Ubuntu Security Podcast

Ubuntu Security Podcast

By Ubuntu Security TeamTechnology
Download on the App Store

Ubuntu Security Podcast episodes

  • Episode 223
    Overview

    This week we bring you a sneak peak of how Ubuntu 23.10 fared at Pwn2Own

    Vancouver 2024, plus news of malicious themes in the KDE Store and we cover
    security updates for the Linux kernel, X.Org X Server, TeX Live, Expat, Bash and
    more.

    This week in Ubuntu Security Updates

    61 unique CVEs addressed

    [USN-6681-3] Linux kernel vulnerabilities (00:54)
    • 8 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
      • CVE-2024-0340
      • CVE-2023-6121
      • CVE-2023-51782
      • CVE-2023-51780
      • CVE-2023-51779
      • CVE-2023-4244
      • CVE-2023-22995
      • CVE-2021-44879
      • 5.4 - IBM, Oracle
      • UAF due to a race-condition in netfilter - underflow a reference counter ->
      • UAF
        [USN-6686-2] Linux kernel vulnerabilities (01:42)
        • 9 CVEs addressed in Jammy (22.04 LTS)
          • CVE-2024-0607
          • CVE-2024-0340
          • CVE-2023-6121
          • CVE-2023-51782
          • CVE-2023-51779
          • CVE-2023-46862
          • CVE-2023-46343
          • CVE-2023-4134
          • CVE-2023-22995
          • 5.15 - Raspi, Lowlatency
          • [USN-6699-1] Linux kernel vulnerabilities (01:52)
            • 3 CVEs addressed in Trusty ESM (14.04 ESM)
              • CVE-2024-24855
              • CVE-2023-4921
              • CVE-2023-30456
              • 3.13 - generic, lowlatency, server, virtual
              • KVM mishandling of control registers for nested guest VMs
                • [USN-6123-1] Linux kernel (OEM) vulnerabilities from Episode 197
                • UAF in Quick Fair Queuing network packet scheduler
                  • Local privesc, reported to Google’s kCTF
                  • [USN-6700-1] Linux kernel vulnerabilities (02:40)
                    • 7 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM)
                      • CVE-2024-24855
                      • CVE-2024-1086
                      • CVE-2024-0775
                      • CVE-2023-51781
                      • CVE-2023-39197
                      • CVE-2023-34256
                      • CVE-2022-20567
                      • 4.4 - generic, kvm, lowlatency, virtual, aws (14.04 only)
                      • UAF in nftables - also originally reported to kCTF
                      • [USN-6701-1] Linux kernel vulnerabilities
                        • 12 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                          • CVE-2024-24855
                          • CVE-2024-1086
                          • CVE-2024-0775
                          • CVE-2023-6121
                          • CVE-2023-51781
                          • CVE-2023-46838
                          • CVE-2023-4132
                          • CVE-2023-39197
                          • CVE-2023-34256
                          • CVE-2023-3006
                          • CVE-2023-23000
                          • CVE-2023-2002
                          • 4.15 - oracle, kvm, aws, generic, lowlatency
                          • UAF in nftables from above and UAF in AppleTalk network driver - [USN-6648-1]
                          • Linux kernel vulnerabilities from Episode 220
                            [USN-6680-3] Linux kernel (AWS) vulnerabilities
                            • 7 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                              • CVE-2024-25744
                              • CVE-2024-0607
                              • CVE-2023-6560
                              • CVE-2023-6121
                              • CVE-2023-51782
                              • CVE-2023-51779
                              • CVE-2023-46343
                              • 6.5 - aws
                              • [USN-6681-4] Linux kernel (AWS) vulnerabilities
                                • 8 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                  • CVE-2024-0340
                                  • CVE-2023-6121
                                  • CVE-2023-51782
                                  • CVE-2023-51780
                                  • CVE-2023-51779
                                  • CVE-2023-4244
                                  • CVE-2023-22995
                                  • CVE-2021-44879
                                  • 5.4 - aws
                                  • UAF in netfilter discussed earlier
                                  • [USN-6686-3] Linux kernel (Oracle) vulnerabilities
                                    • 9 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                      • CVE-2024-0607
                                      • CVE-2024-0340
                                      • CVE-2023-6121
                                      • CVE-2023-51782
                                      • CVE-2023-51779
                                      • CVE-2023-46862
                                      • CVE-2023-46343
                                      • CVE-2023-4134
                                      • CVE-2023-22995
                                      • 5.15 - oracle
                                      • [USN-6702-1] Linux kernel vulnerabilities
                                        • 4 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                          • CVE-2024-24855
                                          • CVE-2024-1086
                                          • CVE-2023-23004
                                          • CVE-2023-23000
                                          • 5.4 - iot, ibm, bluefield, gkeop, kvm, oracle, gcp, generic, lowlatency, oem
                                          • Second netfilter UAF above
                                          • [USN-6587-5] X.Org X Server vulnerabilities (03:34)
                                            • 7 CVEs addressed in Trusty ESM (14.04 ESM)
                                              • CVE-2024-21886
                                              • CVE-2024-21885
                                              • CVE-2024-0409
                                              • CVE-2024-0408
                                              • CVE-2024-0229
                                              • CVE-2023-6816
                                              • CVE-2023-6478
                                              • Previous updates for X now available in 14.04 ESM
                                              • Most issues either OOB R/W - impact is then can crash X Server or potentially
                                              • get code execution - nowadays X runs unprivileged but in 14.04 still runs as
                                                root so these vulns are more severe in the older releases
                                                [USN-6673-2] python-cryptography vulnerability (04:21)
                                                • 1 CVEs addressed in Xenial ESM (16.04 ESM)
                                                  • CVE-2023-50782
                                                  • [USN-6673-1] python-cryptography vulnerabilities from Episode 220
                                                  • [USN-6695-1] TeX Live vulnerabilities (04:28)
                                                    • 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                      • CVE-2024-25262
                                                      • CVE-2023-32668
                                                      • CVE-2019-18604
                                                      • Heap buffer overflow via a crafted TTF file
                                                      • LuaTeX specific issue - allowed a document to make arbitrary network requests
                                                      • since it didn’t disable access to the underlying lua socket library
                                                      • Misused sprint() resulting in a buffer overflow in the axohelp - helper
                                                      • program for the LaTeX axodraw2 package when used with pdflatex
                                                        [USN-6694-1] Expat vulnerabilities (05:24)
                                                        • 2 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                          • CVE-2024-28757
                                                          • CVE-2023-52425
                                                          • C library for parsing xml
                                                            • used by many other applications like gdb, dbus, audacity, git, python,
                                                            • polkit, squid and more
                                                            • CPU/memory-based DoS since would do many full reparsings of a document in some cases
                                                            • XML Entity Expansion attack
                                                              • billion laughs attack / XML bomb - 10 entities which each comprise 10 of the
                                                              • previous entity with the document containing a single instance of the
                                                                largest entity - 1 billion copies of the original entity
                                                                [USN-6696-1] OpenJDK 8 vulnerabilities (06:40)
                                                                • 6 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                  • CVE-2024-20952
                                                                  • CVE-2024-20945
                                                                  • CVE-2024-20926
                                                                  • CVE-2024-20921
                                                                  • CVE-2024-20919
                                                                  • CVE-2024-20918
                                                                  • [USN-6660-1, USN-6661-1] OpenJDK 11 & 17 vulnerabilities from Episode 220
                                                                  • [USN-6697-1] Bash vulnerability (07:01)
                                                                    • 1 CVEs addressed in Jammy (22.04 LTS)
                                                                      • CVE-2022-3715
                                                                      • Heap buffer overflow on a valid parameter transformation - can then
                                                                      • unexpectedly lead to possible code execution
                                                                        [USN-6698-1] Vim vulnerability (07:30)
                                                                        • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                          • CVE-2024-22667
                                                                          • stack buffer overflow when parsing a crafted command file - ie. the user has
                                                                          • to load a crafted file to be sourced by vim
                                                                            [USN-6703-1] Firefox vulnerabilities (07:48)
                                                                            • 11 CVEs addressed in Focal (20.04 LTS)
                                                                              • CVE-2024-2613
                                                                              • CVE-2024-2612
                                                                              • CVE-2024-2610
                                                                              • CVE-2024-2608
                                                                              • CVE-2024-2607
                                                                              • CVE-2024-2606
                                                                              • CVE-2023-5388
                                                                              • CVE-2024-2615
                                                                              • CVE-2024-2614
                                                                              • CVE-2024-2611
                                                                              • CVE-2024-2609
                                                                              • 124.0
                                                                              • Goings on in Ubuntu Security Community
                                                                                Summary of Pwn2Own Vancouver 2024 results against Ubuntu 23.10 (08:05)
                                                                                • https://www.zerodayinitiative.com/blog/2024/3/20/pwn2own-vancouver-2024-day-one-results
                                                                                • The DEVCORE Team was able to execute their LPE attack against Ubuntu
                                                                                • Linux. However, the bug they used was previously known. They still earn
                                                                                  $10,000 and 1 Master of Pwn points.
                                                                                  • https://youtube.com/shorts/fXUrMIM2KYc?si=VIR7YKIt86NGEceU
                                                                                  • Kyle Zeng from ASU SEFCOM used an ever tricky race condition to escalate
                                                                                  • privileges on Ubuntu Linux desktop. This earns him him $20,000 and 20 Master
                                                                                    of Pwn points.
                                                                                    • https://www.youtube.com/shorts/HSIasEbEkXY
                                                                                    • https://www.zerodayinitiative.com/blog/2024/3/21/pwn2own-vancouver-2024-day-two-results
                                                                                    • STAR Labs SG successfully demonstrated their privilege escalation on Ubuntu
                                                                                    • desktop. However, they used a bug that was previously reported. They still
                                                                                      earn $5,000 and 1 Master of Pwn point.
                                                                                    • The final entry of Pwn2Own Vancouver 2024 ends as a collision as Theori used a
                                                                                    • bug that was previously know to escalate privileges on Ubuntu desktop. He
                                                                                      still wins $5,000 and 1 Master of Pwn point.
                                                                                      Reports of malicious themes in KDE Store (10:27)
                                                                                      • https://www.bleepingcomputer.com/news/linux/kde-advises-extreme-caution-after-theme-wipes-linux-users-files/
                                                                                      • https://floss.social/@kde/112128243960545659
                                                                                      • https://www.reddit.com/r/kde/comments/1bixmbx/do_not_install_global_themes_some_wipe_out_all/
                                                                                      • Get in contact
                                                                                        • #ubuntu-security on the Libera.Chat IRC network
                                                                                        • ubuntu-hardened mailing list
                                                                                        • Security section on discourse.ubuntu.com
                                                                                        • @[email protected], @ubuntu_sec on twitter
                                                                                        • 18 min
                                                                                        • Episode 222
                                                                                          Overview

                                                                                          We cover recent Linux malware from the Magnet Goblin threat actor, plus the news

                                                                                          of Ubuntu 23.10 as a target in Pwn2Own Vancouver 2024 and we detail
                                                                                          vulnerabilities in Puma, AccountsService, Open vSwitch, OVN, and more.

