, it is queued up and then delivered
                                                                                                                                                                                            • to a process the next time the kernel returns from kernel space to
                                                                                                                                                                                              that process - ie. when returning from a system-call or scheduling of
                                                                                                                                                                                              that process
                                                                                                                                                                                            • to deliver it, kernel constructs an entirely new stack frame and
                                                                                                                                                                                            • passes execution to the signal handler function - this runs and then
                                                                                                                                                                                              eventually returns control back to the original thread of the process
                                                                                                                                                                                            • Signal handlers are special - since they run on their own special stack
                                                                                                                                                                                            • and outside of the normal thread of execution of the process, they can
                                                                                                                                                                                              potentially cause issues if they do things which modify the global state
                                                                                                                                                                                              of the process - many regular functions are off-limits within signal
                                                                                                                                                                                              handlers since they can inadvertently modify such global state
                                                                                                                                                                                              • only some functions are hence async-signal-safe (7)
                                                                                                                                                                                                • list contains a lot of functions BUT many which might ordinarily get
                                                                                                                                                                                                • used are not included - in particular malloc()/free()
                                                                                                                                                                                                • This vuln was caused then by use of one of these async unsafe functions
                                                                                                                                                                                                • OpenSSH has a functionality called LoginGraceTime which allows an admin to
                                                                                                                                                                                                • configure how long OpenSSH will allow a client to take to login - if they
                                                                                                                                                                                                  don’t log in in that time then it closes the connection
                                                                                                                                                                                                  • Since this code is all single-threaded, can’t just have the code which is
                                                                                                                                                                                                  • listening to the client connection bail out easily - so instead this is
                                                                                                                                                                                                    implemented via the SIGALARM signal - used by the alarm (2) system call to
                                                                                                                                                                                                    configure the SIGALARM signal to be delivered to a process some number of
                                                                                                                                                                                                    seconds later
                                                                                                                                                                                                  • Unfortunately in the signal handler function for this SIGALARM, OpenSSH
                                                                                                                                                                                                  • can end up calling syslog() when trying to which is one of those unsafe functions
                                                                                                                                                                                                    • in glibc syslog() will potentially call malloc()/free() which as we
                                                                                                                                                                                                    • mentioned earlier is not async safe
                                                                                                                                                                                                      • it is possible that the original thread may be in the middle of a call
                                                                                                                                                                                                      • to malloc() / free() and then SIGALARM signal is delivered (since
                                                                                                                                                                                                        malloc()/free() calls brk (2) system call under the hood and so a
                                                                                                                                                                                                        pending signal SIGALARM may be delivered on return from brk())
                                                                                                                                                                                                      • both the original thread and the signal handler are then calling
                                                                                                                                                                                                      • malloc() at the same time - corrupting the global state of the heap
                                                                                                                                                                                                        etc
                                                                                                                                                                                                      • as we know, if can corrupt the heap state ‘correctly’ can get code
                                                                                                                                                                                                      • execution
                                                                                                                                                                                                      • but requires the ability to win this race
                                                                                                                                                                                                      • In fact, this is a reoccurrence of historical CVE-2006-5051 - discovered by
                                                                                                                                                                                                      • Mark Dowd but subsequently fixed
                                                                                                                                                                                                        • code in question was refactored in October 2020 and released in OpenSSH
                                                                                                                                                                                                        • 8.5p1 which would then call syslog() during the SIGALARM signal handler
                                                                                                                                                                                                        • To exploit this, Qualys take inspiration from a 2001 paper by Michal Zalewski
                                                                                                                                                                                                        • (aka lcamtuf previously Director of Information Security Engineering at Google
                                                                                                                                                                                                          and now VP Security Engineering at Snap (ie Snapchat etc))
                                                                                                                                                                                                        • Even so, it is an incredibly difficult path to get to a working exploit - both
                                                                                                                                                                                                        • since this is a race-condition so it is very hard to get the right timing
                                                                                                                                                                                                          conditions and second due to defence-in-depth measures like ASLR
                                                                                                                                                                                                          • First develop an exploit for the original 2006 CVE against a couple older versions
                                                                                                                                                                                                            • OpenSSH 3.4p1 on Debian Woody
                                                                                                                                                                                                              • even on i386 which has much worse ASLR than amd64, takes 10,000 tries to
                                                                                                                                                                                                              • win the race - even then with 10 concurrent connections and each with a
                                                                                                                                                                                                                LoginGraceTime of 5 minutes - ~1week to get a remote root shell
                                                                                                                                                                                                              • OpenSSH 4.2p1 on Ubuntu 6.06 (Dapper Drake) - first LTS version of
                                                                                                                                                                                                              • Ubuntu - this vuln was patched during the lifetime of 6.06 release but
                                                                                                                                                                                                                original install media still contains the unpatched version
                                                                                                                                                                                                                • Similarly, takes ~10,000 tries to win the race - with LoginGraceTime of
                                                                                                                                                                                                                • only 2 minutes can reduce the time to get a remote root shell to 1-2
                                                                                                                                                                                                                  days
                                                                                                                                                                                                                • Finally, OpenSSH 9.2p1 from current Debian stable on i386
                                                                                                                                                                                                                  • 10,000 tries - now 100 connections with 2 minutes grace time - in
                                                                                                                                                                                                                  • practice still ~6-8 hours since still have to guess the address used by
                                                                                                                                                                                                                    glibc and due to ASLR is only 50% accurate
                                                                                                                                                                                                                  • All of these are lab conditions - VMs with quite stable network - and only on
                                                                                                                                                                                                                  • i386 - but Qualys say they were starting on an exploit even for amd64 but
                                                                                                                                                                                                                    didn’t continue after they noticed a related bug report about this
                                                                                                                                                                                                                    async-unsafe signal handling - so decided that may draw attention to the issue
                                                                                                                                                                                                                    and others may discover the vuln and start exploiting it - so best to disclose
                                                                                                                                                                                                                    it in its current state
                                                                                                                                                                                                                  • For Ubuntu, since this only affects version since 8.5p1, only 22.04 LTS
                                                                                                                                                                                                                  • onwards were affected - we released patches on Monday - unattended-upgrades is
                                                                                                                                                                                                                    enabled by default on all relases since 16.04 LTS anyway - checks for and
                                                                                                                                                                                                                    installs security updates every 24 hours - so any affected Ubuntu users would
                                                                                                                                                                                                                    likely have been automatically patched within ~24 of the vuln becoming public
                                                                                                                                                                                                                    (and the restart logic in OpenSSH would have restarted the service when it got
                                                                                                                                                                                                                    upgraded as well)
                                                                                                                                                                                                                  • Other thing which is more internal for Ubuntu is that Qualys explicitly called
                                                                                                                                                                                                                  • out OpenSSH in 24.04 LTS as having a deficiency in the enablement of ASLR -
                                                                                                                                                                                                                    since we are using systemd socket activation we disable reexec support for
                                                                                                                                                                                                                    OpenSSH - so it never reexecutes itself for its child processes - so they
                                                                                                                                                                                                                    never get the benefit of ASLR - BUT by chance it also makes this unexploitable
                                                                                                                                                                                                                    since it changes the use of syslog() within OpenSSH so that syslog() gets
                                                                                                                                                                                                                    called early on in the use of OpenSSH and so then when it gets called in the
                                                                                                                                                                                                                    SIGALARM signal handler it doesn’t do the same memory allocation and hence
                                                                                                                                                                                                                    can’t be used to corrupt memory and get code execution
                                                                                                                                                                                                                    Get in contact
                                                                                                                                                                                                                    • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                    • ubuntu-hardened mailing list
                                                                                                                                                                                                                    • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                    • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                                                    • 30 min
                                                                                                                                                                                                                    • Episode 231
                                                                                                                                                                                                                      Overview

                                                                                                                                                                                                                      A look into CISA’s Known Exploited Vulnerability Catalogue is on our minds this

                                                                                                                                                                                                                      week, plus we look at vulnerability updates for gdb, Ansible, CUPS, libheif,
                                                                                                                                                                                                                      Roundcube, the Linux kernel and more.

                                                                                                                                                                                                                      This week in Ubuntu Security Updates

                                                                                                                                                                                                                      175 unique CVEs addressed

                                                                                                                                                                                                                      [USN-6842-1] gdb vulnerabilities (01:10)
                                                                                                                                                                                                                      • 6 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                        • CVE-2023-39130
                                                                                                                                                                                                                        • CVE-2023-39129
                                                                                                                                                                                                                        • CVE-2023-39128
                                                                                                                                                                                                                        • CVE-2023-1972
                                                                                                                                                                                                                        • CVE-2022-4285
                                                                                                                                                                                                                        • CVE-2020-16599
                                                                                                                                                                                                                        • a couple of these are inherited from binutils as they share that code -
                                                                                                                                                                                                                        • parsing of crafted ELF executables -> NULL ptr deref or possible heap based
                                                                                                                                                                                                                          buffer overflow -> DoS/RCE
                                                                                                                                                                                                                        • other stack and heap buffer overflows as well - parsing of crafted ada files
                                                                                                                                                                                                                        • and crafted debug info files as well -> DoS/RCE
                                                                                                                                                                                                                          [USN-6845-1] Hibernate vulnerability (02:12)
                                                                                                                                                                                                                          • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                            • CVE-2020-25638
                                                                                                                                                                                                                            • Object relational-mapping (ORM) library for Java
                                                                                                                                                                                                                            • SQL injection in the JPA Criteria API implementation - could allow unvalidated
                                                                                                                                                                                                                            • literals when they are used in the SQL comments of a query when logging is
                                                                                                                                                                                                                              enabled - fixed by properly escaping comments in this case
                                                                                                                                                                                                                              [USN-6846-1] Ansible vulnerabilities (02:46)
                                                                                                                                                                                                                              • 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                • CVE-2023-5764
                                                                                                                                                                                                                                • CVE-2022-3697
                                                                                                                                                                                                                                • Possibly would leak the password into log file when using the AWS EC2 module
                                                                                                                                                                                                                                • since failed to validate the tower_callback (nowadays is called aap_callback -
                                                                                                                                                                                                                                  Ansible Automation Platform) parameter appropriately
                                                                                                                                                                                                                                • Allows to mark variables as unsafe - in that they may come from an external,
                                                                                                                                                                                                                                • untrusted source - won’t get evaluated/expanded when used to avoid possible
                                                                                                                                                                                                                                  info leaks etc - various issues where ansible would fail to respect this and
                                                                                                                                                                                                                                  essentially forget they were tagged as unsafe and end up exposing secrets as a
                                                                                                                                                                                                                                  result
                                                                                                                                                                                                                                  [USN-6844-1] CUPS vulnerability (04:08)
                                                                                                                                                                                                                                  • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                                                                                                    • CVE-2024-35235
                                                                                                                                                                                                                                    • When starting, cups would arbitrarily chmod the socket specified as the Listen
                                                                                                                                                                                                                                    • parameter to make it world-writable - if this was a symlink, would then make
                                                                                                                                                                                                                                      the target of the symlink world-readable - in general the cups config file is
                                                                                                                                                                                                                                      only writable by root so requires some other vuln to be able to exploit it
                                                                                                                                                                                                                                      where you can get write access to the config file to exploit it OR be able to
                                                                                                                                                                                                                                      replace the regular cups socket path with a user-controlled symlink - but if
                                                                                                                                                                                                                                      you can, then you can even change the cups config itself to be world-writable
                                                                                                                                                                                                                                      and hence modify other parameters like the user and group that cups should run
                                                                                                                                                                                                                                      as, as well as a crafted FoomaticRIPCommandLine then can run arbitrary commands
                                                                                                                                                                                                                                      as root
                                                                                                                                                                                                                                      [USN-6849-1] Salt vulnerabilities (06:20)
                                                                                                                                                                                                                                      • 2 CVEs addressed in Trusty ESM (14.04 ESM)
                                                                                                                                                                                                                                        • CVE-2020-11652
                                                                                                                                                                                                                                        • CVE-2020-11651
                                                                                                                                                                                                                                        • Failed to properly validate paths in some methods and also failed to restrict
                                                                                                                                                                                                                                        • access to other methods, allowing them to be used without authentication -
                                                                                                                                                                                                                                          could then either allow arbitrary directory access or the ability to retrieve
                                                                                                                                                                                                                                          tokens from the master or run arbitrary commands on minions
                                                                                                                                                                                                                                          [USN-6746-2] Google Guest Agent and Google OS Config Agent vulnerability (06:44)
                                                                                                                                                                                                                                          • 1 CVEs addressed in Noble (24.04 LTS)
                                                                                                                                                                                                                                            • CVE-2024-24786
                                                                                                                                                                                                                                            • A vuln in the embedded golang protobuf module - when parsing JSON could end up
                                                                                                                                                                                                                                            • in an infinite loop -> DoS
                                                                                                                                                                                                                                              [USN-6850-1] OpenVPN vulnerability (07:04)
                                                                                                                                                                                                                                              • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM)
                                                                                                                                                                                                                                                • CVE-2022-0547
                                                                                                                                                                                                                                                • [USN-5347-1] OpenVPN vulnerability from Episode 155 - possibly gets confused
                                                                                                                                                                                                                                                • when using multiple authentication plugins and deferred authentication
                                                                                                                                                                                                                                                  [USN-6847-1] libheif vulnerabilities (07:36)
                                                                                                                                                                                                                                                  • 8 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                    • CVE-2023-49464
                                                                                                                                                                                                                                                    • CVE-2023-49463
                                                                                                                                                                                                                                                    • CVE-2023-49462
                                                                                                                                                                                                                                                    • CVE-2023-49460
                                                                                                                                                                                                                                                    • CVE-2023-29659
                                                                                                                                                                                                                                                    • CVE-2023-0996
                                                                                                                                                                                                                                                    • CVE-2020-23109
                                                                                                                                                                                                                                                    • CVE-2019-11471
                                                                                                                                                                                                                                                    • First time to mention libheif on the podcast - High Efficiency Image File
                                                                                                                                                                                                                                                    • Format - part of the MPEG-H standard - container format used to store images
                                                                                                                                                                                                                                                      or sequences of images
                                                                                                                                                                                                                                                    • Commonly seen due to its use by Apple for images on iPhone
                                                                                                                                                                                                                                                    • C++ - usual types of issues
                                                                                                                                                                                                                                                      • UAF, buffer overflows, floating point exception etc
                                                                                                                                                                                                                                                        • most found through fuzzing
                                                                                                                                                                                                                                                        • [USN-6848-1] Roundcube vulnerabilities (08:21)
                                                                                                                                                                                                                                                          • 4 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                            • CVE-2024-37384
                                                                                                                                                                                                                                                            • CVE-2024-37383
                                                                                                                                                                                                                                                            • CVE-2023-47272
                                                                                                                                                                                                                                                            • CVE-2023-5631
                                                                                                                                                                                                                                                            • webmail front-end for IMAP
                                                                                                                                                                                                                                                            • 2 different possible XSS issues due to mishandling of SVG - email containing
                                                                                                                                                                                                                                                            • an SVG could embed JS that then gets loaded when the email is viewed
                                                                                                                                                                                                                                                            • Also possible XSS through a crafted user preference value - similarly through
                                                                                                                                                                                                                                                            • a crafted Content-Type/Content-Disposition header which can be used for
                                                                                                                                                                                                                                                              attachment preview/download
                                                                                                                                                                                                                                                              [USN-6819-4] Linux kernel (Oracle) vulnerabilities (09:21)
                                                                                                                                                                                                                                                              • 149 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                • CVE-2024-26631
                                                                                                                                                                                                                                                                • CVE-2023-52694
                                                                                                                                                                                                                                                                • CVE-2023-52685
                                                                                                                                                                                                                                                                • CVE-2023-52682
                                                                                                                                                                                                                                                                • CVE-2024-35835
                                                                                                                                                                                                                                                                • CVE-2023-52446
                                                                                                                                                                                                                                                                • CVE-2023-52487
                                                                                                                                                                                                                                                                • CVE-2023-52619
                                                                                                                                                                                                                                                                • CVE-2023-52627
                                                                                                                                                                                                                                                                • CVE-2023-52674
                                                                                                                                                                                                                                                                • CVE-2024-26598
                                                                                                                                                                                                                                                                • CVE-2023-52679
                                                                                                                                                                                                                                                                • CVE-2023-52455
                                                                                                                                                                                                                                                                • CVE-2024-26671
                                                                                                                                                                                                                                                                • CVE-2023-52444
                                                                                                                                                                                                                                                                • CVE-2023-52683
                                                                                                                                                                                                                                                                • CVE-2023-52690
                                                                                                                                                                                                                                                                • CVE-2024-35842
                                                                                                                                                                                                                                                                • CVE-2023-52610
                                                                                                                                                                                                                                                                • CVE-2024-26607
                                                                                                                                                                                                                                                                • CVE-2023-52445
                                                                                                                                                                                                                                                                • CVE-2023-52497
                                                                                                                                                                                                                                                                • CVE-2023-52488
                                                                                                                                                                                                                                                                • CVE-2024-26623
                                                                                                                                                                                                                                                                • CVE-2023-52607
                                                                                                                                                                                                                                                                • CVE-2023-52677
                                                                                                                                                                                                                                                                • CVE-2023-52457
                                                                                                                                                                                                                                                                • CVE-2024-26673
                                                                                                                                                                                                                                                                • CVE-2024-26594
                                                                                                                                                                                                                                                                • CVE-2024-26638
                                                                                                                                                                                                                                                                • CVE-2023-52621
                                                                                                                                                                                                                                                                • CVE-2023-52594
                                                                                                                                                                                                                                                                • CVE-2023-52468
                                                                                                                                                                                                                                                                • CVE-2024-26647
                                                                                                                                                                                                                                                                • CVE-2023-52492
                                                                                                                                                                                                                                                                • CVE-2023-52452
                                                                                                                                                                                                                                                                • CVE-2024-26615
                                                                                                                                                                                                                                                                • CVE-2023-52448
                                                                                                                                                                                                                                                                • CVE-2023-52698
                                                                                                                                                                                                                                                                • CVE-2023-52443
                                                                                                                                                                                                                                                                • CVE-2023-52614
                                                                                                                                                                                                                                                                • CVE-2023-52494
                                                                                                                                                                                                                                                                • CVE-2024-35837
                                                                                                                                                                                                                                                                • CVE-2024-26582
                                                                                                                                                                                                                                                                • CVE-2023-52632
                                                                                                                                                                                                                                                                • CVE-2023-52680
                                                                                                                                                                                                                                                                • CVE-2023-52595
                                                                                                                                                                                                                                                                • CVE-2023-52626
                                                                                                                                                                                                                                                                • CVE-2023-52495
                                                                                                                                                                                                                                                                • CVE-2023-52451
                                                                                                                                                                                                                                                                • CVE-2023-52583
                                                                                                                                                                                                                                                                • CVE-2023-52469
                                                                                                                                                                                                                                                                • CVE-2023-52584
                                                                                                                                                                                                                                                                • CVE-2023-52450
                                                                                                                                                                                                                                                                • CVE-2024-26608
                                                                                                                                                                                                                                                                • CVE-2023-52609
                                                                                                                                                                                                                                                                • CVE-2023-52464
                                                                                                                                                                                                                                                                • CVE-2023-52591
                                                                                                                                                                                                                                                                • CVE-2024-26645
                                                                                                                                                                                                                                                                • CVE-2024-35838
                                                                                                                                                                                                                                                                • CVE-2023-52470
                                                                                                                                                                                                                                                                • CVE-2023-52456
                                                                                                                                                                                                                                                                • CVE-2023-52589
                                                                                                                                                                                                                                                                • CVE-2024-26585
                                                                                                                                                                                                                                                                • CVE-2023-52696
                                                                                                                                                                                                                                                                • CVE-2023-52633
                                                                                                                                                                                                                                                                • CVE-2023-52462
                                                                                                                                                                                                                                                                • CVE-2023-52597
                                                                                                                                                                                                                                                                • CVE-2023-52587
                                                                                                                                                                                                                                                                • CVE-2024-26584
                                                                                                                                                                                                                                                                • CVE-2024-26636
                                                                                                                                                                                                                                                                • CVE-2023-52491
                                                                                                                                                                                                                                                                • CVE-2023-52493
                                                                                                                                                                                                                                                                • CVE-2024-26627
                                                                                                                                                                                                                                                                • CVE-2023-52465
                                                                                                                                                                                                                                                                • CVE-2023-52687
                                                                                                                                                                                                                                                                • CVE-2023-52593
                                                                                                                                                                                                                                                                • CVE-2024-26595
                                                                                                                                                                                                                                                                • CVE-2024-26629
                                                                                                                                                                                                                                                                • CVE-2024-35840
                                                                                                                                                                                                                                                                • CVE-2023-52666
                                                                                                                                                                                                                                                                • CVE-2024-26633
                                                                                                                                                                                                                                                                • CVE-2023-52686
                                                                                                                                                                                                                                                                • CVE-2023-52467
                                                                                                                                                                                                                                                                • CVE-2023-52667
                                                                                                                                                                                                                                                                • CVE-2023-52449
                                                                                                                                                                                                                                                                • CVE-2023-52473
                                                                                                                                                                                                                                                                • CVE-2023-52670
                                                                                                                                                                                                                                                                • CVE-2024-26649
                                                                                                                                                                                                                                                                • CVE-2023-52498
                                                                                                                                                                                                                                                                • CVE-2023-52693
                                                                                                                                                                                                                                                                • CVE-2024-26583
                                                                                                                                                                                                                                                                • CVE-2023-52678
                                                                                                                                                                                                                                                                • CVE-2023-52675
                                                                                                                                                                                                                                                                • CVE-2023-52489
                                                                                                                                                                                                                                                                • CVE-2024-26640
                                                                                                                                                                                                                                                                • CVE-2024-26618
                                                                                                                                                                                                                                                                • CVE-2023-52599
                                                                                                                                                                                                                                                                • CVE-2024-26634
                                                                                                                                                                                                                                                                • CVE-2023-52608
                                                                                                                                                                                                                                                                • CVE-2024-26625
                                                                                                                                                                                                                                                                • CVE-2023-52486
                                                                                                                                                                                                                                                                • CVE-2024-26632
                                                                                                                                                                                                                                                                • CVE-2023-52669
                                                                                                                                                                                                                                                                • CVE-2023-52676
                                                                                                                                                                                                                                                                • CVE-2023-52635
                                                                                                                                                                                                                                                                • CVE-2023-52664
                                                                                                                                                                                                                                                                • CVE-2024-35841
                                                                                                                                                                                                                                                                • CVE-2023-52598
                                                                                                                                                                                                                                                                • CVE-2023-52458
                                                                                                                                                                                                                                                                • CVE-2024-26644
                                                                                                                                                                                                                                                                • CVE-2023-52697
                                                                                                                                                                                                                                                                • CVE-2023-52617
                                                                                                                                                                                                                                                                • CVE-2024-26612
                                                                                                                                                                                                                                                                • CVE-2023-52672
                                                                                                                                                                                                                                                                • CVE-2023-52490
                                                                                                                                                                                                                                                                • CVE-2024-35839
                                                                                                                                                                                                                                                                • CVE-2024-26610
                                                                                                                                                                                                                                                                • CVE-2024-26616
                                                                                                                                                                                                                                                                • CVE-2023-52588
                                                                                                                                                                                                                                                                • CVE-2023-52623
                                                                                                                                                                                                                                                                • CVE-2024-26669
                                                                                                                                                                                                                                                                • CVE-2023-52692
                                                                                                                                                                                                                                                                • CVE-2024-26620
                                                                                                                                                                                                                                                                • CVE-2023-52606
                                                                                                                                                                                                                                                                • CVE-2024-26592
                                                                                                                                                                                                                                                                • CVE-2023-52616
                                                                                                                                                                                                                                                                • CVE-2024-26641
                                                                                                                                                                                                                                                                • CVE-2023-52622
                                                                                                                                                                                                                                                                • CVE-2023-52611
                                                                                                                                                                                                                                                                • CVE-2023-52453
                                                                                                                                                                                                                                                                • CVE-2023-52681
                                                                                                                                                                                                                                                                • CVE-2024-26586
                                                                                                                                                                                                                                                                • CVE-2023-52472
                                                                                                                                                                                                                                                                • CVE-2024-26646
                                                                                                                                                                                                                                                                • CVE-2024-26670
                                                                                                                                                                                                                                                                • CVE-2023-52454
                                                                                                                                                                                                                                                                • CVE-2024-26668
                                                                                                                                                                                                                                                                • CVE-2023-52447
                                                                                                                                                                                                                                                                • CVE-2023-52463
                                                                                                                                                                                                                                                                • CVE-2023-52618
                                                                                                                                                                                                                                                                • CVE-2023-52691
                                                                                                                                                                                                                                                                • CVE-2024-26808
                                                                                                                                                                                                                                                                • CVE-2023-52612
                                                                                                                                                                                                                                                                • CVE-2024-24860
                                                                                                                                                                                                                                                                • CVE-2024-23849
                                                                                                                                                                                                                                                                • CVE-2023-6536
                                                                                                                                                                                                                                                                • CVE-2023-6535
                                                                                                                                                                                                                                                                • CVE-2023-6356
                                                                                                                                                                                                                                                                • Of all these CVEs, 6 had a high priority rating
                                                                                                                                                                                                                                                                  • many are due to bugs in the async handling of cryto operations in the
                                                                                                                                                                                                                                                                  • in-kernel TLS implementation
                                                                                                                                                                                                                                                                    • CVE-2024-26582 and CVE-2024-26584 - both reported by Google kernelCTF program (talked about back in [USN-6766-2] Linux kernel vulnerabilities from Episode 228)
                                                                                                                                                                                                                                                                      • first is UAF in TLS handling of scattter/gather arrays
                                                                                                                                                                                                                                                                      • second is UAF when crypto requests get backlogged and the underlying
                                                                                                                                                                                                                                                                      • crypto engine can’t process them all in time - can then end up having
                                                                                                                                                                                                                                                                        the async callback invoked twice
                                                                                                                                                                                                                                                                      • CVE-2024-26585
                                                                                                                                                                                                                                                                        • very similar - UAF in handling of crypto operations from TLS - thread
                                                                                                                                                                                                                                                                        • which handles the socket could close this before all the operations had
                                                                                                                                                                                                                                                                          been scheduled
                                                                                                                                                                                                                                                                        • CVE-2024-26583 - similarly, race between async notify event and socket close -> UAF
                                                                                                                                                                                                                                                                        • UAF in BPF and a UAF in netfilter - also reported via Google kernelCTF -
                                                                                                                                                                                                                                                                        • both able to be triggered via an unpriv userns
                                                                                                                                                                                                                                                                          Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                          Discussion of CISA KEV
                                                                                                                                                                                                                                                                          • US Gov Cybersecurity & Infrastructure Security Agency
                                                                                                                                                                                                                                                                            • “America’s Cyber Defense Agency”
                                                                                                                                                                                                                                                                            • National Coordinator for Critical Infrastructure Security and Resilience
                                                                                                                                                                                                                                                                            • Publish various guidance for organisations around topics of cybersecurity
                                                                                                                                                                                                                                                                              • for instance, recently published a report “Exploring Memory Safety in Critical Open Source Projects”
                                                                                                                                                                                                                                                                                • Joint guidance (FBI, ASD / ACSC & Candadian CSC)
                                                                                                                                                                                                                                                                                • Builds on the previous case for memory safe roadmaps by looking at the
                                                                                                                                                                                                                                                                                • prevalence of memory unsafe languages in various critical open source
                                                                                                                                                                                                                                                                                  projects
                                                                                                                                                                                                                                                                                • Also maintain the KEV - Known Exploitable Vulnerabilities Catalog
                                                                                                                                                                                                                                                                                  • “authoritative source of vulnerabilities that have been exploited in the wild”
                                                                                                                                                                                                                                                                                  • Mandates for federal civilian agencies in the US to remediate KEV vulns within various timeframes
                                                                                                                                                                                                                                                                                  • Also recommend that anyone else monitors this list and immediately addresses these vulns as part of the vuln remediation plan
                                                                                                                                                                                                                                                                                  • List of vilns that are causing immediate harm based on observed adversarial activity
                                                                                                                                                                                                                                                                                  • Various requirements to be listed in the KEV:
                                                                                                                                                                                                                                                                                    • CVE ID assigned
                                                                                                                                                                                                                                                                                    • Evidence it has been or is being actively exploited
                                                                                                                                                                                                                                                                                      • reliable evidence that execution of malicious code was performed on a system by an unauthorised actor
                                                                                                                                                                                                                                                                                      • also includes both attempted and successful exploitation (e.g. includes honeypots as well as real systems)
                                                                                                                                                                                                                                                                                      • Clear remediation guidelines
                                                                                                                                                                                                                                                                                        • An update is available and should be applied OR
                                                                                                                                                                                                                                                                                        • Vulnerable component should be removed from networks etc if it is EOL and cannot be updated
                                                                                                                                                                                                                                                                                        • available as CSV or JSON
                                                                                                                                                                                                                                                                                        • Currently lists 1126 CVEs including:
                                                                                                                                                                                                                                                                                          • Accellion File Transfer Appliances
                                                                                                                                                                                                                                                                                          • Adobe Reader, Flash Player
                                                                                                                                                                                                                                                                                          • Apache HTTP Server, Struts (Solarwinds), Log4j
                                                                                                                                                                                                                                                                                          • Huge number of Apple iOS etc (WebKit and more)
                                                                                                                                                                                                                                                                                          • Atlassian Confluence
                                                                                                                                                                                                                                                                                          • Citrix Gateways
                                                                                                                                                                                                                                                                                          • Exim
                                                                                                                                                                                                                                                                                          • Fortinet
                                                                                                                                                                                                                                                                                          • Gitlab
                                                                                                                                                                                                                                                                                          • Google Chromium
                                                                                                                                                                                                                                                                                          • ImageMagick
                                                                                                                                                                                                                                                                                          • Microsoft Windows and Exchange
                                                                                                                                                                                                                                                                                          • Mozilla Firefox
                                                                                                                                                                                                                                                                                          • Ivanti Pulse Connect Security
                                                                                                                                                                                                                                                                                          • SaltStack
                                                                                                                                                                                                                                                                                          • VMWare
                                                                                                                                                                                                                                                                                          • WordPress
                                                                                                                                                                                                                                                                                          • Oldest CVEs are 2 against Windows from 2002 and 2004
                                                                                                                                                                                                                                                                                          • Newest include 26 2024 CVEs - various Chromium, Windows, Android Pixel, Ivanti and more
                                                                                                                                                                                                                                                                                            • interestingly includes ARM Mali GPU Driver CVE-2024-4610 - this affects
                                                                                                                                                                                                                                                                                            • the Bifrost and Valhall drivers - in Ubuntu we only ship the related
                                                                                                                                                                                                                                                                                              Midgard driver back in bionic and focal so not affected by this one
                                                                                                                                                                                                                                                                                            • but as you may have noticed, lots that we potentially are affected by
                                                                                                                                                                                                                                                                                              • Apache HTTP Server, Exim, Firefox, Thunderbird - plus OpenJDK, GNU C
                                                                                                                                                                                                                                                                                              • Library, Bash, Roundcube (mentioned earlier but not this particular vuln),
                                                                                                                                                                                                                                                                                                WinRAR (unrar), not to mention a number against the Linux kernel
                                                                                                                                                                                                                                                                                                • all for Linux kernel are privesc - most against either netfilter or
                                                                                                                                                                                                                                                                                                • various other systems like perf, AF_PACKET, tty, ptrace, futex and
                                                                                                                                                                                                                                                                                                  others
                                                                                                                                                                                                                                                                                                • For Ubuntu, not surprisingly, we prioritise these vulnerabilities in our
                                                                                                                                                                                                                                                                                                • patching process
                                                                                                                                                                                                                                                                                                  Get in contact
                                                                                                                                                                                                                                                                                                  • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                  • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                  • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                  • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                  • 19 min
                                                                                                                                                                                                                                                                                                  • Episode 230
                                                                                                                                                                                                                                                                                                    Overview