                                                                                          This week in Ubuntu Security Updates

                                                                                          102 unique CVEs addressed

                                                                                          [USN-6679-1] FRR vulnerability (01:11)
                                                                                          • 1 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                                                            • CVE-2024-27913
                                                                                            • OOB read when parsing a malformed OSPF LSA packet - would try and access
                                                                                            • attributes fields even if none where present
                                                                                              [LSN-0101-1] Linux kernel vulnerability (01:50)
                                                                                              • 5 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                • CVE-2024-0646
                                                                                                • CVE-2024-0193
                                                                                                • CVE-2023-7192
                                                                                                • CVE-2023-6932
                                                                                                • CVE-2023-6817
                                                                                                • [USN-6648-1] Linux kernel vulnerabilities from Episode 220
                                                                                                • [USN-6606-1] Linux kernel (OEM) vulnerabilities from Episode 217
                                                                                                • [USN-6647-1] Linux kernel vulnerabilities from Episode 220
                                                                                                • [USN-6601-1] Linux kernel vulnerability from Episode 217
                                                                                                • Kernel type
                                                                                                  22.04
                                                                                                  20.04
                                                                                                  18.04
                                                                                                  16.04
                                                                                                  14.04
                                                                                                  aws
                                                                                                  101.1
                                                                                                  101.1
                                                                                                  101.1
                                                                                                  101.1
                                                                                                  —
                                                                                                  aws-5.15
                                                                                                  —
                                                                                                  101.1
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  aws-5.4
                                                                                                  —
                                                                                                  —
                                                                                                  101.1
                                                                                                  —
                                                                                                  —
                                                                                                  aws-6.5
                                                                                                  101.1
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  aws-hwe
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  101.1
                                                                                                  —
                                                                                                  azure
                                                                                                  101.1
                                                                                                  101.1
                                                                                                  —
                                                                                                  101.1
                                                                                                  —
                                                                                                  azure-4.15
                                                                                                  —
                                                                                                  —
                                                                                                  101.1
                                                                                                  —
                                                                                                  —
                                                                                                  azure-5.4
                                                                                                  —
                                                                                                  —
                                                                                                  101.1
                                                                                                  —
                                                                                                  —
                                                                                                  azure-6.5
                                                                                                  101.1
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  gcp
                                                                                                  101.1
                                                                                                  101.1
                                                                                                  —
                                                                                                  101.1
                                                                                                  —
                                                                                                  gcp-4.15
                                                                                                  —
                                                                                                  —
                                                                                                  101.1
                                                                                                  —
                                                                                                  —
                                                                                                  gcp-5.15
                                                                                                  —
                                                                                                  101.1
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  gcp-5.4
                                                                                                  —
                                                                                                  —
                                                                                                  101.1
                                                                                                  —
                                                                                                  —
                                                                                                  gcp-6.5
                                                                                                  101.1
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  generic-4.15
                                                                                                  —
                                                                                                  —
                                                                                                  101.1
                                                                                                  101.1
                                                                                                  —
                                                                                                  generic-4.4
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  101.1
                                                                                                  101.1
                                                                                                  generic-5.15
                                                                                                  —
                                                                                                  101.2
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  generic-5.4
                                                                                                  —
                                                                                                  101.1
                                                                                                  101.1
                                                                                                  —
                                                                                                  —
                                                                                                  gke
                                                                                                  101.1
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  gke-5.15
                                                                                                  —
                                                                                                  101.1
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  gkeop
                                                                                                  —
                                                                                                  101.1
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  hwe-6.5
                                                                                                  101.1
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  ibm
                                                                                                  101.1
                                                                                                  101.1
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  ibm-5.15
                                                                                                  —
                                                                                                  101.1
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  linux
                                                                                                  101.2
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  lowlatency-4.15
                                                                                                  —
                                                                                                  —
                                                                                                  101.1
                                                                                                  101.1
                                                                                                  —
                                                                                                  lowlatency-4.4
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  101.1
                                                                                                  101.1
                                                                                                  lowlatency-5.15
                                                                                                  —
                                                                                                  101.2
                                                                                                  —
                                                                                                  —
                                                                                                  —
                                                                                                  lowlatency-5.4
                                                                                                  —
                                                                                                  101.1
                                                                                                  101.1
                                                                                                  —
                                                                                                  —

                                                                                                  To check your kernel type and Livepatch version, enter this command:

                                                                                                  canonical-livepatch status
                                                                                                  [USN-6680-1] Linux kernel vulnerabilities (02:47)
                                                                                                  • 7 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                                                                    • CVE-2024-25744
                                                                                                    • CVE-2024-0607
                                                                                                    • CVE-2023-6560
                                                                                                    • CVE-2023-6121
                                                                                                    • CVE-2023-51782
                                                                                                    • CVE-2023-51779
                                                                                                    • CVE-2023-46343
                                                                                                    • [USN-6681-1] Linux kernel vulnerabilities
                                                                                                      • 8 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                        • CVE-2024-0340
                                                                                                        • CVE-2023-6121
                                                                                                        • CVE-2023-51782
                                                                                                        • CVE-2023-51780
                                                                                                        • CVE-2023-51779
                                                                                                        • CVE-2023-4244
                                                                                                        • CVE-2023-22995
                                                                                                        • CVE-2021-44879
                                                                                                        • [USN-6686-1] Linux kernel vulnerabilities
                                                                                                          • 9 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                            • CVE-2024-0607
                                                                                                            • CVE-2024-0340
                                                                                                            • CVE-2023-6121
                                                                                                            • CVE-2023-51782
                                                                                                            • CVE-2023-51779
                                                                                                            • CVE-2023-46862
                                                                                                            • CVE-2023-46343
                                                                                                            • CVE-2023-4134
                                                                                                            • CVE-2023-22995
                                                                                                            • [USN-6680-2] Linux kernel vulnerabilities
                                                                                                              • 7 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                • CVE-2024-25744
                                                                                                                • CVE-2024-0607
                                                                                                                • CVE-2023-6560
                                                                                                                • CVE-2023-6121
                                                                                                                • CVE-2023-51782
                                                                                                                • CVE-2023-51779
                                                                                                                • CVE-2023-46343
                                                                                                                • [USN-6681-2] Linux kernel vulnerabilities
                                                                                                                  • 8 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                    • CVE-2024-0340
                                                                                                                    • CVE-2023-6121
                                                                                                                    • CVE-2023-51782
                                                                                                                    • CVE-2023-51780
                                                                                                                    • CVE-2023-51779
                                                                                                                    • CVE-2023-4244
                                                                                                                    • CVE-2023-22995
                                                                                                                    • CVE-2021-44879
                                                                                                                    • [USN-6688-1] Linux kernel (OEM) vulnerabilities (03:32)
                                                                                                                      • 63 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                        • CVE-2024-26600
                                                                                                                        • CVE-2023-52467
                                                                                                                        • CVE-2023-52588
                                                                                                                        • CVE-2023-52594
                                                                                                                        • CVE-2023-52470
                                                                                                                        • CVE-2024-26598
                                                                                                                        • CVE-2023-52589
                                                                                                                        • CVE-2023-52583
                                                                                                                        • CVE-2023-52444
                                                                                                                        • CVE-2023-52449
                                                                                                                        • CVE-2024-26591
                                                                                                                        • CVE-2023-52598
                                                                                                                        • CVE-2023-52448
                                                                                                                        • CVE-2024-26597
                                                                                                                        • CVE-2023-52605
                                                                                                                        • CVE-2023-52451
                                                                                                                        • CVE-2023-52454
                                                                                                                        • CVE-2023-52445
                                                                                                                        • CVE-2023-52587
                                                                                                                        • CVE-2023-52447
                                                                                                                        • CVE-2023-52436
                                                                                                                        • CVE-2023-52593
                                                                                                                        • CVE-2023-52601
                                                                                                                        • CVE-2024-26594
                                                                                                                        • CVE-2024-26592
                                                                                                                        • CVE-2024-26589
                                                                                                                        • CVE-2023-52462
                                                                                                                        • CVE-2023-52469
                                                                                                                        • CVE-2023-52438
                                                                                                                        • CVE-2023-52457
                                                                                                                        • CVE-2023-52458
                                                                                                                        • CVE-2023-52595
                                                                                                                        • CVE-2023-52597
                                                                                                                        • CVE-2023-52464
                                                                                                                        • CVE-2023-52463
                                                                                                                        • CVE-2023-52606
                                                                                                                        • CVE-2024-26625
                                                                                                                        • CVE-2023-52584
                                                                                                                        • CVE-2024-26624
                                                                                                                        • CVE-2023-52600
                                                                                                                        • CVE-2024-26581
                                                                                                                        • CVE-2024-26588
                                                                                                                        • CVE-2023-52603
                                                                                                                        • CVE-2023-52599
                                                                                                                        • CVE-2023-52443
                                                                                                                        • CVE-2023-52602
                                                                                                                        • CVE-2023-52456
                                                                                                                        • CVE-2023-52607
                                                                                                                        • CVE-2024-26628
                                                                                                                        • CVE-2024-26601
                                                                                                                        • CVE-2024-26627
                                                                                                                        • CVE-2023-52439
                                                                                                                        • CVE-2023-52604
                                                                                                                        • CVE-2024-26599
                                                                                                                        • CVE-2024-24860
                                                                                                                        • CVE-2024-23849
                                                                                                                        • CVE-2024-1086
                                                                                                                        • CVE-2024-1085
                                                                                                                        • CVE-2024-0340
                                                                                                                        • CVE-2023-6610
                                                                                                                        • CVE-2023-5633
                                                                                                                        • CVE-2023-50431
                                                                                                                        • CVE-2023-46838
                                                                                                                        • [USN-6682-1] Puma vulnerabilities (05:00)
                                                                                                                          • 6 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                            • CVE-2024-21647
                                                                                                                            • CVE-2023-40175
                                                                                                                            • CVE-2022-24790
                                                                                                                            • CVE-2022-23634
                                                                                                                            • CVE-2020-11077
                                                                                                                            • CVE-2020-11076
                                                                                                                            • HTTP server for Ruby/Rack applications that uses threading for improved performance
                                                                                                                            • [USN-6597-1] Puma vulnerability from Episode 217 - HTTP request smuggling
                                                                                                                            • attack - fixed for mantic and lunar - now for older releases, plus a bunch of
                                                                                                                              other older HTTP request smuggling issues as well
                                                                                                                              [USN-6683-1] HtmlCleaner vulnerability (05:45)
                                                                                                                              • 1 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                • CVE-2023-34624
                                                                                                                                • Java library for parsing HTML
                                                                                                                                • DoS through crafted objects with cyclic dependencies
                                                                                                                                • [USN-6684-1] ncurses vulnerability (06:01)
                                                                                                                                  • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                    • CVE-2023-50495
                                                                                                                                    • Possible issue when parsing terminfo files - these are generally trusted, and
                                                                                                                                    • since the previous update for CVE-2023-29491 in
                                                                                                                                      [USN-6099-1] ncurses vulnerabilities from
                                                                                                                                      Episode 196 untrusted terminfo files are not parsed when the application is
                                                                                                                                      setuid root. So has no real security impact.
                                                                                                                                      [USN-6685-1] mqtt-client vulnerability ()
                                                                                                                                      • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                        • CVE-2019-0222
                                                                                                                                        • Java MQTT Client library
                                                                                                                                        • Unmarshalling a crafted MQTT frame could lead to a OOM exception -> DoS
                                                                                                                                        • [USN-6687-1] AccountsService vulnerability (07:25)
                                                                                                                                          • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                            • CVE-2012-6655
                                                                                                                                            • Oldest CVE this week?
                                                                                                                                            • Only fixed 1 year ago by upstream
                                                                                                                                            • To change the user’s password, Would invoke usermod with -p option and the new
                                                                                                                                            • encrypted/salted password - as such any user on the system would be able to
                                                                                                                                              see that via inspection of /proc//cmdline - very low risk since the
                                                                                                                                              process only exists for a very small time AND it is encrypted already - so
                                                                                                                                              instead now invokes chpasswd and specifies the new encrypted password over
                                                                                                                                              standard input - would then need to be able to ptrace to see it which with
                                                                                                                                              YAMA ptrace_scope enabled in Ubuntu means you need to be root (or a parent
                                                                                                                                              process of accountsservice, which is started by dbus for the current user) -
                                                                                                                                              so then an attacker would have to be able to cause the existing accountservice
                                                                                                                                              to stop and then start their own to see the new encrypted password
                                                                                                                                              [USN-6658-2] libxml2 vulnerability (09:41)
                                                                                                                                              • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                • CVE-2024-25062
                                                                                                                                                • [USN-6658-1] libxml2 vulnerability from Episode 220
                                                                                                                                                • UAF if using DTD validation with XInclude expansion enabled
                                                                                                                                                • [USN-6690-1] Open vSwitch vulnerabilities (10:01)
                                                                                                                                                  • 2 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                    • CVE-2023-5366
                                                                                                                                                    • CVE-2023-3966
                                                                                                                                                    • [USN-6514-1] Open vSwitch vulnerability from Episode 214
                                                                                                                                                    • Original fix was incomplete - required additional fixes
                                                                                                                                                    • OOB read in hardware offload of Geneve packets (protocol for generic network
                                                                                                                                                    • virtualisation encapsulation) - can mitigate by disabling this option in
                                                                                                                                                      config
                                                                                                                                                      [USN-6689-1] Rack vulnerabilities (10:41)
                                                                                                                                                      • 3 CVEs addressed in Mantic (23.10)
                                                                                                                                                        • CVE-2024-26146
                                                                                                                                                        • CVE-2024-26141
                                                                                                                                                        • CVE-2023-27539
                                                                                                                                                        • Modular Ruby web server
                                                                                                                                                        • Possible reflected DoS - crafted Range header can result in unexpectedly large
                                                                                                                                                        • responses - can request ranges for a file which ends up being larger than the
                                                                                                                                                          file itself - so now just return nothing
                                                                                                                                                        • ReDoS in header parsing - used a regex to split options and strip - now just splits on a
                                                                                                                                                        • comma directly then strip each separately
                                                                                                                                                          [USN-6656-2] PostgreSQL vulnerability (11:51)
                                                                                                                                                          • 1 CVEs addressed in Xenial ESM (16.04 ESM)
                                                                                                                                                            • CVE-2024-0985
                                                                                                                                                            • [USN-6656-1] PostgreSQL vulnerability from Episode 220
                                                                                                                                                            • [USN-6691-1] OVN vulnerability (12:00)
                                                                                                                                                              • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                • CVE-2024-2182
                                                                                                                                                                • Enabled bidirectional forwarding detection on logical ports - this is used to
                                                                                                                                                                • monitor the health of remote nodes and the tunnels between them - BFD packets
                                                                                                                                                                  are then transmitted in-band in these tunnels along with other traffic - OVN
                                                                                                                                                                  would then process any BFD packet received on a tunnel where it was enabled -
                                                                                                                                                                  as such a remote attacker within a container/VM connected to a OVN logical
                                                                                                                                                                  switch port of such a tunnel could craft BFD packets which would then get
                                                                                                                                                                  tunnelled to and processed by another node and then change the BFD state of
                                                                                                                                                                  the tunnel and hence affect future forwarding decisions - ie. could
                                                                                                                                                                  essentially cause a DoS to future traffic along the tunnel
                                                                                                                                                                  [USN-6692-1] Gson vulnerability (13:04)
                                                                                                                                                                  • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                    • CVE-2022-25647
                                                                                                                                                                    • Java library for JSON serialisation/deserialisation to/from Java objects
                                                                                                                                                                    • Only affected Java Serialisation - and then only if you were not careful when
                                                                                                                                                                    • deserialising to not include circular references between objects
                                                                                                                                                                      [USN-6693-1] .NET vulnerability (13:27)
                                                                                                                                                                      • 1 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                        • CVE-2024-21392
                                                                                                                                                                        • Patch Tuesday for dotnet7/8 - no real details from MS
                                                                                                                                                                        • [USN-6663-2] OpenSSL update (13:55)
                                                                                                                                                                          • Affecting Xenial ESM (16.04 ESM)
                                                                                                                                                                          • [USN-6663-1] OpenSSL update from Episode 220
                                                                                                                                                                          • Hardening update to return output instead of an exception when wrong padding
                                                                                                                                                                          • was used - removes a timing side-channel for inferring secret key
                                                                                                                                                                            Goings on in Ubuntu Security Community
                                                                                                                                                                            Ubuntu 23.10 to be a target in Pwn2Own Vancouver 2024 (14:26)
                                                                                                                                                                            • Part of CanSecWest in Vancouver March 20-22 2024
                                                                                                                                                                            • Ubuntu Desktop 23.10 target in Local Escalation of Privilege Category - must
                                                                                                                                                                            • leverage a kernel vuln to escalate privs
                                                                                                                                                                            • Unfortunately the userns restrictions are not enabled by default in 23.10
                                                                                                                                                                            • (Mantic) so will be interesting to see what kinds of vulns get turned up
                                                                                                                                                                            • Will report back on findings in later episodes
                                                                                                                                                                            • Check Point Research report on Magnet Goblin’s Linux Malware Variants (15:42)
                                                                                                                                                                              • https://research.checkpoint.com/2024/magnet-goblin-targets-publicly-facing-servers-using-1-day-vulnerabilities/
                                                                                                                                                                              • Check Point Research reported on recent attacks targeting Ivanti Connect
                                                                                                                                                                              • Secure VPN by a threat actor they call Magnet Goblin
                                                                                                                                                                                • Ivanti Connect Secure VPN CVEs were made public in January and have been exploited in the wild
                                                                                                                                                                                • CPR decided to investigate a cluster of attacks
                                                                                                                                                                                • In doing so cover the details of MGs Nerbian family of malware
                                                                                                                                                                                • Report from Eclypsium suggests running an old version of Linux
                                                                                                                                                                                  • CentOS 6.4; which was released in 2013 and officially end of life in 2020
                                                                                                                                                                                    • Linux kernel 2.6.32 (EOL Feb 2016)
                                                                                                                                                                                    • openssl 1.0.2n (EOL Dec 2017)
                                                                                                                                                                                    • Perl 5.6.1 (EOL April 2001)
                                                                                                                                                                                    • Clear then that the malware not only exploits Ivanti Connect but also Linux in general
                                                                                                                                                                                    • CPR report includes details on what TTPs to look for - IP addresses / domains etc
                                                                                                                                                                                    • Then details the NerbianRAT malware
                                                                                                                                                                                      • First disclosed in 2022 by ProofPoint when detailing the Windows variant
                                                                                                                                                                                      • Earliest sample of this Linux variant is in an upload to VT from May 2022
                                                                                                                                                                                      • But unlike the Windows variant, the Linux one does not include any
                                                                                                                                                                                      • hardening measures - even has DWARF debugging info present so can easily
                                                                                                                                                                                        decompile
                                                                                                                                                                                      • Only anti-debug/analysis trick is to check there are no other variants of
                                                                                                                                                                                      • itself running by trying to allocate a static shared memory segment - if
                                                                                                                                                                                        this succeeds then assumes it is not running and proceeds to:
                                                                                                                                                                                        • collect basic info like current time, $USER, machine name etc
                                                                                                                                                                                        • loads a public RSA key which is later used to encrypt network comms back to a hardcoded IP address used for C2
                                                                                                                                                                                        • then loads config which allows to configure things like when to start /
                                                                                                                                                                                        • end, other C2 hosts to use, time to sleep during file transfers and more
                                                                                                                                                                                        • for C2 uses raw TCP sockets and encrypts using the RSA key
                                                                                                                                                                                        • waits for magic string which contains the command to run from C2
                                                                                                                                                                                        • Also detail the MiniNerbian which is a simplified form for just command
                                                                                                                                                                                        • execution but which used HTTP and sends POST requests to a /dashboard/
                                                                                                                                                                                          endpoint - likely to try and hide its network traffic in plain-sight (rather
                                                                                                                                                                                          than the raw TCP sockets with custom encrypted protocol employed by
                                                                                                                                                                                          NerbianRAT)
                                                                                                                                                                                        • For initial access, details are less clear but appears to exploit vulns in
                                                                                                                                                                                        • Ivanti, Magento, Qlink Sense and possibly Apache ActiveMQ - dubbed 1-day
                                                                                                                                                                                          exploits
                                                                                                                                                                                        • What do we learn?
                                                                                                                                                                                          • Device makers who use OSS need to keep it up-to-date (or build on top of
                                                                                                                                                                                          • systems like Ubuntu Core which come with OTA etc OOTB)
                                                                                                                                                                                          • End-users of devices need to keep them up-to-date and deploy usual
                                                                                                                                                                                          • defence-in-depth practices (but this is hard when the device is intended to
                                                                                                                                                                                            be deployed on the edge of a network - hard to add additional DiD to a VPN
                                                                                                                                                                                            concentrator)
                                                                                                                                                                                            Get in contact
                                                                                                                                                                                            • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                            • ubuntu-hardened mailing list
                                                                                                                                                                                            • Security section on discourse.ubuntu.com
                                                                                                                                                                                            • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                            • 25 min
                                                                                                                                                                                            • Episode 221
                                                                                                                                                                                              Overview

                                                                                                                                                                                              Andrei is back to discuss recent academic research into malware within the

                                                                                                                                                                                              Python/PyPI ecosystem and whether it is possible to effectively combat it with
                                                                                                                                                                                              open source tooling, plus we cover security updates for Unbound, libuv, node.js,
                                                                                                                                                                                              the Linux kernel, libgit2 and more.

                                                                                                                                                                                              This week in Ubuntu Security Updates

                                                                                                                                                                                              56 unique CVEs addressed

                                                                                                                                                                                              [USN-6665-1] Unbound vulnerabilities (00:50)
                                                                                                                                                                                              • 2 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                • CVE-2023-50868
                                                                                                                                                                                                • CVE-2023-50387
                                                                                                                                                                                                • Another update for recent vulns discovered in DNSSEC standard - [USN-6633-1]
                                                                                                                                                                                                • Bind vulnerabilities from Episode 219 and [USN-6657-1] Dnsmasq
                                                                                                                                                                                                  vulnerabilities from Episode 220
                                                                                                                                                                                                  [USN-6666-1] libuv vulnerability (01:16)
                                                                                                                                                                                                  • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                    • CVE-2024-24806
                                                                                                                                                                                                    • Async event handling library - used by nodejs and others - supports async
                                                                                                                                                                                                    • handling TCP/UDP sockets, DNS resolution, file system operations etc
                                                                                                                                                                                                    • Would truncate hostnames to 256 characters before calling getaddrinfo() - but
                                                                                                                                                                                                    • would then fail to NUL-terminate the string - as such, getaddrinfo() would
                                                                                                                                                                                                      read past the end of the buffer and the address that got resolved may not be
                                                                                                                                                                                                      the intended one - so then a remote attacker who could influence this could
                                                                                                                                                                                                      end up causing the application to contact a different address than expected
                                                                                                                                                                                                      and so perhaps access internal services etc
                                                                                                                                                                                                      [USN-6667-1] Cpanel-JSON-XS vulnerability (02:21)
                                                                                                                                                                                                      • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                        • CVE-2022-48623
                                                                                                                                                                                                        • Perl module for JSON serialisation
                                                                                                                                                                                                        • OOB read on crafted JSON - when parsing in relaxed mode, if JSON was malformed
                                                                                                                                                                                                        • and missing a colon would read beyond the end of the data and so potentially
                                                                                                                                                                                                          could result in an info-leak or a crash
                                                                                                                                                                                                          [USN-6668-1] python-openstackclient vulnerability (02:55)
                                                                                                                                                                                                          • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                            • CVE-2023-6110
                                                                                                                                                                                                            • When deleting an access rule, would search for it by name - if it didn’t exist
                                                                                                                                                                                                            • may end up returning a different rule which would then get deleted instead -
                                                                                                                                                                                                              changes the semantics to only allow rules to be deleted via their ID which is
                                                                                                                                                                                                              unique
                                                                                                                                                                                                              [USN-6648-2] Linux kernel (Azure) vulnerabilities (03:23)
                                                                                                                                                                                                              • 4 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                • CVE-2024-0646
                                                                                                                                                                                                                • CVE-2024-0565
                                                                                                                                                                                                                • CVE-2023-6915
                                                                                                                                                                                                                • CVE-2023-51781
                                                                                                                                                                                                                • [USN-6648-1] Linux kernel vulnerabilities from Episode 220
                                                                                                                                                                                                                • OOB write in KTLS
                                                                                                                                                                                                                • UAF in AppleTalk network driver
                                                                                                                                                                                                                • [USN-6651-2, USN-6651-3] Linux kernel (including StarFive) vulnerabilities (03:52)
                                                                                                                                                                                                                  • 6 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                    • CVE-2024-0646
                                                                                                                                                                                                                    • CVE-2024-0582
                                                                                                                                                                                                                    • CVE-2024-0565
                                                                                                                                                                                                                    • CVE-2023-6915
                                                                                                                                                                                                                    • CVE-2023-51781
                                                                                                                                                                                                                    • CVE-2023-51780
                                                                                                                                                                                                                    • [USN-6653-2, USN-6653-3, USN-6653-4] Linux kernel (AWS, Low Latency & GKE) vulnerabilities (04:07)
                                                                                                                                                                                                                      • 5 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                        • CVE-2024-0646
                                                                                                                                                                                                                        • CVE-2024-0565
                                                                                                                                                                                                                        • CVE-2023-6915
                                                                                                                                                                                                                        • CVE-2023-51781
                                                                                                                                                                                                                        • CVE-2023-51780
                                                                                                                                                                                                                        • [USN-6647-2] Linux kernel (Azure) vulnerabilities (04:15)
                                                                                                                                                                                                                          • 3 CVEs addressed in Trusty ESM (14.04 ESM)
                                                                                                                                                                                                                            • CVE-2023-7192
                                                                                                                                                                                                                            • CVE-2023-51782
                                                                                                                                                                                                                            • CVE-2023-51780
                                                                                                                                                                                                                            • [USN-6647-1] Linux kernel vulnerabilities from Episode 220
                                                                                                                                                                                                                            • Memory leak in netfilter able to be abused via an unprivileged user
                                                                                                                                                                                                                            • namespace - DoS via exhausting system memory
                                                                                                                                                                                                                              [USN-6670-1] php-guzzlehttp-psr7 vulnerabilities (04:36)
                                                                                                                                                                                                                              • 2 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                • CVE-2023-29197
                                                                                                                                                                                                                                • CVE-2022-24775
                                                                                                                                                                                                                                • HTTP message library conforming the the PSR-7 specification - failed to
                                                                                                                                                                                                                                • properly account for embedded newlines in HTTP headers - classic HTTP
                                                                                                                                                                                                                                  smuggling attack vuln
                                                                                                                                                                                                                                • Original fix from 2022 was found to be incomplete so additional CVE assigned
                                                                                                                                                                                                                                • for the follow-up fix
                                                                                                                                                                                                                                  [USN-6671-1] php-nyholm-psr7 vulnerability (05:15)
                                                                                                                                                                                                                                  • 1 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                    • CVE-2023-29197
                                                                                                                                                                                                                                    • Alternative PSR-7 implementation which also suffered from the same issue
                                                                                                                                                                                                                                    • [USN-6669-1] Thunderbird vulnerabilities (05:35)
                                                                                                                                                                                                                                      • 17 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                        • CVE-2024-1552
                                                                                                                                                                                                                                        • CVE-2024-1551
                                                                                                                                                                                                                                        • CVE-2024-1546
                                                                                                                                                                                                                                        • CVE-2024-0746
                                                                                                                                                                                                                                        • CVE-2024-1553
                                                                                                                                                                                                                                        • CVE-2024-1550
                                                                                                                                                                                                                                        • CVE-2024-1549
                                                                                                                                                                                                                                        • CVE-2024-1548
                                                                                                                                                                                                                                        • CVE-2024-1547
                                                                                                                                                                                                                                        • CVE-2024-0755
                                                                                                                                                                                                                                        • CVE-2024-0753
                                                                                                                                                                                                                                        • CVE-2024-0751
                                                                                                                                                                                                                                        • CVE-2024-0750
                                                                                                                                                                                                                                        • CVE-2024-0749
                                                                                                                                                                                                                                        • CVE-2024-0747
                                                                                                                                                                                                                                        • CVE-2024-0742
                                                                                                                                                                                                                                        • CVE-2024-0741
                                                                                                                                                                                                                                        • 115.8.1
                                                                                                                                                                                                                                        • [USN-6672-1] Node.js vulnerabilities (06:03)
                                                                                                                                                                                                                                          • 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                            • CVE-2023-2650
                                                                                                                                                                                                                                            • CVE-2023-23920
                                                                                                                                                                                                                                            • CVE-2023-23919
                                                                                                                                                                                                                                            • Leverages OpenSSL for cryptographic related work - failed to clear the OpenSSL
                                                                                                                                                                                                                                            • error stack in when calling various routines - as such, may get false-positive
                                                                                                                                                                                                                                              errors on subsequent calls to OpenSSL from the same thread and hence DoS - so
                                                                                                                                                                                                                                              a remote attacker could provide an invalid cert which would then set this
                                                                                                                                                                                                                                              error and subsequent routines to validate certs would also appear to fail even
                                                                                                                                                                                                                                              if they were valid
                                                                                                                                                                                                                                            • Uses ICU for unicode handling - allows a user to specify their own ICU data
                                                                                                                                                                                                                                            • via an environment variable - but node.js can run in different privilege
                                                                                                                                                                                                                                              contexts so a user could then force it to load data under their control when
                                                                                                                                                                                                                                              running with elevated privileges
                                                                                                                                                                                                                                            • ASN.1 encoding issue inherited from OpenSSL
                                                                                                                                                                                                                                            • [USN-6673-1] python-cryptography vulnerabilities (07:30)
                                                                                                                                                                                                                                              • 2 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                • CVE-2024-26130
                                                                                                                                                                                                                                                • CVE-2023-50782
                                                                                                                                                                                                                                                • Another issue of mishandling the OpenSSL API - in this case would not properly
                                                                                                                                                                                                                                                • handle errors returned from OpenSSL when processing certificates that had
                                                                                                                                                                                                                                                  incorrect padding (talked about this last week in [USN-6663-1] OpenSSL update)
                                                                                                                                                                                                                                                • Mishandled error case when a PKCS+12 key and certificate did not match
                                                                                                                                                                                                                                                • one-another - would trigger an exception at runtime
                                                                                                                                                                                                                                                  [USN-6674-1, USN-6674-2] Django vulnerability (08:22)
                                                                                                                                                                                                                                                  • 1 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                    • CVE-2024-27351
                                                                                                                                                                                                                                                    • ReDoS in Truncator template filter - if supplied an input string of all
                                                                                                                                                                                                                                                    • opening angle brackets <<<<<<.... then would cause exponential performance
                                                                                                                                                                                                                                                      degredation
                                                                                                                                                                                                                                                      [USN-6675-1] ImageProcessing vulnerability (08:52)
                                                                                                                                                                                                                                                      • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                        • CVE-2022-24720
                                                                                                                                                                                                                                                        • Image processing library for ruby based on ImageMagick
                                                                                                                                                                                                                                                        • If an application allowed the user to specify the set of operations to be
                                                                                                                                                                                                                                                        • performed, could then be abused to get arbitrary shell command execution -
                                                                                                                                                                                                                                                          internally used send() rather than public_send() which allowed access to
                                                                                                                                                                                                                                                          private methods to directly execute system calls
                                                                                                                                                                                                                                                          [USN-6677-1] libde265 vulnerabilities (09:23)
                                                                                                                                                                                                                                                          • 7 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                            • CVE-2023-49468
                                                                                                                                                                                                                                                            • CVE-2023-49467
                                                                                                                                                                                                                                                            • CVE-2023-49465
                                                                                                                                                                                                                                                            • CVE-2023-47471
                                                                                                                                                                                                                                                            • CVE-2023-43887
                                                                                                                                                                                                                                                            • CVE-2023-27103
                                                                                                                                                                                                                                                            • CVE-2023-27102
                                                                                                                                                                                                                                                            • Next lot of libde265 vulns after discussed previously in both
                                                                                                                                                                                                                                                            • [USN-6659-1] libde265 vulnerabilities from
                                                                                                                                                                                                                                                              Episode 221 and
                                                                                                                                                                                                                                                              [USN-6627-1] libde265 vulnerabilities from
                                                                                                                                                                                                                                                              Episode 219 - more fuzzing related fixes for usual sorts of issues - this
                                                                                                                                                                                                                                                              time includes a couple from our own David (aka @litios)
                                                                                                                                                                                                                                                              [USN-6678-1] libgit2 vulnerabilities (09:50)
                                                                                                                                                                                                                                                              • 5 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                • CVE-2024-24577
                                                                                                                                                                                                                                                                • CVE-2024-24575
                                                                                                                                                                                                                                                                • CVE-2023-22742
                                                                                                                                                                                                                                                                • CVE-2020-12279
                                                                                                                                                                                                                                                                • CVE-2020-12278
                                                                                                                                                                                                                                                                • Used by various tools like cargo, gnome-builder etc
                                                                                                                                                                                                                                                                • Fix for a possible infinite loop (CPU-based DoS) when parsing a crafted
                                                                                                                                                                                                                                                                • revision named simply @
                                                                                                                                                                                                                                                                • Use-after free when handling crafted input to git_index_add
                                                                                                                                                                                                                                                                • Mishandles equivalent filenames due to NTFS Data Streams (similar to
                                                                                                                                                                                                                                                                • CVE-2019-1352 - [USN-4220-1] Git vulnerabilities from Episode 56)
                                                                                                                                                                                                                                                                • Failed to perform certificate checking when using an SSH remote via the
                                                                                                                                                                                                                                                                • optional libssh2 backend - which we do in Ubuntu
                                                                                                                                                                                                                                                                  [USN-6649-2] Firefox regressions (10:47)
                                                                                                                                                                                                                                                                  • 12 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                    • CVE-2024-1556
                                                                                                                                                                                                                                                                    • CVE-2024-1552
                                                                                                                                                                                                                                                                    • CVE-2024-1551
                                                                                                                                                                                                                                                                    • CVE-2024-1546
                                                                                                                                                                                                                                                                    • CVE-2024-1557
                                                                                                                                                                                                                                                                    • CVE-2024-1555
                                                                                                                                                                                                                                                                    • CVE-2024-1554
                                                                                                                                                                                                                                                                    • CVE-2024-1553
                                                                                                                                                                                                                                                                    • CVE-2024-1550
                                                                                                                                                                                                                                                                    • CVE-2024-1549
                                                                                                                                                                                                                                                                    • CVE-2024-1548
                                                                                                                                                                                                                                                                    • CVE-2024-1547
                                                                                                                                                                                                                                                                    • 123.0.1
                                                                                                                                                                                                                                                                    • [USN-6676-1] c-ares vulnerability (10:55)
                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                        • CVE-2024-25629
                                                                                                                                                                                                                                                                        • async DNS lookup library
                                                                                                                                                                                                                                                                        • Failed to properly handle embedded NUL characters when parsing
                                                                                                                                                                                                                                                                        • /erc/resolv.conf /etc/hosts, /etc/nsswitch.conf or anything specifed via the
                                                                                                                                                                                                                                                                          HOSTALIASES environment variable - if has an embedded NUL as the first
                                                                                                                                                                                                                                                                          character in a new line, would then attempt to read memory prior to the start
                                                                                                                                                                                                                                                                          of the buffer and hence an OOB read -> crash
                                                                                                                                                                                                                                                                          Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                          Andrei discusses malware detection with the Python and PyPi ecosystem (11:46)
                                                                                                                                                                                                                                                                          • Bad Snakes: Understanding and Improving Python Package Index Malware Scanning
                                                                                                                                                                                                                                                                          • Hey, Alex!