                                                                                                                                                                                                                                                                                                    This week we bring you a special edition of the podcast, featuring an interview

                                                                                                                                                                                                                                                                                                    between Ijlal Loutfi and Karen Horovitz who deep-dive into Confidential
                                                                                                                                                                                                                                                                                                    Computing. Ranging from a high-level discussion of the need for and the features
                                                                                                                                                                                                                                                                                                    provided by confidential computing, through to the specifics of how this is
                                                                                                                                                                                                                                                                                                    implemented in Ubuntu and a look at similar future security technologies that
                                                                                                                                                                                                                                                                                                    are on the horizon.

                                                                                                                                                                                                                                                                                                    Confidential Computing with Ijlal Loutfi and Karen Horovitz (01:17)
                                                                                                                                                                                                                                                                                                    Get in contact
                                                                                                                                                                                                                                                                                                    • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                    • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                    • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                    • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                    • 22 min
                                                                                                                                                                                                                                                                                                    • Episode 229
                                                                                                                                                                                                                                                                                                      Overview

                                                                                                                                                                                                                                                                                                      As the podcast winds down for a break over the next month, this week we talk

                                                                                                                                                                                                                                                                                                      about RSA timing side-channel attacks and the recently announced DNSBomb
                                                                                                                                                                                                                                                                                                      vulnerability as we cover security updates in VLC, OpenSSL, Netatalk, WebKitGTK,
                                                                                                                                                                                                                                                                                                      amavisd-new, Unbound, Intel Microcode and more.

                                                                                                                                                                                                                                                                                                      This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                      152 unique CVEs addressed

                                                                                                                                                                                                                                                                                                      [USN-6783-1] VLC vulnerabilities (00:54)
                                                                                                                                                                                                                                                                                                      • 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                        • CVE-2023-47360
                                                                                                                                                                                                                                                                                                        • CVE-2023-47359
                                                                                                                                                                                                                                                                                                        • integer underflow and a heap buffer overflow -> RCE
                                                                                                                                                                                                                                                                                                        • [USN-6663-3] OpenSSL update (01:40)
                                                                                                                                                                                                                                                                                                          • Affecting Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                          • [USN-6663-1] OpenSSL update from Episode 220 - hardening improvement to return
                                                                                                                                                                                                                                                                                                          • deterministic random bytes instead of an error when an incorrect padding
                                                                                                                                                                                                                                                                                                            length is detected during PKCS#1 v1.5 RSA to avoid this being used for
                                                                                                                                                                                                                                                                                                            possible Bleichenbacher timing attacks
                                                                                                                                                                                                                                                                                                            [USN-6673-3] python-cryptography vulnerability (02:32)
                                                                                                                                                                                                                                                                                                            • 1 CVEs addressed in Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                              • CVE-2024-26130
                                                                                                                                                                                                                                                                                                              • [USN-6673-1] python-cryptography vulnerabilities from Episode 220 -
                                                                                                                                                                                                                                                                                                              • counterpart to the OpenSSL update mentioned earlier
                                                                                                                                                                                                                                                                                                                [USN-6736-2] klibc vulnerabilities (02:43)
                                                                                                                                                                                                                                                                                                                • 4 CVEs addressed in Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                  • CVE-2022-37434
                                                                                                                                                                                                                                                                                                                  • CVE-2018-25032
                                                                                                                                                                                                                                                                                                                  • CVE-2016-9841
                                                                                                                                                                                                                                                                                                                  • CVE-2016-9840
                                                                                                                                                                                                                                                                                                                  • [USN-6736-1] klibc vulnerabilities from Episode 228
                                                                                                                                                                                                                                                                                                                  • [USN-6784-1] cJSON vulnerabilities (02:58)
                                                                                                                                                                                                                                                                                                                    • 3 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                      • CVE-2024-31755
                                                                                                                                                                                                                                                                                                                      • CVE-2023-50472
                                                                                                                                                                                                                                                                                                                      • CVE-2023-50471
                                                                                                                                                                                                                                                                                                                      • 2 different researchers fuzzing cJSON APIs
                                                                                                                                                                                                                                                                                                                        • all different NULL ptr deref - requires particular / “incorrect” or possible
                                                                                                                                                                                                                                                                                                                        • misuse use of the APIs (like passing in purposefully corrupted values) so
                                                                                                                                                                                                                                                                                                                          unlikely to be an issue in practice
                                                                                                                                                                                                                                                                                                                          [USN-6785-1] GNOME Remote Desktop vulnerability (03:52)
                                                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                            • CVE-2024-5148
                                                                                                                                                                                                                                                                                                                            • Discovered by a member of the SUSE security team when reviewing g-r-d
                                                                                                                                                                                                                                                                                                                            • Exposed various DBus services that were able to be called by any unprivileged
                                                                                                                                                                                                                                                                                                                            • user which would then return the SSL private key used to encrypt the
                                                                                                                                                                                                                                                                                                                              connection - so could allow a local user to possibly spy on the sessions of
                                                                                                                                                                                                                                                                                                                              other users remotely connected to the system
                                                                                                                                                                                                                                                                                                                              [USN-6786-1] Netatalk vulnerabilities (04:45)
                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                • CVE-2022-22995
                                                                                                                                                                                                                                                                                                                                • Apple file sharing implementation for Linux
                                                                                                                                                                                                                                                                                                                                • If the same path was shared via both AFP and SMB then a remote attacker could
                                                                                                                                                                                                                                                                                                                                • combine various operations through both file-systems (like creating a crafted
                                                                                                                                                                                                                                                                                                                                  symlink, which would then be followed during a second operation where a file
                                                                                                                                                                                                                                                                                                                                  is renamed) to allow them to overwrite arbirary files and hence achieve
                                                                                                                                                                                                                                                                                                                                  arbitrary code execution on the host
                                                                                                                                                                                                                                                                                                                                  [USN-6788-1] WebKitGTK vulnerabilities (05:48)
                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                    • CVE-2024-27834
                                                                                                                                                                                                                                                                                                                                    • Possible pointer authentication bypass - used on arm64 in particular -
                                                                                                                                                                                                                                                                                                                                    • demonstrated at Pwn2Own earlier this year by Manfred Paul - $60k
                                                                                                                                                                                                                                                                                                                                      [USN-6789-1] LibreOffice vulnerability (06:28)
                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                        • CVE-2024-3044
                                                                                                                                                                                                                                                                                                                                        • Unchecked script execution triggered when clicking on a graphic - allows to
                                                                                                                                                                                                                                                                                                                                        • run arbitrary scripts without the usual prompt
                                                                                                                                                                                                                                                                                                                                          [USN-6790-1] amavisd-new vulnerability (07:09)
                                                                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                            • CVE-2024-28054
                                                                                                                                                                                                                                                                                                                                            • MTA / AV interface - often used in conjunction with Postfix, not just for AV
                                                                                                                                                                                                                                                                                                                                            • but also can be used to do DKIM verification and integration with spamassassin
                                                                                                                                                                                                                                                                                                                                              etc
                                                                                                                                                                                                                                                                                                                                            • Misinterpreted MIME message boundaries in emails, allowing email parts to
                                                                                                                                                                                                                                                                                                                                            • possibly bypass usual checks
                                                                                                                                                                                                                                                                                                                                              [USN-6791-1] Unbound vulnerability (07:46)
                                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                                • CVE-2024-33655
                                                                                                                                                                                                                                                                                                                                                • DNSBomb attack announced recently at IEEE S&P - affecting multiple different
                                                                                                                                                                                                                                                                                                                                                • DNS implementations including BIND, Unbound, PowerDNS, Knot, DNSMasq and others
                                                                                                                                                                                                                                                                                                                                                • Unbound itself was not necessarily vulnerable to such an attack specifically,
                                                                                                                                                                                                                                                                                                                                                • but could be used to generate such an attack against others - in particular
                                                                                                                                                                                                                                                                                                                                                  Unbound had the highest amplification factor of ~22k times - next highest was
                                                                                                                                                                                                                                                                                                                                                  DNSMasq at ~3k times
                                                                                                                                                                                                                                                                                                                                                • Fix involves introducing a number of timeout parameters for various operations
                                                                                                                                                                                                                                                                                                                                                • and discarding operations if they take longer than this to avoid the ability
                                                                                                                                                                                                                                                                                                                                                  to “store up” responses to be released at a later time
                                                                                                                                                                                                                                                                                                                                                  [USN-6793-1] Git vulnerabilities (09:31)
                                                                                                                                                                                                                                                                                                                                                  • 5 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-32465
                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-32021
                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-32020
                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-32004
                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-32002
                                                                                                                                                                                                                                                                                                                                                    • [USN-6792-1] Flask-Security vulnerability
                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-23385
                                                                                                                                                                                                                                                                                                                                                        • [USN-6794-1] FRR vulnerabilities
                                                                                                                                                                                                                                                                                                                                                          • 4 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-34088
                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-31951
                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-31950
                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-31948
                                                                                                                                                                                                                                                                                                                                                            • [USN-6777-4] Linux kernel (HWE) vulnerabilities (09:40)
                                                                                                                                                                                                                                                                                                                                                              • 17 CVEs addressed in Xenial ESM (16.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52583
                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-26801
                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-26805
                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-26735
                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-26622
                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-46981
                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52566
                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52604
                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-26704
                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-26614
                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52602
                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-26635
                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52439
                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52601
                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52530
                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52524
                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-47233
                                                                                                                                                                                                                                                                                                                                                                • [USN-6777-1] Linux kernel vulnerabilities from Episode 228
                                                                                                                                                                                                                                                                                                                                                                • AWS HWE kernel (4.15)
                                                                                                                                                                                                                                                                                                                                                                • [USN-6795-1] Linux kernel (Intel IoTG) vulnerabilities (10:00)
                                                                                                                                                                                                                                                                                                                                                                  • 95 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52588
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52622
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26920
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52607
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52530
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52435
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52615
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26684
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26829
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26614
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52489
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52642
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52583
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26696
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26627
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26636
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26663
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26702
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26685
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26715
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26668
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52492
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52498
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26825
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52587
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26615
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52608
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26660
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52601
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26910
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26676
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52493
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26673
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26707
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26698
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26641
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52494
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52595
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26697
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52617
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26675
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26610
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26606
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52614
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26712
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52635
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26689
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26916
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26665
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52623
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26635
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26602
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52597
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52619
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26808
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26600
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26826
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26644
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26695
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52604
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26625
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52618
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26664
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26593
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52633
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52606
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26640
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52486
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52631
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26720
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52599
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26671
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26722
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52602
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26645
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52637
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26704
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52638
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26717
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26592
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52491
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52627
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52598
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26594
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52643
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26622
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52594
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26608
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26679
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52616
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-23849
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-2201
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2022-0001
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-1151
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-47233
                                                                                                                                                                                                                                                                                                                                                                    • Very similar to [USN-6766-2] Linux kernel vulnerabilities from Episode 228
                                                                                                                                                                                                                                                                                                                                                                    • 5.15 Intel IOTG - optimisations for various Intel IOT platforms like NUCs and
                                                                                                                                                                                                                                                                                                                                                                    • Atom-based devices - low power x86
                                                                                                                                                                                                                                                                                                                                                                      [USN-6779-2] Firefox regressions (10:30)
                                                                                                                                                                                                                                                                                                                                                                      • 14 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-4770
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-4367
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-4764
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-4778
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-4777
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-4776
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-4775
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-4774
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-4773
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-4772
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-4771
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-4769
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-4768
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-4767
                                                                                                                                                                                                                                                                                                                                                                        • 126.0.1 - drag-and-drop was broken in 126.0
                                                                                                                                                                                                                                                                                                                                                                        • [USN-6787-1] Jinja2 vulnerability (10:48)
                                                                                                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-34064
                                                                                                                                                                                                                                                                                                                                                                            • Incorrect handling of various HTML attributes - attacker could then possibly
                                                                                                                                                                                                                                                                                                                                                                            • inject arbitrary HTML attrs/values and hence inject JS code to peform XSS
                                                                                                                                                                                                                                                                                                                                                                              attacks etc
                                                                                                                                                                                                                                                                                                                                                                              [USN-6797-1] Intel Microcode vulnerabilities (11:22)
                                                                                                                                                                                                                                                                                                                                                                              • 9 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-46103
                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-47855
                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-45745
                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-45733
                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-43490
                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-39368
                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-38575
                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-28746
                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-22655
                                                                                                                                                                                                                                                                                                                                                                                • Latest release from upstream - mitigates against various hardware vulns
                                                                                                                                                                                                                                                                                                                                                                                  • A couple issues in SGX/TDX on different Intel Xeon processors:
                                                                                                                                                                                                                                                                                                                                                                                    • Invalid restrictions -> local root -> super-privesc
                                                                                                                                                                                                                                                                                                                                                                                    • Invalid input on TDX -> local root -> super-privesc
                                                                                                                                                                                                                                                                                                                                                                                    • Invalid SGX base key calculation -> info leak
                                                                                                                                                                                                                                                                                                                                                                                    • Transient execution attacks to read privileged information
                                                                                                                                                                                                                                                                                                                                                                                    • DoS through bus lock mishandling or through invalid instruction sequences
                                                                                                                                                                                                                                                                                                                                                                                    • Get in contact
                                                                                                                                                                                                                                                                                                                                                                                      • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                      • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                      • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                                      • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                      • 14 min
                                                                                                                                                                                                                                                                                                                                                                                      • Episode 228
                                                                                                                                                                                                                                                                                                                                                                                        Overview

                                                                                                                                                                                                                                                                                                                                                                                        The team is back from Madrid and this week we bring you some of our plans for

                                                                                                                                                                                                                                                                                                                                                                                        the upcoming Ubuntu 24.10 release, plus we talk about Google’s kernelCTF project
                                                                                                                                                                                                                                                                                                                                                                                        and Mozilla’s PDF.js sandbox when covering security updates for the Linux
                                                                                                                                                                                                                                                                                                                                                                                        kernel, Firefox, Spreadsheet::ParseExcel, idna and more.