                                                                                                                                                                                                                                                                            We will continue our journey today beyond the scope of the previous episodes. We’ve delved into the realms of network security, federated infrastructures, and vulnerability detection and assessment.

                                                                                                                                                                                                                                                                            Today’s paper

                                                                                                                                                                                                                                                                            Last year, the Ubuntu Security Team participated in the Linux Security Summit in Bilbao. At that time, I managed to have a discussion with Zach, who hosted a presentation at the Supply Chain Security Con entitled “Will Large-Scale Automated Scanning Stop Malware on OSS Repositories?”. I later discovered that his talk was backed by a paper that he and his colleagues from Chainguard had published.

                                                                                                                                                                                                                                                                            With this in mind, today we will be examining “Bad Snakes: Understanding and Improving Python Package Index Malware Scanning”, which was published last year in ACM’s International Conference on Software Engineering.

                                                                                                                                                                                                                                                                            The aim of the paper is to highlight the current state of the Python and PyPi ecosystems from a malware detection standpoint, identify the requirements for a mature malware scanner that can be integrated into PyPi, and ascertain whether the existing open-source tools meet these objectives.

                                                                                                                                                                                                                                                                            Repositories. PyPi

                                                                                                                                                                                                                                                                            With this in mind, let’s start by understanding the context.

                                                                                                                                                                                                                                                                            Applications can be distributed through repositories. This means that the applications are packaged into a generic format and published in either managed or unmanaged repositories. Users can then install the application by querying the repositories, downloading the application in a format that they can unpack through a client, and subsequently run on their hosts.

                                                                                                                                                                                                                                                                            There are numerous repositories out there. Some target specific operating systems, as is the case with Debian repositories, the Snap Store, Google Play, or the Microsoft Store. Others are designed to store packages for a specific programming language, such as PyPi, npm, and RubyGems. Firefox Add-ons and the Chrome extension store target a specific platform, namely the browser.

                                                                                                                                                                                                                                                                            Another relevant characteristic when discussing repositories is the level of curation. The Ubuntu Archive is considered a curated repository of software packages because there are several trustworthy contributors able to publish software within the repository. Conversely, npm is unmanaged because any member of the open-source community can publish anything in it.

                                                                                                                                                                                                                                                                            We will discuss the Python Package Index extensively, which is the de facto unmanaged repository for the Python programming language. As of the 7th of March 2024, there were 5.4 million releases for 520 thousand projects and nearly 800 thousand users. It is governed by a non-profit organisation and run by volunteers worldwide.

                                                                                                                                                                                                                                                                            Supply chain attacks

                                                                                                                                                                                                                                                                            Software repositories foster the dependencies of software on other pieces of software, controlled by different parties. As seen in campaigns such as the SolarWinds SUNBURST attack, this can go awry. Attackers can gain control over software in a company’s supply chain, gain initial access to their infrastructure, and exploit this advantage.

                                                                                                                                                                                                                                                                            Multiple attack vectors are possible. Accounts can be hijacked. Attackers may publish packages with similar names (in a tactic known as typosquatting). They can also leverage shrink-wrapped clones, which are duplicates of existing packages, where malicious code is injected after gaining users’ trust. While covering all attack vectors is beyond the scope of this podcast episode, you can find a comprehensive taxonomy in a paper called “Taxonomy of Attacks on Open-Source Software Supply Chains”, which lists over 100 unique attack vectors.

                                                                                                                                                                                                                                                                            From 2017 to 2022, the number of unique projects removed from PyPi increased rapidly: 38 in the first year, followed by 130, 60, 500, 27 thousands, and finally 12 thousands in the last year. Despite the fact that most of these were reported as malware, it’s worth noting that the impact of some of them is limited due to the lack of organic usage.

                                                                                                                                                                                                                                                                            Malware analysis

                                                                                                                                                                                                                                                                            These attacks can be mitigated by implementing techniques such as multi-factor authentication, software signing, update frameworks, or reproducible builds, but the most widespread method is malware analysis.

                                                                                                                                                                                                                                                                            Some engines check for anomalies via static and dynamic heuristics, while others rely on signatures due to their simplicity. Once a piece of software is detected as malicious, its hash is added to a deny list that is embedded in the anti-malware engine. Each file is then hashed and the result is checked against the deny list. If the heuristics or the hash comparison identifies the file as malicious, it is either reported, blocked, or deleted depending on the strategy implemented by the anti-malware engine.

                                                                                                                                                                                                                                                                            Malware analysis in PyPi

                                                                                                                                                                                                                                                                            These solutions are already implemented in software repositories. In the case of PyPi, malware scanning was introduced in February 2022 with the assistance of a malware check feature in Warehouse, the application serving PyPi. However, it was disabled by the administrators two years later and ultimately removed in May 2023 due to an overload of alerts.

                                                                                                                                                                                                                                                                            In addition to this technical solution, PyPi also capitalises on a form of social symbiosis. Software security companies and individuals conduct security research, reporting any discovered malware to the PyPi administrators via email. The administrators typically allocate 20 minutes per week to review these malware reports and remove any packages that can be verified as true positives. Ultimately, the reporting companies and individuals gain reputation or attention for their brands, products, and services.

                                                                                                                                                                                                                                                                            Requirements

                                                                                                                                                                                                                                                                            In addition to information about software repositories, supply chain attacks, malware analysis, and PyPi, the researchers also interviewed administrators from PyPi to understand their requirements for a malware analysis tool that could assist them. The three interviews, each lasting one hour, were conducted in July and August 2022 and involved only three individuals. This limited number of interviews is due to the focus on the PyPi ecosystem, where only ten people are directly involved in malware scanning activities.

                                                                                                                                                                                                                                                                            When discussing requirements, the administrators desired tools with a binary outcome, which could be determined by checking if a numerical score exceeds a threshold or not. The decision should also be supported by arguments. While administrators can tolerate false negatives, they aim to reduce the rate of false positives to zero. The tool should also operate on limited resources and be easy to adopt, use and maintain.

                                                                                                                                                                                                                                                                            Current tooling

                                                                                                                                                                                                                                                                            But do the current solutions tick these boxes?

                                                                                                                                                                                                                                                                            The researchers selected tools based on a set of criteria: analysing the code of the packages, having public detection techniques, and detection rules. Upon examining the available solutions, they found that only three could be used for evaluation in the context of their research: PyPi’s malware checks, Bandit4Mal, and OSSGadget’s OSS Detect Backdoor.

                                                                                                                                                                                                                                                                            Regarding the former, it should be noted that the researchers did not match the YARA rules only against the setup files, but also against all files in the Python package. The second, Bandit4Mal, is an open-source version of Bandit that has been adapted to include multiple rules for detecting malicious patterns in the AST generated from a program’s codebase. The last, OSSGadget’s OSS Detect Backdoor, is a tool developed by Microsoft in June 2020 to perform rule-based malware detection on each file in a package.

                                                                                                                                                                                                                                                                            These tools were tested against both malicious and benign Python packages. The researchers used two datasets containing 168 manually-selected malicious packages. For the benign packages, they selected 1,400 popular packages and one thousand randomly-selected benign Python packages.

                                                                                                                                                                                                                                                                            For the evaluation process, they considered an alert in a malicious package to be a true positive and an alert in a benign package to be a false positive.

                                                                                                                                                                                                                                                                            The true positive rate was 85% for the PyPi checks, the same for OSS Detect Backdoor and 90% for Bandit4Mal. The false positive rates ranged from 15% for the PyPi checks over the random packages, to 80% for Bandit4Mal on popular packages.

                                                                                                                                                                                                                                                                            The tools ran in a time-effective manner, with a median time of around two seconds per package across all datasets. The maximum runtime was recorded for Ansible’s package, which was scanned in 26 minutes.

                                                                                                                                                                                                                                                                            Despite their efficient run times, we can infer from these results that the tools are not accurate enough to meet the demands of PyPi’s administrators. The analysts may be overwhelmed by alerts for benign packages, which could interfere with their other operations.

                                                                                                                                                                                                                                                                            Conclusions

                                                                                                                                                                                                                                                                            And with this, we can conclude the episode of the Ubuntu Security Podcast, which details the paper “Bad Snakes: Understanding and Improving Python Package Index Malware Scanning”. We have discussed software repositories, malware analysis, and malware-related operations within PyPi. We’ve also explored the requirements that would make a new open-source Python malware scanner suitable for the PyPi administrators and evaluated how the current solutions perform.

                                                                                                                                                                                                                                                                            If you come across any interesting topics that you believe should be discussed, please email us at [email protected].

                                                                                                                                                                                                                                                                            Over to you, Alex!

                                                                                                                                                                                                                                                                            Resources
                                                                                                                                                                                                                                                                            • Bad Snakes: Understanding and Improving Python Package Index Malware Scanning
                                                                                                                                                                                                                                                                            • Taxonomy of Attacks on Open-Source Software Supply Chains
                                                                                                                                                                                                                                                                            • Bandit4Mal
                                                                                                                                                                                                                                                                            • OSS Detect Backdoor
                                                                                                                                                                                                                                                                            • PyPi’s malware checks
                                                                                                                                                                                                                                                                            • Get in contact
                                                                                                                                                                                                                                                                              • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                              • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                              • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                              • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                              • 24 min
                                                                                                                                                                                                                                                                              • Episode 220
                                                                                                                                                                                                                                                                                Overview

                                                                                                                                                                                                                                                                                The Linux kernel.org CNA has assigned their first CVEs so we revisit this topic

                                                                                                                                                                                                                                                                                to assess the initial impact on Ubuntu and the CVE ecosystem, plus we cover
                                                                                                                                                                                                                                                                                security updates for Roundcube Webmail, less, GNU binutils and the Linux kernel
                                                                                                                                                                                                                                                                                itself.