                                                                                                                                                                                                                                                                                                                                                                                        This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                        121 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                                        [USN-6766-2] Linux kernel vulnerabilities (01:07)
                                                                                                                                                                                                                                                                                                                                                                                        • 92 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26697
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52489
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26644
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26702
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52492
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52616
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26808
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26920
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52494
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26698
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26695
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52635
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26707
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26715
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52597
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52435
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26668
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52598
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26593
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52643
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26717
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52604
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26602
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26664
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52491
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26635
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26640
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26696
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26627
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52623
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26641
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26829
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26679
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26600
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26916
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26606
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52614
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26675
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26712
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52587
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52642
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26636
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52615
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26615
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26722
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52608
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52607
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52631
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52486
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26645
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52617
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26660
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52595
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52599
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26592
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26610
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26608
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26704
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26671
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26676
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52583
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26689
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26910
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52619
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52498
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52638
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26685
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26673
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52602
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52627
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26614
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26720
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26625
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26594
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52606
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26825
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52637
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52588
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52618
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26663
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26684
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52633
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52493
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26665
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52622
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26826
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52601
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52594
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-23849
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-2201
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2022-0001
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-1151
                                                                                                                                                                                                                                                                                                                                                                                          • 5.15 - raspi kernel on 22.04 and OEM or optional HWE on 20.04
                                                                                                                                                                                                                                                                                                                                                                                          • Linux kernel CNA has been quite busy assigning both historical and recent CVEs against the kernel
                                                                                                                                                                                                                                                                                                                                                                                          • As discussed previously Linux kernel becomes a CNA from Episode 219 Follow up
                                                                                                                                                                                                                                                                                                                                                                                          • to Linux kernel CNA from Episode 220, the impact of these CVEs is often not
                                                                                                                                                                                                                                                                                                                                                                                            apparent so it makes it quite hard to assign a proper priority - even the
                                                                                                                                                                                                                                                                                                                                                                                            kernel CNA themselves are not assigning a CVSS score - so for now we have
                                                                                                                                                                                                                                                                                                                                                                                            little information which we can glean for each of these
                                                                                                                                                                                                                                                                                                                                                                                          • As such, the USNs contain quite little detail and are very generic - and for
                                                                                                                                                                                                                                                                                                                                                                                          • each we will be assigning just a medium priority unless we have some good
                                                                                                                                                                                                                                                                                                                                                                                            evidence otherwise
                                                                                                                                                                                                                                                                                                                                                                                          • One example here is CVE-2024-26808 - UAF in netfilter - was reported via
                                                                                                                                                                                                                                                                                                                                                                                          • Google’s kernelCTF (not to be confused with their kCTF which is their
                                                                                                                                                                                                                                                                                                                                                                                            kubernetes-based CTF hosting platform - but which also has a vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                            reward program (VRP)) - kernelCTF - program to offer rewards for exploits
                                                                                                                                                                                                                                                                                                                                                                                            against the kernel - but not just any exploits - can’t use io_uring or
                                                                                                                                                                                                                                                                                                                                                                                            nftables since they were disabled in their target kernel configuration due to
                                                                                                                                                                                                                                                                                                                                                                                            high number of historical vulns in both subsystems
                                                                                                                                                                                                                                                                                                                                                                                            • base reward of $21k, $10k bonus if is reliable more than 90% of the time,
                                                                                                                                                                                                                                                                                                                                                                                            • additional $20k bonus if works without using unprivileged user namespaces,
                                                                                                                                                                                                                                                                                                                                                                                              and a final additional $20k bonus if it is 0-day (ie not patched in the
                                                                                                                                                                                                                                                                                                                                                                                              mainline tree and not disclosed anywhere - including via syzkaller)
                                                                                                                                                                                                                                                                                                                                                                                            • So in this case, we rated this CVE with a high priority since it is known
                                                                                                                                                                                                                                                                                                                                                                                            • exploitable
                                                                                                                                                                                                                                                                                                                                                                                              • can see it listed in their public spreadsheet
                                                                                                                                                                                                                                                                                                                                                                                              • [USN-6766-3] Linux kernel (AWS) vulnerabilities (04:48)
                                                                                                                                                                                                                                                                                                                                                                                                • 92 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26697
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52489
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26644
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26702
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52492
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52616
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26808
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26920
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52494
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26698
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26695
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52635
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26707
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26715
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52597
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52435
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26668
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52598
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26593
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52643
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26717
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52604
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26602
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26664
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52491
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26635
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26640
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26696
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26627
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52623
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26641
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26829
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26679
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26600
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26916
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26606
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52614
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26675
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26712
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52587
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52642
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26636
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52615
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26615
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26722
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52608
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52607
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52631
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52486
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26645
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52617
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26660
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52595
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52599
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26592
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26610
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26608
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26704
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26671
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26676
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52583
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26689
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26910
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52619
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52498
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52638
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26685
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26673
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52602
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52627
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26614
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26720
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26625
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26594
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52606
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26825
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52637
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52588
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52618
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26663
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26684
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52633
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52493
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26665
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52622
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26826
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52601
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52594
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-23849
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-2201
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2022-0001
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-1151
                                                                                                                                                                                                                                                                                                                                                                                                  • 5.15 - AWS on both 22.04 and 20.04
                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6774-1] Linux kernel vulnerabilities (05:01)
                                                                                                                                                                                                                                                                                                                                                                                                    • 13 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26801
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52601
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26622
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26635
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52602
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26614
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52604
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26805
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52615
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26704
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-2201
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2022-0001
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-47233
                                                                                                                                                                                                                                                                                                                                                                                                      • 6.5 - all on 23.10, HWE (all) on 22.04
                                                                                                                                                                                                                                                                                                                                                                                                      • [USN-6775-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                        • 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52530
                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26622
                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-47233
                                                                                                                                                                                                                                                                                                                                                                                                          • 5.15 all on 22.04, HWE (all) on 20.04
                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6775-2] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                            • 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-52530
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-26622
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-47233
                                                                                                                                                                                                                                                                                                                                                                                                              • 5.15 AWS/GKE
                                                                                                                                                                                                                                                                                                                                                                                                              • [USN-6776-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                • 4 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26622
                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52530
                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26614
                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-47233
                                                                                                                                                                                                                                                                                                                                                                                                                  • 5.4 all on 20.04, HWE (all) on 18.04
                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6777-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                    • 17 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52583
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26801
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26805
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26735
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26622
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2021-46981
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52566
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52604
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26704
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26614
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52602
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26635
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52439
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52601
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52530
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52524
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-47233
                                                                                                                                                                                                                                                                                                                                                                                                                      • 4.15 - all on 18.04, HWE (all) on 16.04
                                                                                                                                                                                                                                                                                                                                                                                                                      • [USN-6777-2] Linux kernel (Azure) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                        • 17 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52583
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26801
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26805
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26735
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26622
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2021-46981
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52566
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52604
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26704
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26614
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52602
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26635
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52439
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52601
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52530
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52524
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-47233
                                                                                                                                                                                                                                                                                                                                                                                                                          • 4.15 - azure
                                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6777-3] Linux kernel (GCP) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                            • 17 CVEs addressed in Xenial ESM (16.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-52583
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-26801
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-26805
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-26735
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-26622
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2021-46981
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-52566
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-52604
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-26704
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-26614
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-52602
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-26635
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-52439
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-52601
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-52530
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-52524
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-47233
                                                                                                                                                                                                                                                                                                                                                                                                                              • [USN-6778-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                • 14 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52524
                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52530
                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52604
                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26614
                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2021-46939
                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26704
                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52566
                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26801
                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52602
                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26635
                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26805
                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-26622
                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52601
                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-47233
                                                                                                                                                                                                                                                                                                                                                                                                                                  • 4.4 - all on 16.04, HWE on 14.04
                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6773-1] .NET vulnerabilities (05:34)
                                                                                                                                                                                                                                                                                                                                                                                                                                    • 2 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-30046
                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-30045
                                                                                                                                                                                                                                                                                                                                                                                                                                      • dotnet 7 and 8
                                                                                                                                                                                                                                                                                                                                                                                                                                      • [USN-6779-1] Firefox vulnerabilities (05:54)
                                                                                                                                                                                                                                                                                                                                                                                                                                        • 14 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-4770
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-4367
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-4764
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-4778
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-4777
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-4776
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-4775
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-4774
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-4773
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-4772
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-4771
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-4769
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-4768
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-4767
                                                                                                                                                                                                                                                                                                                                                                                                                                          • 126.0
                                                                                                                                                                                                                                                                                                                                                                                                                                          • UAF due to multiple WebRTC threads trying to use an audio input device if it
                                                                                                                                                                                                                                                                                                                                                                                                                                          • was just added
                                                                                                                                                                                                                                                                                                                                                                                                                                          • type confusion bug in handling of missing fonts -> arbitrary JS execution via
                                                                                                                                                                                                                                                                                                                                                                                                                                          • PDF.js (this is in the context of PDF.js which uses the quickjs JS engine
                                                                                                                                                                                                                                                                                                                                                                                                                                            inside the standard ComponentUtils.Sandbox implementation - which is the same
                                                                                                                                                                                                                                                                                                                                                                                                                                            sandbox used to execute JS from websites etc in firefox) - unrelated to this
                                                                                                                                                                                                                                                                                                                                                                                                                                            vuln but PDFs can contain JavaScript (e.g. in a form, to calculate values
                                                                                                                                                                                                                                                                                                                                                                                                                                            based on user input)
                                                                                                                                                                                                                                                                                                                                                                                                                                            • also PDF.js doesn’t implement the PDF APIs related to network or disk etc to
                                                                                                                                                                                                                                                                                                                                                                                                                                            • avoid possible security issues
                                                                                                                                                                                                                                                                                                                                                                                                                                              [USN-6782-1] Thunderbird vulnerabilities (07:29)
                                                                                                                                                                                                                                                                                                                                                                                                                                              • 6 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-4770
                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-4367
                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-4777
                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-4769
                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-4768
                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-4767
                                                                                                                                                                                                                                                                                                                                                                                                                                                • 115.11.0
                                                                                                                                                                                                                                                                                                                                                                                                                                                • same PDF.js issues and others as above from Firefox
                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6781-1] Spreadsheet::ParseExcel vulnerability (07:51)
                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-7101
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • RCE vuln via the use of eval() on untrusted user input - high profile,
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • disclosed by Mandiant - high profile since it affected Barracuda email gateway
                                                                                                                                                                                                                                                                                                                                                                                                                                                      devices and was publicly reported as being exploited against these by a
                                                                                                                                                                                                                                                                                                                                                                                                                                                      Chinese APT group
                                                                                                                                                                                                                                                                                                                                                                                                                                                      [USN-6780-1] idna vulnerability (08:59)
                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-3651
                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Python module for handling internationalised domain names (RFC 5895)
                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CPU-based DoS due to inefficient algorithm when encoding a domain name
                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                                          Ubuntu Security Plans for 24.10 Development Cycle (09:33)
                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Progressing the FIPS certification for 24.04 though NIST
                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Implementation of OpenVEX and OSV data formats for machine readable vulnerability information
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Historically have generated OVAL data for this purpose
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • XML-based format, existed for over 20 years
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • more recently, OpenVEX and OSV have appeared which also serve the same
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • purpose and have a more vibrant community around them
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Similarly, next version of the SPDX format will also support vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • descriptions too
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Finally, given the recent announcement that
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CIS has
                                                                                                                                                                                                                                                                                                                                                                                                                                                              relinquished the role in sponsoring OVAL project and there doesn’t appear
                                                                                                                                                                                                                                                                                                                                                                                                                                                              to be any other sponsor on the horizon, thought it was prudent to develop a
                                                                                                                                                                                                                                                                                                                                                                                                                                                              “second-supplier” approach given this uncertain future for OVAL upstream
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • likely will have more to say on this in the future
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Improvements to the process the team uses for working with the snap store and doing reviews etc
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • AppArmor profile development across the 24.10 release
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                                              • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                                              • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                                                                                                              • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 16 min
                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Episode 227
                                                                                                                                                                                                                                                                                                                                                                                                                                                                Overview

                                                                                                                                                                                                                                                                                                                                                                                                                                                                Ubuntu 24.04 LTS is finally released and we cover all the new security features

                                                                                                                                                                                                                                                                                                                                                                                                                                                                it brings, plus we look at security vulnerabilities in, and updates for,
                                                                                                                                                                                                                                                                                                                                                                                                                                                                FreeRDP, Zabbix, CryptoJS, cpio, less, JSON5 and a heap more.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                                                                                                61 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                [USN-6749-1] FreeRDP vulnerabilities (00:45)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 7 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-32459
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-32460
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-32458
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-32041
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-32040
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-32039
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-22211
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Bunch of issues all reported by researcher from Kaspersky - usual sorts of issues in this package - written in C etc
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • OOB reads, heap buffer overflow, integer overflow / underflow -> OOB write
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6752-1] FreeRDP vulnerabilities (01:41)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 4 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-32661
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-32660
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-32659
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-32658
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Not long after those - more CVEs announced
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • OOB read, NULL ptr deref and memory exhaustion
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • [USN-6657-2] Dnsmasq vulnerabilities (01:54)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 3 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-28450
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-50868
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-50387
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6657-1] Dnsmasq vulnerabilities from Episode 220
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6743-3] Linux kernel (Azure) vulnerabilities (02:13)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 5 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-52603
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-26581
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-26591
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-26589
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-52600
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • [USN-6750-1] Thunderbird vulnerabilities (02:19)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 8 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-3861
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-3859
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-3857
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-3854
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-3302
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-3864
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-3852
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-2609
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 115.10.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6751-1] Zabbix vulnerabilities (02:54)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 2 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2022-35230
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2022-35229
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • First time Zabbix has featured in the podcast!
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Fixes 2 reflected XSS issues - in newer versions both require the attacker to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • be able to specify the user’s specific CSRF token - but in older versions only
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        there was only a session ID which is easier to guess
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [USN-6753-1] CryptoJS vulnerability (03:38)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-46233
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Insecure default config - uses older parameters for the implementation of
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • PBKDF2 - SHA1 with a single iteration - makes any passwords protected via
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            PBKDF2 in crypto-js easier to brute-force from the hashed value - instead
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            updated to use SHA256 with 250,000 rounds
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [USN-6754-1] nghttp2 vulnerabilities (04:32)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 4 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-28182
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-44487
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-9513
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-9511
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Fixes for most recent issue in HTTP/2 (plus a few older HTTP/2 issues for ESM
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • releases - HTTP/2 Rapid Reset and 2 disclosed by Netflix back in 2019 which we
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                covered back in [USN-4099-1] nginx vulnerabilities from Episode 49 -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                all DoS attacks)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • HTTP/2 continuation frames - no proper limit on the amount of these frames
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • which can be sent in a single stream - attacker can send many to cause a DoS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                on the server either through CPU by lots of processing or memory by storing
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                all these headers in memory
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [USN-6755-1] GNU cpio vulnerabilities (05:42)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-7207
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Path traversal vuln - possible to write outside of the target directory
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Specific to Debian/Ubuntu etc since reverted part of the fix for historic
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2015-1197 - path traversal via inclusion of a malicious symlink in the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    archive - since it broke the use of the --no-absolute-filenames CLI argument
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Was reverted back in 2.13+dfsg-2 - this was included in all releases of Ubuntu
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • since focal
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Now use more correct fix from upstream (April 2023)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6756-1] less vulnerability (07:10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-32487
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Second vuln in less in the last 10 weeks or so - [USN-6664-1] less vulnerability from Episode 220
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Similar issue - this time in the use of LESSOPEN environment variable - failed
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • to properly quote newlines embedded in a filename - could then allow for
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        arbitrary code execution if ran less on some untrusted file
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • LESSOPEN is automatically set in Debian/Ubuntu via lesspipe - allows to run
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • less on say a gz compressed log file or even on a tar.gz tarball to list the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        files etc
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [USN-6757-1] PHP vulnerabilities (08:41)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 3 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-3096
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-2756
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2022-4900
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Incomplete fix for historic CVE-2022-31629 - ability for an attacker on the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • same network/site could set a cookie via HTTP with one name, which then gets
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            used by sessions using HTTPS and when using a different cookie name - is a
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            problem since certain cookie names (like __Host- and __Secure-) have specific
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            meanings which in general should be allowed to be specified by the network but
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            only by the browser itself - so can be used to bypass usual restrictions
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            (apparently this issue was reported upstream by the original reported of the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            2022 vuln but it got ignored by upstream till now…)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • password_verify() function would sometimes return true for wrong passwords -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • ie if the actual password started with a NUL byte and the specified a password
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            was the empty string would verify as true (unlikely to be an issue in practice)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Heap buffer overflow due to a large PHP_CLI_SERVER_WORKERS env var value -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • integer overflow -> wraparound -> allocate small amount of memory for a large
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            number of values -> buffer overflow (low priority since would need to be able
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            to set this env var first)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [USN-6761-1] Anope vulnerability (11:15)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-30187
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Failed to deny ability to reset the password of a suspended account and hence
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • gain access again
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [USN-6758-1] JSON5 vulnerability (11:37)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 1 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2022-46175
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • NodeJS module for the JSON5 format - “JSON for humans” - much more similar to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • yaml, does away with a lot of the usual quotes etc
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Protoype pollution vuln - when parsing would fail to restrict use of the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • __proto__ key and hence would allow the ability to set arbitrary keys etc
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    within the returned object -> RCE
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [LSN-0103-1] Linux kernel vulnerability (12:46)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 7 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26597
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-1086
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-1085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-0193
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-51781
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-6817
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-4569
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Kernel type
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        22.04
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        20.04
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        18.04
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        aws
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        aws-5.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        aws-5.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        aws-6.5
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        azure
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        azure-5.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        azure-6.5
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        gcp
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        gcp-5.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        gcp-5.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        gcp-6.5
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        generic-5.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        generic-5.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        gke
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        hwe-6.5
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ibm
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ibm-5.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        linux
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        lowlatency-5.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        lowlatency-5.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        103.3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        canonical-livepatch status
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [USN-6760-1] Gerbv vulnerability (13:01)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-4508
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Vuln found by the Ubuntu Security team - David and (former member) Andrei -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Andrei found this whilst patching Gerbv back in 2023 and doing a bunch of
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            testing with ASan enabled - crafted filename -> crash
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [USN-6759-1] FreeRDP vulnerabilities (13:41)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 5 CVEs addressed in Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-32662
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-32661
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-32660
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-32659
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-32658
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • [USN-6737-2] GNU C Library vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 1 CVEs addressed in Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-2961
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6729-3] Apache HTTP Server vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 3 CVEs addressed in Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-27316
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-24795
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-38709
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • [USN-6718-3] curl vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 2 CVEs addressed in Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-2398
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-2004
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6733-2] GnuTLS vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 2 CVEs addressed in Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-28835
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-28834
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • [USN-6734-2] libvirt vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 2 CVEs addressed in Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-2494
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-1441
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6744-3] Pillow vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 1 CVEs addressed in Noble (24.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-28219
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Ubuntu 24.04 LTS (Noble Numbat) released (14:27)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • https://ubuntu.com/blog/canonical-releases-ubuntu-24-04-noble-numbat
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • https://ubuntu.com/blog/ubuntu-desktop-24-04-noble-numbat-deep-dive
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • https://ubuntu.com/blog/whats-new-in-security-for-ubuntu-24-04-lts
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Up to 12 years of support via Ubuntu Pro + Legacy Support Add-on
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • New security features / improvements:
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Unprivileged user namespace restrictions
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Binary hardening
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • AppArmor 4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Disabling of old TLS versions
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Upstream Kernel Security Features
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Intel shadow stack support
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Secure virtualisation with AMD SEV-SNP and Intel TDX
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Strict compile-time bounds checking
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 25 min
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Episode 226
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Overview

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                John and Georgia are at the Linux Security Summit presenting on some long

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                awaited developments in AppArmor and we give you all the details in a sneak peek
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                preview as well as some of the other talks to look out for, plus we cover
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                security updates for NSS, Squid, Apache, libvirt and more and we put out a call
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                for testing of a pending AppArmor security fix too.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                86 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [USN-6727-1, USN-6727-2] NSS vulnerabilities + regression (01:02)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-6135
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-5388
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-4421
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • All various different timing side channels - two were effectively the same
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • since the original fix was incomplete - mishandling of padding in PKCS#1 (RSA)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    certificate checks - possible to infer the length of the encrypted message and
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    other properties to eventually infer secret key by sending a large number of
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    attacker-chosen ciphertexts, the other when using various NIST
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    curves (elliptic curve cryptography)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Original fix caused some issues with loading NSS security modules so published
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • a second update to fix that on focal+jammy
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [USN-6728-1, USN-6728-2] Squid vulnerabilities + regression (02:05)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 5 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-25617
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-25111
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-23638
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-5824
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-49288
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • All found by the same researcher (Joshua Rogers) who performed a security
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • audit of Squid back in 2021 -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        https://megamansec.github.io/Squid-Security-Audit/ - first mentioned by us in
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [USN-6500-1] Squid vulnerabilities in Episode
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        214 back in December 2023
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Then we mentioned how squid was under-resourced and so hadn’t be able to fix
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • all the identified issues - over time upstream has published fixes for more
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        issues and we are now incorporating those into squid in Ubuntu
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • All of these were various DoS issues where could either cause squid to crash
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • or stop responding
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • One of these fixes was problematic and caused squid to crash itself so was reverted
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • [USN-6729-1] Apache HTTP Server vulnerabilities (03:01)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-27316
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-24795
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-38709
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 2 different issues that could result in HTTP request splitting attacks -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • similar to HTTP request smuggling which is a more specific version of this
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            attack, relies on different parsing/interpretation of HTTP request messages by
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            an intermediate (load balancer/proxy/WAF etc.) to split a single HTTP request
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            into multiple HTTP requests at the backend - allowing to bypass restrictions
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            along the way - usually involves the use of injected CR/LF/TAB/SPC etc in
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            headers
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Plus memory-based DoS in handling of HTTP/2 - client could just keep sending
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • more headers, buffered by the server so it can generate an informative
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            response, until it exhausts memory
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • limit to just 100 headers before bailing with such an error
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-6730-1] Apache Maven Shared Utils vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2022-29599
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6731-1] YARD vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 3 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-27285
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2019-1020001
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2017-17042
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-6732-1] WebKitGTK vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 8 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-23284
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-23280
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-23263
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-23254
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-23252
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-42956
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-42950
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-42843
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-6733-1] GnuTLS vulnerabilities (04:57)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 2 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-28835
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-28834
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Timing side-channel in ECDSA
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Crash when verifying crafted PEM bundles -> DoS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-6734-1] libvirt vulnerabilities (05:13)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-2496
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-2494
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-1441
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • off-by-one in handling of udev interface names - unpriv client could then
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • abuse this to send crafted udev data to the libvirt daemon, triggering a crash -> DoS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • NULL ptr deref in same code - race condition, need to detach a host interface
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • whilst calling into the function
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Crash in RPC handling - pass a negative length value, would then try and
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • allocate a negative number of array indices - uses underlying g_new0() from
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  glib which expects an unsigned value -> tries to allocate an extremely large
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  amount of memory -> crash
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [USN-6735-1] Node.js vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 3 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-30590
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-30589
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-30588
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-6736-1] klibc vulnerabilities (06:33)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 4 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2022-37434
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2018-25032
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2016-9841
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2016-9840
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • All old memory corruption issues in zlib - vendored within klibc
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-6724-2] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 12 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-52438
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-52439
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-52435
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-52436
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-52434
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-23850
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-22705
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6610
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-23851
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-52429
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-50431
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-46838
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-6725-2] Linux kernel (AWS) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 46 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52470
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52469
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52451
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52610
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52441
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52467
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52449
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-26591
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52458
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-26597
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-26633
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52436
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52444
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-26589
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-26586
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-26598
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52612
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52439
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-26631
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52442
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52443
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52480
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52438
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52454
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52456
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52464
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52457
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52448
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52609
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52462
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52445
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52463
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-24860
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-23850
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-22705
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-23851
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52429
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-52340
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-46838
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-3867
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-38431
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-38430
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-38427
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-32258
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-32254
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-1194
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6726-2] Linux kernel (IoT) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 23 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52438
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52436
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52454
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52470
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52451
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52445
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52469
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52609
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52444
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52449
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26597
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-26633
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52612
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52439
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52443
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52457
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52448
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52464
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-0607
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-23851
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52429
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-52340
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-46838
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-6726-3] Linux kernel (Xilinx ZynqMP) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 23 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52438
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52436
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52454
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52470
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52451
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52445
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52469
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52609
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52444
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52449
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-26597
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-26633
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52612
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52439
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52443
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52457
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52448
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52464
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-0607
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-23851
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52429
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52340
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-46838
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Linux Security Summit NA 2024 (07:22)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • https://events.linuxfoundation.org/linux-security-summit-north-america/
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Unprivileged Access Control in AppArmor - John Johansen & Georgia Garcia, Canonical
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • https://static.sched.com/hosted_files/lssna24/97/AppArmor%20-%20Unprivileged%20Application%20Policy.pdf
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Friday 19th @ 9.15am PDT - live stream at https://www.youtube.com/watch?v=S-RQZGRoQFY
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • AppArmor - MAC - sysadmin defines policy
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Allowing applications to define and load their own policy
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • APIs in libapparmor to allow this to be done from static policy OR to build up policy over time
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • policy is compiled in userspace and loaded into the kernel as usual
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • To then stop a compromised application from unloading its policy, can mark
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • it immutable so it can’t be further modified / removed
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Any further restrictions though can then be stacked against the immutable
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • policy to say allow it to be confined futher
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • On kernel side
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • sysctl to allow/deny applications to load their own policy
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • checks on the amount of memory able to be used to avoid apps DoSing system
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • verification of compiled policy by kernel state machine
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • policy only applies to the task and its children
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Various complexities in handling credentials/labels across tasks
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • (ie. processes) and how these interact with the userspace
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  processes/threads etc
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Also still have to resolve whether to use prctl vs syscall as the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • interface since we can’t use the LSM syscalls
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • May result in an AppArmor specific syscall
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • But for now just using a prctl
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Application profiles then stack against any relevant system policy
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • ie. if there is system policy, and policy loaded by the application itself is bounded by the system policy
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Demo of implementing pledge() and unveil() from OpenBSD
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • pledge is similar to seccomp() on linux - allows an application to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • restrict what it can do by declaring what subsystems it should be allowed
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      access to “promises”
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • stdio, inet, bpf, unix, audio, video and many others
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • map these to equivalent AppArmor permissions (although this is not a perfect mapping but WIP)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • also since this is at the LSM layer, we are not necessarily blocking
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • syscalls as is done by pledge (since it is more akin to seccomp)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • but can use seccomp to plug any gaps
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • to fully emulate this also need to emulate the return value - since on
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • OpenBSD if the application violates the promise, deliver a SIGABRT -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        whereas LSMs return EACCES
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • can do this via a new profile flag called kill along with the associated signal to deliver
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • further complications to this since not always SIGABRT, sometimes is an errno (ENOSYS/EACCES) too
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • extend apparmor policy to allow to specify priorities of what action should be taken in various cases
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • can use the aforementioned immutable profile flag and stacking to then implement the promise reduction feature of pledge()
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • unveil is used to remove visibility of parts of the file-system
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • maps quite cleanly to apparmor file rules
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Full video of the session should be available soon
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Lots of other interesting talks:
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Stacked LSMs and User Space - Casey Schaufler, The Smack Project
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • LSM syscalls and associated liblsm to provide an easier API plus emulation for older systems
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • https://static.sched.com/hosted_files/lssna24/1a/2024-04-LSSNA-liblsm.pdf
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Mitigating Integer Overflow in C - Kees Cook, Google
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • LKSPP - latest efforts to mitigate integer overflows within the kernel
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • through the use of compiler sanitizers
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • https://static.sched.com/hosted_files/lssna24/fb/Mitigating%20Integer%20Overflow%20in%20C.pdf
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Enhancing Kernel Bug Discovery with Large Language Models - Zahra Tarkhani, Microsoft
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • SandBox Mode (SBM) - New Execution Mode Between Kernel and User Space - Petr Tesarik, Self-employed
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Upcoming AppArmor Security update for CVE-2016-1585
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • https://discourse.ubuntu.com/t/upcoming-apparmor-security-update-for-cve-2016-1585/44268/1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • https://bugs.launchpad.net/apparmor/+bug/1597017
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 24 min
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Episode 225
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Overview