                                                                                                                                                                                                                                                                                This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                64 unique CVEs addressed

                                                                                                                                                                                                                                                                                [USN-6647-1] Linux kernel vulnerabilities (01:14)
                                                                                                                                                                                                                                                                                • 3 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                  • CVE-2023-7192
                                                                                                                                                                                                                                                                                  • CVE-2023-51782
                                                                                                                                                                                                                                                                                  • CVE-2023-51780
                                                                                                                                                                                                                                                                                  • 4.15 - AWS/Azure/GCP/HWE/KVM/Oracle
                                                                                                                                                                                                                                                                                  • Memory leak in netfilter able to be abused via an unprivileged user
                                                                                                                                                                                                                                                                                  • namespace - DoS via exhausting system memory
                                                                                                                                                                                                                                                                                    [USN-6648-1] Linux kernel vulnerabilities (02:00)
                                                                                                                                                                                                                                                                                    • 4 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                      • CVE-2024-0646
                                                                                                                                                                                                                                                                                      • CVE-2024-0565
                                                                                                                                                                                                                                                                                      • CVE-2023-6915
                                                                                                                                                                                                                                                                                      • CVE-2023-51781
                                                                                                                                                                                                                                                                                      • 5.4 - IOT/Xilinx ZynqMP/IBM/Bluefield/GKEOP/Raspi/KVM/Oracle/AWS/GCP/Generic/LowLatency/OEM
                                                                                                                                                                                                                                                                                      • OOB write in KTLS reported by Jann Horn - if a user can get the kernel to
                                                                                                                                                                                                                                                                                      • splice a ktls socket can possibly escalate privileges
                                                                                                                                                                                                                                                                                      • UAF in AppleTalk network driver - could be abused by a local unprivileged
                                                                                                                                                                                                                                                                                      • user - can be mitigated by blocklisting in /etc/modprobe.d/blacklist-rare-network.conf
                                                                                                                                                                                                                                                                                        # appletalk
                                                                                                                                                                                                                                                                                        alias net-pf-5 off
                                                                                                                                                                                                                                                                                        [USN-6650-1] Linux kernel (OEM) vulnerability (03:30)
                                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                          • CVE-2023-6915
                                                                                                                                                                                                                                                                                          • NULL ptr deref in generic ID allocator
                                                                                                                                                                                                                                                                                          • [USN-6651-1] Linux kernel vulnerabilities (03:38)
                                                                                                                                                                                                                                                                                            • 6 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                              • CVE-2024-0646
                                                                                                                                                                                                                                                                                              • CVE-2024-0582
                                                                                                                                                                                                                                                                                              • CVE-2024-0565
                                                                                                                                                                                                                                                                                              • CVE-2023-6915
                                                                                                                                                                                                                                                                                              • CVE-2023-51781
                                                                                                                                                                                                                                                                                              • CVE-2023-51780
                                                                                                                                                                                                                                                                                              • ktls + appletalk
                                                                                                                                                                                                                                                                                              • [USN-6653-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                • 5 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                  • CVE-2024-0646
                                                                                                                                                                                                                                                                                                  • CVE-2024-0565
                                                                                                                                                                                                                                                                                                  • CVE-2023-6915
                                                                                                                                                                                                                                                                                                  • CVE-2023-51781
                                                                                                                                                                                                                                                                                                  • CVE-2023-51780
                                                                                                                                                                                                                                                                                                  • ktls + appletalk
                                                                                                                                                                                                                                                                                                  • [USN-6652-1] Linux kernel (Azure) vulnerabilities (03:47)
                                                                                                                                                                                                                                                                                                    • 15 CVEs addressed in Mantic (23.10)
                                                                                                                                                                                                                                                                                                      • CVE-2024-0646
                                                                                                                                                                                                                                                                                                      • CVE-2024-0641
                                                                                                                                                                                                                                                                                                      • CVE-2024-0582
                                                                                                                                                                                                                                                                                                      • CVE-2024-0565
                                                                                                                                                                                                                                                                                                      • CVE-2023-6915
                                                                                                                                                                                                                                                                                                      • CVE-2023-6622
                                                                                                                                                                                                                                                                                                      • CVE-2023-6531
                                                                                                                                                                                                                                                                                                      • CVE-2023-6176
                                                                                                                                                                                                                                                                                                      • CVE-2023-5972
                                                                                                                                                                                                                                                                                                      • CVE-2023-51781
                                                                                                                                                                                                                                                                                                      • CVE-2023-51780
                                                                                                                                                                                                                                                                                                      • CVE-2023-46862
                                                                                                                                                                                                                                                                                                      • CVE-2023-46813
                                                                                                                                                                                                                                                                                                      • CVE-2023-35827
                                                                                                                                                                                                                                                                                                      • CVE-2023-34324
                                                                                                                                                                                                                                                                                                      • ktls + appletalk + NULL ptr deref in TLS impl ([LSN-0100-1] Linux kernel vulnerability from Episode 219)
                                                                                                                                                                                                                                                                                                      • [USN-6649-1] Firefox vulnerabilities (04:14)
                                                                                                                                                                                                                                                                                                        • 12 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                          • CVE-2024-1556
                                                                                                                                                                                                                                                                                                          • CVE-2024-1552
                                                                                                                                                                                                                                                                                                          • CVE-2024-1551
                                                                                                                                                                                                                                                                                                          • CVE-2024-1546
                                                                                                                                                                                                                                                                                                          • CVE-2024-1557
                                                                                                                                                                                                                                                                                                          • CVE-2024-1555
                                                                                                                                                                                                                                                                                                          • CVE-2024-1554
                                                                                                                                                                                                                                                                                                          • CVE-2024-1553
                                                                                                                                                                                                                                                                                                          • CVE-2024-1550
                                                                                                                                                                                                                                                                                                          • CVE-2024-1549
                                                                                                                                                                                                                                                                                                          • CVE-2024-1548
                                                                                                                                                                                                                                                                                                          • CVE-2024-1547
                                                                                                                                                                                                                                                                                                          • 123.0
                                                                                                                                                                                                                                                                                                          • [USN-6654-1] Roundcube Webmail vulnerability (04:35)
                                                                                                                                                                                                                                                                                                            • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                              • CVE-2023-43770
                                                                                                                                                                                                                                                                                                              • XSS able to abused by simple text/plain emails with crafted links - included
                                                                                                                                                                                                                                                                                                              • the ability to detect link references like [1] and linkify them to the
                                                                                                                                                                                                                                                                                                                source - if an attacker used a form like [] this would be
                                                                                                                                                                                                                                                                                                                included in the generated HTML without escaping and so could get arbitrary XSS
                                                                                                                                                                                                                                                                                                              • Since is in universe, this update is available via Ubuntu Pro
                                                                                                                                                                                                                                                                                                              • [USN-6655-1] GNU binutils vulnerabilities (05:54)
                                                                                                                                                                                                                                                                                                                • 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                  • CVE-2022-48065
                                                                                                                                                                                                                                                                                                                  • CVE-2022-48063
                                                                                                                                                                                                                                                                                                                  • CVE-2022-47695
                                                                                                                                                                                                                                                                                                                  • 3 instances of DoS via excessive memory consumption, one of NULL ptr deref -
                                                                                                                                                                                                                                                                                                                  • in general upstream does not consider binutils safe for analysing untrusted
                                                                                                                                                                                                                                                                                                                    inputs
                                                                                                                                                                                                                                                                                                                    [USN-6656-1] PostgreSQL vulnerability (06:31)
                                                                                                                                                                                                                                                                                                                    • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                      • CVE-2024-0985
                                                                                                                                                                                                                                                                                                                      • Failed to properly drop privileges when handling REFRESH MATERIALIZED VIEW CONCURRENTLY commands - should drop privileges so that the SQL is executed as
                                                                                                                                                                                                                                                                                                                      • the owner of the materialized view - as such, if an attacker could get a user
                                                                                                                                                                                                                                                                                                                        or automated system to run such a command they could possibly execute
                                                                                                                                                                                                                                                                                                                        arbitrary SQL as the user rather than as the owner of the view as expected
                                                                                                                                                                                                                                                                                                                        [USN-6657-1] Dnsmasq vulnerabilities (07:10)
                                                                                                                                                                                                                                                                                                                        • 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                          • CVE-2023-28450
                                                                                                                                                                                                                                                                                                                          • CVE-2023-50868
                                                                                                                                                                                                                                                                                                                          • CVE-2023-50387
                                                                                                                                                                                                                                                                                                                          • KeyTrap and NSEC3 proof related vuln in DNSSEC - [USN-6633-1] Bind
                                                                                                                                                                                                                                                                                                                          • vulnerabilities from Episode 219
                                                                                                                                                                                                                                                                                                                            [USN-6658-1] libxml2 vulnerability (07:33)
                                                                                                                                                                                                                                                                                                                            • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                              • CVE-2024-25062
                                                                                                                                                                                                                                                                                                                              • UAF if using DTD validation with XInclude expansion enabled
                                                                                                                                                                                                                                                                                                                              • [USN-6659-1] libde265 vulnerabilities (07:52)
                                                                                                                                                                                                                                                                                                                                • 13 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                  • CVE-2023-24758
                                                                                                                                                                                                                                                                                                                                  • CVE-2023-24757
                                                                                                                                                                                                                                                                                                                                  • CVE-2023-24756
                                                                                                                                                                                                                                                                                                                                  • CVE-2023-24755
                                                                                                                                                                                                                                                                                                                                  • CVE-2023-24754
                                                                                                                                                                                                                                                                                                                                  • CVE-2023-24752
                                                                                                                                                                                                                                                                                                                                  • CVE-2023-24751
                                                                                                                                                                                                                                                                                                                                  • CVE-2022-43245
                                                                                                                                                                                                                                                                                                                                  • CVE-2023-25221
                                                                                                                                                                                                                                                                                                                                  • CVE-2022-47665
                                                                                                                                                                                                                                                                                                                                  • CVE-2022-43250
                                                                                                                                                                                                                                                                                                                                  • CVE-2022-43249
                                                                                                                                                                                                                                                                                                                                  • CVE-2022-43244
                                                                                                                                                                                                                                                                                                                                  • Next lot of libde265 vulns after discussed previously in
                                                                                                                                                                                                                                                                                                                                  • [USN-6627-1] libde265 vulnerabilities from
                                                                                                                                                                                                                                                                                                                                    Episode 219 - more fuzzing related fixes for usual sorts of issues
                                                                                                                                                                                                                                                                                                                                    [USN-6660-1, USN-6661-1] OpenJDK 11 & 17 vulnerabilities (08:17)
                                                                                                                                                                                                                                                                                                                                    • 6 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                      • CVE-2024-20952
                                                                                                                                                                                                                                                                                                                                      • CVE-2024-20945
                                                                                                                                                                                                                                                                                                                                      • CVE-2024-20926
                                                                                                                                                                                                                                                                                                                                      • CVE-2024-20921
                                                                                                                                                                                                                                                                                                                                      • CVE-2024-20919
                                                                                                                                                                                                                                                                                                                                      • CVE-2024-20918
                                                                                                                                                                                                                                                                                                                                      • 11.0.22; 17.0.10
                                                                                                                                                                                                                                                                                                                                      • [USN-6662-1] OpenJDK 21 vulnerabilities
                                                                                                                                                                                                                                                                                                                                        • 5 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                          • CVE-2024-20952
                                                                                                                                                                                                                                                                                                                                          • CVE-2024-20945
                                                                                                                                                                                                                                                                                                                                          • CVE-2024-20921
                                                                                                                                                                                                                                                                                                                                          • CVE-2024-20919
                                                                                                                                                                                                                                                                                                                                          • CVE-2024-20918
                                                                                                                                                                                                                                                                                                                                          • 21.0.2
                                                                                                                                                                                                                                                                                                                                          • [USN-6305-2] PHP vulnerabilities (08:37)
                                                                                                                                                                                                                                                                                                                                            • 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                              • CVE-2023-3824
                                                                                                                                                                                                                                                                                                                                              • CVE-2023-3823
                                                                                                                                                                                                                                                                                                                                              • [USN-6663-1] OpenSSL update (08:40)
                                                                                                                                                                                                                                                                                                                                                • Affecting Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                • Hardening update for openssl 3.0 / 1.0 - OpenSSL 3.2.0 introduced a change to
                                                                                                                                                                                                                                                                                                                                                • return random output instead of an exception when it detected wrong padding
                                                                                                                                                                                                                                                                                                                                                  for PKCS#1 v1.5 encryption - without this there is a timing side-channel which
                                                                                                                                                                                                                                                                                                                                                  can be used to infer the secret key and hence break confidentiality
                                                                                                                                                                                                                                                                                                                                                  [USN-6664-1] less vulnerability (09:40)
                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                    • CVE-2022-48624
                                                                                                                                                                                                                                                                                                                                                    • Failed to quote filenames when using LESSCLOSE - could then get arbitrary
                                                                                                                                                                                                                                                                                                                                                    • shell commands - env var that tells less to invoke a particular command as an
                                                                                                                                                                                                                                                                                                                                                      input post-processor (this is used in conjunction with LESSOPEN to
                                                                                                                                                                                                                                                                                                                                                      pre-processor the file before it is displayed by less - for instance, if you
                                                                                                                                                                                                                                                                                                                                                      wanted to use less to page through a HTML file you might perhaps use this to
                                                                                                                                                                                                                                                                                                                                                      run it via html2text first - then use LESSCLOSE to do any cleanup)
                                                                                                                                                                                                                                                                                                                                                      [USN-6644-2] LibTIFF vulnerabilities (10:51)
                                                                                                                                                                                                                                                                                                                                                      • 3 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6277
                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6228
                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-52356
                                                                                                                                                                                                                                                                                                                                                        • Heap buffer overflow in libtiff itself, plus a heap buffer overflow in the
                                                                                                                                                                                                                                                                                                                                                        • tiffcp tool (used to combine multiple TIFF files into a single one) and
                                                                                                                                                                                                                                                                                                                                                          finally a possible OOM issue in libtiff if an input file specified a very
                                                                                                                                                                                                                                                                                                                                                          large size but then failed to actually contain such data (ie the headers
                                                                                                                                                                                                                                                                                                                                                          specify a certain size but the file itself doesn’t contain that amount of
                                                                                                                                                                                                                                                                                                                                                          data)
                                                                                                                                                                                                                                                                                                                                                          Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                          Follow up to Linux kernel CNA (11:40)
                                                                                                                                                                                                                                                                                                                                                          • Since announcing kernel.org has now started assigning CVEs
                                                                                                                                                                                                                                                                                                                                                          • First CVE assigned
                                                                                                                                                                                                                                                                                                                                                            • https://lore.kernel.org/linux-cve-announce/2024022058-outsell-equator-e1c5@gregkh/T/#u
                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-52433: netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction
                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-52433
                                                                                                                                                                                                                                                                                                                                                            • Assigned on 2024-02-20 12:53 UTC
                                                                                                                                                                                                                                                                                                                                                            • Both historical and recent
                                                                                                                                                                                                                                                                                                                                                              • 40 from 2024
                                                                                                                                                                                                                                                                                                                                                              • 66 from 2023
                                                                                                                                                                                                                                                                                                                                                              • 1 from 2022
                                                                                                                                                                                                                                                                                                                                                              • 165 from 2021
                                                                                                                                                                                                                                                                                                                                                              • 13 from 2020
                                                                                                                                                                                                                                                                                                                                                              • 3 from 2019
                                                                                                                                                                                                                                                                                                                                                              • As of Fri 01 Mar 2024 04:04:26 UTC have assigned 288 CVEs
                                                                                                                                                                                                                                                                                                                                                                • 9 days, 15 hours and 11 minutes or so
                                                                                                                                                                                                                                                                                                                                                                • 231 hours
                                                                                                                                                                                                                                                                                                                                                                • Currently assigning more than 1 CVE per hour
                                                                                                                                                                                                                                                                                                                                                                • Looking at these, 8 appear to be due to reported issues from Coverity -
                                                                                                                                                                                                                                                                                                                                                                • popular static analysis tool which is not infallible. Others appear to come
                                                                                                                                                                                                                                                                                                                                                                  directly from the GSD project (Global Security Database)
                                                                                                                                                                                                                                                                                                                                                                  • e.g. CVE-2019-25160
                                                                                                                                                                                                                                                                                                                                                                  • (https://lore.kernel.org/linux-cve-announce/2024022657-CVE-2019-25160-e487@gregkh/T/#u)
                                                                                                                                                                                                                                                                                                                                                                    is the same as GSD-2022-1001715
                                                                                                                                                                                                                                                                                                                                                                  • As I mentioned in Episode 219, GSD has over 13573 Linux kernel issues
                                                                                                                                                                                                                                                                                                                                                                  • Whilst I also said that I hoped that the kernel CNA wouldn’t be so much of a
                                                                                                                                                                                                                                                                                                                                                                  • firehose, currently it seems to be quite significant
                                                                                                                                                                                                                                                                                                                                                                  • On a personal note - I have been doing the CVE Triage role on our team this
                                                                                                                                                                                                                                                                                                                                                                  • week - in past weeks, I would normally spend about 30-minutes to 1 hour each
                                                                                                                                                                                                                                                                                                                                                                    day doing this - and this week it has been at least 2 hours each day, mostly
                                                                                                                                                                                                                                                                                                                                                                    due to the large influx of kernel CVEs
                                                                                                                                                                                                                                                                                                                                                                  • Perhaps the only way to solve this is better tooling - on our side, mdeslaur
                                                                                                                                                                                                                                                                                                                                                                  • added support for automatically extracting the required git commits from the
                                                                                                                                                                                                                                                                                                                                                                    CVE notifications and the kernel team already has tooling which checks if the
                                                                                                                                                                                                                                                                                                                                                                    required commits are in the git trees of the various Ubuntu kernels
                                                                                                                                                                                                                                                                                                                                                                  • Hopefully that helps - but it doesn’t help to assign priorities to each CVE
                                                                                                                                                                                                                                                                                                                                                                  • The kernel CNA is not assigning CVSS scores and they don’t intend to -
                                                                                                                                                                                                                                                                                                                                                                  • although my understanding is this is required - and so we can’t use this to help
                                                                                                                                                                                                                                                                                                                                                                  • So then we need to try and manually assess the impact of each CVE - but even
                                                                                                                                                                                                                                                                                                                                                                  • the kernel CNA says this is not obvious - so then perhaps the solution is to
                                                                                                                                                                                                                                                                                                                                                                    just assign them all to medium and deal with them as part of the usual kernel
                                                                                                                                                                                                                                                                                                                                                                    SRU cycle
                                                                                                                                                                                                                                                                                                                                                                    Get in contact
                                                                                                                                                                                                                                                                                                                                                                    • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                    • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                    • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                    • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                    • 19 min
                                                                                                                                                                                                                                                                                                                                                                    • Episode 219
                                                                                                                                                                                                                                                                                                                                                                      Overview