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    This week we cover the recent reports of a new local privilege escalation

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    exploit against the Linux kernel, follow-up on the xz-utils backdoor from last
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    week and it’s the beta release of Ubuntu 24.04 LTS - plus we talk security
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    vulnerabilities in the X Server, Django, util-linux and more.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    76 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [LSN-0102-1] Linux kernel vulnerability (00:53)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 6 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-1086
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-0646
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-51781
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-6176
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-4569
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-1872
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • All covered in previous episodes
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • netfilter UAF ([USN-6700-1] Linux kernel vulnerabilities from Episode 223)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • OOB write in KTLS ([USN-6648-1] Linux kernel vulnerabilities from Episode 220)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • UAF in AppleTalk network driver ([USN-6648-1] Linux kernel vulnerabilities from Episode 220)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • NULL ptr deref in TLS impl ([LSN-0100-1] Linux kernel vulnerability from Episode 219)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Memory leak in netfilter ([USN-6383-1] Linux kernel vulnerabilities from Episode 210)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Kernel type
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          22.04
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          20.04
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          18.04
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          16.04
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          14.04
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          aws
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          aws-5.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          aws-5.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          aws-6.5
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          aws-hwe
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          azure
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          azure-4.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          azure-5.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          azure-6.5
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          gcp
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          gcp-4.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          gcp-5.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          gcp-5.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          gcp-6.5
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          generic-4.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          generic-4.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          generic-5.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          generic-5.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          gke
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          gke-5.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          gkeop
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          hwe-6.5
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ibm
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ibm-5.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          linux
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          lowlatency
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          lowlatency-4.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          lowlatency-4.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          lowlatency-5.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          lowlatency-5.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          102.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          canonical-livepatch status
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [USN-6710-2] Firefox regressions (01:54)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 2 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-29944
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-29943
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 124.0.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • In particular fixes to allow firefox when installed directly from Mozilla to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • work under 24.04 LTS with the new AppArmor userns restrictions
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • As discussed in previous episodes, default profile allows to use userns but
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • then to be blocked on getting additional capabilities - Firefox would
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                previously try and do both a new userns and a new PID NS in one call - which
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                would be blocked - now split this into two separate calls so the userns can
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                succeed but pidns will be denied (since requires CAP_SYS_ADMIN) - but then
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                firefox correctly detects this and falls back to the correct behaviour
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [USN-6721-1] X.Org X Server vulnerabilities (04:11)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 4 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-31083
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-31082
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-31081
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-31080
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Various OOB reads -> crash / info leaks when handling byte-swapped length
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • values - able to be easily triggered by a client who is using a different
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    endianness than the X server
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • UAF in glyph handling -> crash / RCE
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6721-2] X.Org X Server regression
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 4 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-31083
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-31082
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-31081
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-31080
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • [USN-6722-1] Django vulnerability (05:19)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Trusty ESM (14.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2019-19844
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Possible account takeover - would use a case transformation on unicode of the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • email address - so if an attacker can register an email address that is the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            same as the intended targets email address after this case transformation -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            fix simply just discards the transformed email address and sends to the one
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            registered by the user
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [USN-6723-1] Bind vulnerabilities (06:11)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 2 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-50868
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-50387
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • [USN-6633-1] Bind vulnerabilities from Episode 219
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • [USN-6724-1] Linux kernel vulnerabilities (06:27)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 12 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52438
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52439
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52435
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52436
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52434
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-23850
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-22705
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-6610
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-23851
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-52429
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-50431
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-46838
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6725-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 46 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52470
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52469
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52451
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52610
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52441
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52467
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52449
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26591
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52458
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26597
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26633
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52436
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52444
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26589
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26586
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26598
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52612
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52439
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-26631
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52442
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52443
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52480
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52438
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52454
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52456
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52464
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52457
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52448
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52609
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52462
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52445
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52463
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-24860
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-23850
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-22705
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-23851
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52429
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-52340
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-46838
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-3867
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-38431
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-38430
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-38427
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-32258
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-32254
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-1194
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • [USN-6726-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 23 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52438
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52436
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52454
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52470
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52451
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52445
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52469
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52609
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52444
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52449
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26597
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-26633
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52612
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52439
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52443
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52457
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52448
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52464
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-0607
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-23851
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52429
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-52340
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-46838
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6701-4] Linux kernel (Azure) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 12 CVEs addressed in Trusty ESM (14.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-24855
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-1086
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-0775
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6121
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-51781
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-46838
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-4132
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-39197
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-34256
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-3006
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-23000
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-2002
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • [USN-6719-2] util-linux vulnerability (07:08)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-28085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Initial fix in [USN-6719-1] util-linux vulnerability from Episode 224 tried to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • escape output to avoid shell command injection - as is often the case, turned
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    out to be insufficient, so instead have now just removed the setgid permission
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    from the wall/write binaries - can then only send to yourself rather than all
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    users
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Reports of a new local root privilege escalation exploit against Linux kernel (08:32)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • https://github.com/YuriiCrimson/ExploitGMStr
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Ukrainian hacker YuriiCrimson
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Has generated a lot of interest since whilst there are always vulns / CVEs in
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • the kernel we don’t always see full PoCs much anymore
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Originally developed an exploit against the n_gsm driver in the 6.4 and and 6.5 kernels
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Says they were contacted by another hacker jmpeax (Jammes) - who wanted to purchase the exploit
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • After selling it to them, seems they tried to pass it off as their own
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • https://github.com/jmpe4x/GSM_Linux_Kernel_LPE_Nday_Exploit
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • https://jmpeax.dev/The-tale-of-a-GSM-Kernel-LPE.html
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • commit timestamps of the purported copy by Jammes are all dated over 3 weeks ago
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • but the original is only is only 1 week ago
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • so on the surface would appear the other way around
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • however, Yurii posted a video of their interaction with Jammes on Telegram
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • to try and prove their side
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • looking at repo metadata
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • https://api.github.com/repos/jmpe4x/GSM_Linux_Kernel_LPE_Nday_Exploit shows
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        the so-called copy was created on 22nd March
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • whereas the Yurii’s is 6th April - so would appear that perhaps Jammes is
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • the original author
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • also can compare the two exploits and see they are almost identical - but
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Jammes has an extra target for the 6.5.0-26-generic kernel from mantic
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        diff -w <(curl https://raw.githubusercontent.com/jmpe4x/GSM_Linux_Kernel_LPE_Nday_Exploit/main/main.c) <(curl https://raw.githubusercontent.com/YuriiCrimson/ExploitGSM/main/ExploitGSM_6_5/main.c)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • who the actual author is remains unclear (also I don’t have telegram so
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • couldn’t check the video)…
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Regarding the actual vulnerability - turns out there is at least 2 if not 3 in this module
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Old CVE-2023-6546 - written up https://github.com/Nassim-Asrir/ZDI-24-020/
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Fixed in 6.5-rc7
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Yurii / Jammes
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Additional exploit by Yurii apparently targeting 5.15-6.1 - also in n_gsm
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Mixed reports about this last exploit but report the one from
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Yurii/Jammes does work even on the latest upstream kernel
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Waiting on a fix from upstream to then integrate in Ubuntu kernels
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Interesting these exploits all used the same basic info leak from xen via
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • /sys/kernel/notes which leaks the symbol of the xen_startup function and
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          allows to break KASLR
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Reports this was known since at least 2020
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Many eyes…?
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Ubuntu 24.04 LTS (Noble Numbat) Beta released (14:01)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • https://lists.ubuntu.com/archives/ubuntu-announce/2024-April/000300.html
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • https://discourse.ubuntu.com/t/noble-numbat-release-notes/
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Also releases for all the flavours
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Edubuntu, Kubuntu, Lubuntu, Ubuntu Budgie, Ubuntu Cinnamon, UbuntuKylin,
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Ubuntu MATE, Ubuntu Studio, Ubuntu Unity, Xubuntu
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Final release scheduled for 25th April (just under 2 weeks)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Update on xz-utils (15:18)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • When we talked about xz-utils last week, didn’t really talk much about the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • main upstream developer Lasse Collin
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Thought it could be interesting to dive into how they essentially got
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • compromised by this actor - but that is perhaps done better by others - go
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                listen to the latest episode of Between Two Nerds from Tom Uren and The Grugq
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                (https://risky.biz/BTN74/) talking about the tradecraft used to infiltrate the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                project and comparing this against the more traditional HUMINT elements
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Lasse Collin’s github account and the Github project for xz was reinstated
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Backdoor removed
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Great sense of humour:
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • The executable payloads were embedded as binary blobs in

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  the test files. This was a blatant violation of the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Debian Free Software Guidelines.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • On machines that see lots bots poking at the SSH port, the backdoor

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  noticeably increased CPU load, resulting in degraded user experience
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  and thus overwhelmingly negative user feedback.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • The maintainer who added the backdoor has disappeared.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Backdoors are bad for security.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Also removed the ifunc (indirect function) support - ostensibly used to allow a
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • developer to create multiple implementations of a given function and select
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    between then at runtime - in this case was for an optimised version of CRC
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    calculation - but abused by the backdoor to be able to hook into and replace
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    functions in the global symbol table before it gets made read-only by the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    dynamic loader
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Says this was not for security reasons but since it makes the code harder to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • maintain but is clearly a good win for security
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Lasse still plans to make to write an article on the backdoor etc but is more
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • focused on cleaning up the upstream repo first - next version is likely to be
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      5.8.0
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Watch this space…
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 20 min
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Episode 224
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Overview

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        It’s been an absolutely manic week in the Linux security community as the news

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        and reaction to the recent announcement of a backdoor in the xz-utils project
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        was announced late last week, so we dive deep into this issue and discuss how it
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        impacts Ubuntu and give some insights for what this means for the open source
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        and Linux communities in the future.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        20 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [USN-6718-2] curl vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-2398
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6719-1] util-linux vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-28085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • [USN-6686-5] Linux kernel (Intel IoTG) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 9 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-0607
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-0340
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-6121
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-51782
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-51779
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-46862
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-46343
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-4134
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-22995
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6715-1] unixODBC vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-1013
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • [USN-6704-4] Linux kernel (Intel IoTG) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 5 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-24855
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-1086
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-1085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-32247
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-23000
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6707-4] Linux kernel (Azure) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 4 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-26599
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-26597
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-1086
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-1085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • [USN-6720-1] Cacti vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 1 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-39361
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    xz-utils backdoor and Ubuntu
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • https://www.openwall.com/lists/oss-security/2024/03/29/4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Late last week, 28th / 29th March backdoor in liblzma from xz-utils was
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • disclosed to the open source community via oss-security mailing list - this
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      was in the recent 5.6.0/5.6.1 releases from late Feb/early March this year
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • initially the impact was not entirely clear - assumed initially that it may
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • impact only xz-utils and so only in handling of xz compressed data / files -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      but even with that assumption that perhaps it could then infect anything that
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      got compressed/decompressed
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • within a few hours though became clear that the primary target was not
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • xz-utils/liblzma itself but openssh - and the affect was to provide a backdoor
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      into openssh that would allow the attacker to get remote access to any machine
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      running ssh server with this backdoor liblzma installed
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • To paint a picture - this was all unfolding on late Thursday / Friday of the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Easter break, so lots of folks were either EOD or on leave etc - and trying to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      grapple with a threat that we knew could possibly impact the impedending 24.04
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      LTS release
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Good news:
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • TL;DR for Ubuntu, this version was only ever in the -proposed pocket for the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • currently in-development 24.04 release - not in any other Ubuntu versions -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        and was removed as soon as we became aware, so unless you are running the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        devel release AND you had manually opted to install this version from the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        -proposed pocket, you would not be affected - very lucky
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • https://discourse.ubuntu.com/t/xz-liblzma-security-update/43714
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • What do we know about this? A lot - there has been significant investigation
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • (and speculation) since it was announced, both at the social side of things
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        and the technical aspects of the backdoor itself
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • For the purpose of the podcast, we won’t go too deep into either but will try
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • and cover the salient details
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Regarding the inclusion of the backdoor itself - looks to have been a very
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • long and patient campaign by the attacker, who slowly gained the trust of the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        upstream project over the last 2 years and likely pressured the maintainer via
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        sock-puppet accounts to then get themselves added as an additional maintainer
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Since then they seemed to be quite a good maintainer themselves - diligently
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • adding new features and bug fixes etc over the past 2 years, but then suddenly
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        introduced the backdoor into the most recent 2 releases
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • The method of introducing the backdoor was also interesting, in that it
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • required 2 parts - the binary containing the backdoor and the code to get this
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        compiled into the liblzma library at build time
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • The binary was committed into the upstream git repo disguised as an xz
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • archive itself used as part of the test suite
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • The code to inject this into the build was NOT part of the git repo, but
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • instead was just in the tarball prepared by the maintainer for the official
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          release
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • And it used many levels of obfuscation to hide this backdoor within that
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • fake test xz archive
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • So the attacker was not just patient but also very technically skilled - and
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • not just multiple levels of obfuscation in the build process but the backdoor
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          code itself contained many elements to try and make it harder to recognise and
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          reverse engineer, presumably to allow it to hide in plain sight
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • although as we will see, this runtime obfuscation within the backdoor binary
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • was what gave it away eventually
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • It’s often said that one of the advantages of Open Source is the huge
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • community, which is summarised as Linus’ Law - with enough eyeballs all bugs
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            are shallow - but sadly this wasn’t proven out in this case
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Backdoor was not
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • found by anyone doing review of the changes upstream or by the various distros
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            like Debian / Fedora / OpenSUSE / Arch or even Ubuntu when incorporating this
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            new version into their repos - but instead was found by Andres Freund, one of
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            the maintainers of PostgreSQL, when they were looking to benchmark some new
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            changes scheduled for the next PostgreSQL release
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Luckily decided to use Debian unstable for this, and Debian had incorporated
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • this new version into unstable a few weeks ago, and wanted to get the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            performance noise floor of the system as low as possible before doing
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            benchmarking of PostgreSQL - noticed large transient CPU spikes in sshd and
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            then eventually weird memory errors in sshd due to bugs in the initial version
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            of the backdoor
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • After a lot of painstaking work was able to determine that liblzma was the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • culprit and appeared to contain some very strange code to hook into the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            authentication process of sshd when it was launched via systemd
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Was able to trace that back to the aforementioned manually prepared tarballs
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • of xz-utils on Github
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • The CPU spikes Andres observed were due to the use of things like a trie to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • lookup symbol names at runtime, rather than directly encoding them in the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            exploit binary, presumably to try and make reverse engineering of the binary
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            harder (since you can’t just run strings on it and get any real sensible output)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Some excellent writeups have been done regarding both the technical aspects of
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • the backdoor itself, as well as the process taken by the attacker to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            incorporate this into the xz-utils project - both from a community point of
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            view and a technical point of view
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • From a technical point of view, the impact of this backdoor was to allow an
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • attacker to get pre-authentication remote-code execution in sshd via a
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            specific private key when connecting to the server - NOBUS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Hooked into the RSA certificate validation process in sshd, looking for a
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • particular matching private key from the client - and if found would then
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              proceed to execute arbitrary commands specified by the client without
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              requiring usual authentication
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • By using this mechanism, nobody but the attacker can use the backdoor since
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • they don’t have the matching private key - so the impact of the backdoor is
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              somewhat limited
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • BUT the fact they targeted such a widely used and deployed package across a
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • huge number of distros, means they essentially wanted a backdoor into any
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Linux machine in the future that only they could use
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Interesting to try and speculate who the attacker could be (nation state?) and
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • what their intended purpose was especially given this wide reaching goal of
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              getting this into all the major Linux distros - but it would be just
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              speculation
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • So rather than speculate, for the purpose of this podcast episode, interesting
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • to look at the timeline as it concerned Ubuntu
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • The publishing history of the package is all visible in Launchpad
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Packages in Ubuntu get inherited from Debian who also publish history
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Upstream published the first backdoored version 5.6.0 via GitHub tarball on 24th Feb 2024
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Debian incorporated this into unstable on 26th Feb
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • On 27th Feb, the Ubuntu Archive Auto-Sync bot copied this version into noble-proposed
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Due to the ongoing time_t transition, sat it noble-proposed for the next month
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Security team heard whispers of the possible backdoor just hours before it was
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • publicly disclosed, and as soon as we heard of the possible backdoor, and
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              realised that it only affected the version in-development noble-proposed we
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              quickly notified the Archive Admin team who then deleted it from
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              noble-proposed on 29th March, neutralising the main threat
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Most important thing to know for Ubuntu, we have taken a very conservative
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • approach - not only have we removed this version from noble-proposed as soon
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              as we became aware, we are then rebuilding every binary package that got built
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              since that compromised version was in noble-proposed originally - out of an
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              abundance of caution - we don’t have any information that says this backdoor
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              was doing anything other than what the various writeups have found so far, BUT
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              we also can’t be certain that it didn’t have other functionality either - so
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              being very cautious and rebuilding everything that was itself built since 27th
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Feb
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • As such, delayed the development of 24.04 so beta release is slipping by one week
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • One of the most interesting parts is the sheer luck that this was found - not
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • by security researchers or maintainers but by a developer from Microsoft who
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              happened to be looking for the right things at the right time and decided to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              be curious
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Also for Ubuntu, luck that the time_t transition in Debian/Ubuntu caused many
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • packages to be stuck in noble-proposed and not in the release pocket, else
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              many Ubuntu users and developers would have been impacted if this had migrated
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              to the noble release pocket
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Also interesting that the attacker appears to have had quite a good grasp on
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • OSS development practices and was quite persistent in trying to get this
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              incorporated into distros - even urging for this new version to be synced to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Ubuntu so that it would land in the upcoming noble release as recently as
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Thursday last week, just hours before the public disclosure
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Not only could they do all the original social engineering work upstream,
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • and technical work to develop and hide the backdoor, but could then
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                interface with distros via their established practices to try and get them
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                to incorporate their new backdoored version faster than they may have
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                otherwise
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Huge amount of work has been done to detail both the timeline of the attack as
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • well as the technical details of both the code used to incorporate the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                backdoored code into the final liblzma binary during the build process, as
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                well as the details of the backdoor itself and how it operates at runtime
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • In the end highlights both the challenges and strengths of OSS - lots of OSS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • projects have long dependency chains - in this case openssh when integrated
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                with libsystemd which in turn used liblzma - and it is unclear who the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                maintainers and authors are or what procedures are in place for vetting and
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                transferring ownership of OSS projects - all present significant challenges
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                for OSS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • However, significant strength of OSS is the visibility and ability for anyone
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • to get involved, which is what we saw in the aftermath - despite all the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                advanced obfuscation techniques employed was able to be analysed in a matter
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                of days by the community working together - and to analyse it in a huge amount
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                of depth and in such an open way that it leaves little room for questioning
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                the validity of the assessment - anyone can double check the work and come to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                the same conclusions
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • This isn’t the first software supply chain attack and likely isn’t even the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • first against an OSS project but it is a wake-up call to the OSS and Linux
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ecosystem
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 29 min

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                About Ubuntu Security Podcast

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                From the publisher's feed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                A fortnightly podcast talking about the latest developments and updates from the Ubuntu Security team, including a summary of recent security vulnerabilities and fixes as well as a discussion on some…