                                                                                                                                                                                                                                                                                                                                                                      This week the Linux kernel project announced they will be assigning their own

                                                                                                                                                                                                                                                                                                                                                                      CVEs so we discuss the possible implications and fallout from such a shift, plus
                                                                                                                                                                                                                                                                                                                                                                      we cover vulnerabilities in the kernel, Glance_store, WebKitGTK, Bind and more.

                                                                                                                                                                                                                                                                                                                                                                      This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                      64 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                      [LSN-0100-1] Linux kernel vulnerability (00:56)
                                                                                                                                                                                                                                                                                                                                                                      • 5 CVEs addressed in Jammy (22.04 LTS), Focal (20.04 LTS), Bionic ESM (18.04 ESM), Xenial ESM (16.04 ESM), Trusty ESM (14.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6932
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6817
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6176
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6040
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-5345
                                                                                                                                                                                                                                                                                                                                                                        • UAF in IGMP protocol ([USN-6601-1] Linux kernel vulnerability from Episode 217)
                                                                                                                                                                                                                                                                                                                                                                        • UAF in netfilter ([USN-6606-1] Linux kernel (OEM) vulnerabilities from Episode 217)
                                                                                                                                                                                                                                                                                                                                                                        • UAF in SMB client implementation - local crash / privesc ([USN-6607-1] Linux kernel (Azure) vulnerabilities from Episode 217)
                                                                                                                                                                                                                                                                                                                                                                        • NULL ptr deref in kernel TLS offload implementation - allows a userspace
                                                                                                                                                                                                                                                                                                                                                                        • application to request that the kernel do TLS by providing it the key etc -
                                                                                                                                                                                                                                                                                                                                                                          internally the kernel then takes the data to be sent from userspace and frames
                                                                                                                                                                                                                                                                                                                                                                          it into a scatter list (describes the regions in memory containing the data to
                                                                                                                                                                                                                                                                                                                                                                          be sent) - uses the kernel crypto API which is asynchronous
                                                                                                                                                                                                                                                                                                                                                                          • userspace can construct an invalid initial sequence number to trigger the
                                                                                                                                                                                                                                                                                                                                                                          • kernel to enter a code path where the network packet is freed before it has
                                                                                                                                                                                                                                                                                                                                                                            finished being processed by the crypto API -> UAF
                                                                                                                                                                                                                                                                                                                                                                            Kernel type
                                                                                                                                                                                                                                                                                                                                                                            22.04
                                                                                                                                                                                                                                                                                                                                                                            20.04
                                                                                                                                                                                                                                                                                                                                                                            18.04
                                                                                                                                                                                                                                                                                                                                                                            16.04
                                                                                                                                                                                                                                                                                                                                                                            14.04
                                                                                                                                                                                                                                                                                                                                                                            aws
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            aws-5.15
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            aws-5.4
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            aws-6.2
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            aws-hwe
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            azure
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            azure-4.15
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            azure-5.4
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            azure-6.2
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            gcp
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            gcp-4.15
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            gcp-5.15
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            gcp-5.4
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            gcp-6.2
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            generic-4.15
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            generic-4.4
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            generic-5.15
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            generic-5.4
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            gke
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            gke-5.15
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            gkeop
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            hwe-6.2
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            ibm
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            ibm-5.15
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            linux
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            lowlatency-4.15
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            lowlatency-4.4
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            lowlatency-5.15
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            lowlatency-5.4
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            100.1
                                                                                                                                                                                                                                                                                                                                                                            —
                                                                                                                                                                                                                                                                                                                                                                            —

                                                                                                                                                                                                                                                                                                                                                                            To check your kernel type and Livepatch version, enter this command:

                                                                                                                                                                                                                                                                                                                                                                            canonical-livepatch status
                                                                                                                                                                                                                                                                                                                                                                            [USN-6624-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                            • 9 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-0641
                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6622
                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6531
                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6176
                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-5972
                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-46862
                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-46813
                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-35827
                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-34324
                                                                                                                                                                                                                                                                                                                                                                              • [USN-6625-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                • 4 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-46343
                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-45863
                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-35827
                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-34324
                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6626-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                    • 10 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-0641
                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-6622
                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-6176
                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-6039
                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-46813
                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-35827
                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-34324
                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-32257
                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-32252
                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-32250
                                                                                                                                                                                                                                                                                                                                                                                      • [USN-6625-2] Linux kernel (GCP) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                        • 4 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-46343
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-45863
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-35827
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-34324
                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6628-1] Linux kernel (Intel IoTG) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                            • 16 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-0641
                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2024-0193
                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6932
                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6931
                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6817
                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6622
                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6606
                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6176
                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6040
                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6039
                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-46813
                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-35827
                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-34324
                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-32257
                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-32252
                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-32250
                                                                                                                                                                                                                                                                                                                                                                                              • [USN-6626-2] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                • 10 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-0641
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-6622
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-6176
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-6039
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-46813
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-35827
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-34324
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-32257
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-32252
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-32250
                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6608-2] Linux kernel (NVIDIA) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                    • 5 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-0193
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-6932
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-6931
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-6817
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-6606
                                                                                                                                                                                                                                                                                                                                                                                                      • [USN-6635-1] Linux kernel (GCP) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                        • 13 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-0193
                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-6932
                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-6931
                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-6817
                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-6606
                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-5717
                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-5178
                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-5158
                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-42754
                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-39193
                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-39192
                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-39189
                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-37453
                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6627-1] libde265 vulnerabilities (04:10)
                                                                                                                                                                                                                                                                                                                                                                                                            • 18 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-1253
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-43253
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-43252
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-43248
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-43243
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-43240
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-43239
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-43237
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-43236
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-43235
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2021-36410
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2021-36409
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2021-36408
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-43242
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-43241
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-43238
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2021-36411
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2021-35452
                                                                                                                                                                                                                                                                                                                                                                                                              • Open H.265 video codec implementation - used by gstreamer and hence Videos
                                                                                                                                                                                                                                                                                                                                                                                                              • (totem) in particular
                                                                                                                                                                                                                                                                                                                                                                                                              • Lots of the usual sorts of issues - a lot appear to have been found by a
                                                                                                                                                                                                                                                                                                                                                                                                              • couple different researchers fuzzing - assertion failure, NULL ptr derefs, OOB
                                                                                                                                                                                                                                                                                                                                                                                                                reads, UAF, OOB writes etc - impact then ranging from DoS to possible code
                                                                                                                                                                                                                                                                                                                                                                                                                execution
                                                                                                                                                                                                                                                                                                                                                                                                                [USN-6630-1] Glance_store vulnerability (05:26)
                                                                                                                                                                                                                                                                                                                                                                                                                • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-1141
                                                                                                                                                                                                                                                                                                                                                                                                                  • OpenStack Image Service store library - library for interacting with assets
                                                                                                                                                                                                                                                                                                                                                                                                                  • (images) via different storage technologies (local file-system, HTTP, RBD,
                                                                                                                                                                                                                                                                                                                                                                                                                    Swift, S3 and others)
                                                                                                                                                                                                                                                                                                                                                                                                                  • S3 backend would log the access_key if logging configured at DEBUG level - any
                                                                                                                                                                                                                                                                                                                                                                                                                  • user then able to read the logs could see the access key and hence potentially
                                                                                                                                                                                                                                                                                                                                                                                                                    get access to the S3 bucket (would also need the secret key too and this was
                                                                                                                                                                                                                                                                                                                                                                                                                    never logged so impact minimal)
                                                                                                                                                                                                                                                                                                                                                                                                                    [USN-6631-1] WebKitGTK vulnerabilities (06:26)
                                                                                                                                                                                                                                                                                                                                                                                                                    • 3 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-23222
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-23213
                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2024-23206
                                                                                                                                                                                                                                                                                                                                                                                                                      • Minimal info as with all webkit issues
                                                                                                                                                                                                                                                                                                                                                                                                                        • “improved memory handling to fix possible arbitrary code execution when processing crafted web content”
                                                                                                                                                                                                                                                                                                                                                                                                                        • “improved access restrictions to fix user fingerprinting from a crafted web page”
                                                                                                                                                                                                                                                                                                                                                                                                                        • “improved checks to fix a type confusion issue able to be triggered from
                                                                                                                                                                                                                                                                                                                                                                                                                        • crafted web content - possibly exploited in the wild”
                                                                                                                                                                                                                                                                                                                                                                                                                          [USN-6632-1] OpenSSL vulnerabilities (07:13)
                                                                                                                                                                                                                                                                                                                                                                                                                          • 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-0727
                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-5678
                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-6622-1] OpenSSL vulnerabilities from Episode 218
                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-6633-1] Bind vulnerabilities (07:33)
                                                                                                                                                                                                                                                                                                                                                                                                                              • 5 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-5679
                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-5517
                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-50868
                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-50387
                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-4408
                                                                                                                                                                                                                                                                                                                                                                                                                                • Range of issues including 2 different CPU-based DoS - one in handling of
                                                                                                                                                                                                                                                                                                                                                                                                                                • regular DNS queries / responses, the other in DNSSEC - “KeyTrap” - also
                                                                                                                                                                                                                                                                                                                                                                                                                                  affects resolvers not just servers (so any client system as well that is doing
                                                                                                                                                                                                                                                                                                                                                                                                                                  lookups) - affects the DNSSEC standard itself and hence affects various other
                                                                                                                                                                                                                                                                                                                                                                                                                                  implementations as well
                                                                                                                                                                                                                                                                                                                                                                                                                                • Attack works by having an attacker create a DNS zone with many RRSIG and
                                                                                                                                                                                                                                                                                                                                                                                                                                • DNSKEY records - these contain a cryptographic signature and public key
                                                                                                                                                                                                                                                                                                                                                                                                                                  respectively - so when trying to validate the DNSSEC record need both - and so
                                                                                                                                                                                                                                                                                                                                                                                                                                  will end up trying every possible RRSIG with every possible DNSKEY to find a
                                                                                                                                                                                                                                                                                                                                                                                                                                  match - with no bound on the computation time (and if implemented in a single
                                                                                                                                                                                                                                                                                                                                                                                                                                  threaded manner) - can completely DoS the server / client etc.
                                                                                                                                                                                                                                                                                                                                                                                                                                • Plus a similar issue in the NSEC3 proof of non-existence in DNSSEC
                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6634-1] .NET vulnerabilities (09:47)
                                                                                                                                                                                                                                                                                                                                                                                                                                  • 2 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-21404
                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-21386
                                                                                                                                                                                                                                                                                                                                                                                                                                    • Updates for dotnet 6, 7 and 8
                                                                                                                                                                                                                                                                                                                                                                                                                                    • DoS when parsing X509 certificates if using OpenSSL (as is the case in Ubuntu)
                                                                                                                                                                                                                                                                                                                                                                                                                                    • and a DoS in the SignalR library (allows a server to send asynchronous
                                                                                                                                                                                                                                                                                                                                                                                                                                      notifications to client-side web applications) able to be triggered by a
                                                                                                                                                                                                                                                                                                                                                                                                                                      malicious client
                                                                                                                                                                                                                                                                                                                                                                                                                                      [USN-6629-1, USN-6629-2] UltraJSON vulnerabilities (10:34)
                                                                                                                                                                                                                                                                                                                                                                                                                                      • 3 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2022-31117
                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2022-31116
                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2021-45958
                                                                                                                                                                                                                                                                                                                                                                                                                                        • Fast JSON encoder/decoder for Python
                                                                                                                                                                                                                                                                                                                                                                                                                                        • Is actually implemented in C with Python bindings - so has usual issues - UAF,
                                                                                                                                                                                                                                                                                                                                                                                                                                        • memory corruption, stack buffer overflow
                                                                                                                                                                                                                                                                                                                                                                                                                                          Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                          Linux kernel becomes a CNA (11:25)
                                                                                                                                                                                                                                                                                                                                                                                                                                          • Earlier this week, Greg Kroah-Hartman (one of the more famous Linux kernel

                                                                                                                                                                                                                                                                                                                                                                                                                                            developers - responsible for the various stable kernel trees / releases plus
                                                                                                                                                                                                                                                                                                                                                                                                                                            various subsystems within the kernel - also wrote one of the most popular
                                                                                                                                                                                                                                                                                                                                                                                                                                            books on Linux Kernel Driver development - even if it is woefully outdated
                                                                                                                                                                                                                                                                                                                                                                                                                                            nowadays) announced that the Linux kernel project itself has been accepted as
                                                                                                                                                                                                                                                                                                                                                                                                                                            a CNA by MITRE and would start issues CVEs for the vulnerabilities found
                                                                                                                                                                                                                                                                                                                                                                                                                                            within the kernel itself

                                                                                                                                                                                                                                                                                                                                                                                                                                          • Historically the upstream kernel developers and Greg himself have been quite

                                                                                                                                                                                                                                                                                                                                                                                                                                            disparaging of the CVE process / ecosystem and essentially saying that CVEs
                                                                                                                                                                                                                                                                                                                                                                                                                                            for the kernel are meaningless since that all bugs are potentially security
                                                                                                                                                                                                                                                                                                                                                                                                                                            issues and there are so many fixes that go into the kernel of which the
                                                                                                                                                                                                                                                                                                                                                                                                                                            security impact is not clear, that the only way to stay secure is to track one
                                                                                                                                                                                                                                                                                                                                                                                                                                            of the supported upstream stable kernel trees - otherwise CVEs would be issued
                                                                                                                                                                                                                                                                                                                                                                                                                                            for basically every commit that goes into one of the stable trees

                                                                                                                                                                                                                                                                                                                                                                                                                                            • Whilst in Ubuntu we tend to agree that the only way to maintain a kernel is
                                                                                                                                                                                                                                                                                                                                                                                                                                            • to use the stable trees (and hence the Ubuntu Kernel team continuously
                                                                                                                                                                                                                                                                                                                                                                                                                                              incorporates all the fixes from the upstream stable kernel trees into the
                                                                                                                                                                                                                                                                                                                                                                                                                                              different Ubuntu kernels) we still see a lot of value in the CVE ecosystem -
                                                                                                                                                                                                                                                                                                                                                                                                                                              and also we do not agree that all fix commits warrant a CVE
                                                                                                                                                                                                                                                                                                                                                                                                                                            • It was not then surprising to see that in the initial announcement there was a

                                                                                                                                                                                                                                                                                                                                                                                                                                              statement that:

                                                                                                                                                                                                                                                                                                                                                                                                                                              Note, due to the layer at which the Linux kernel is in a system, almost any

                                                                                                                                                                                                                                                                                                                                                                                                                                              bug might be exploitable to compromise the security of the kernel, but the
                                                                                                                                                                                                                                                                                                                                                                                                                                              possibility of exploitation is often not evident when the bug is
                                                                                                                                                                                                                                                                                                                                                                                                                                              fixed. Because of this, the CVE assignment team is overly cautious and assign
                                                                                                                                                                                                                                                                                                                                                                                                                                              CVE numbers to any bugfix that they identify.

                                                                                                                                                                                                                                                                                                                                                                                                                                            • This led many (including us) to fear that the kernel CNA would be issuing an

                                                                                                                                                                                                                                                                                                                                                                                                                                              extremely high volume of CVEs which would effectively overwhelm the CVE
                                                                                                                                                                                                                                                                                                                                                                                                                                              process and make it unworkable - for instance, LWN calculated that for the 6.1
                                                                                                                                                                                                                                                                                                                                                                                                                                              stable kernel has had over 12,000 fixes applied to it over the past year. So
                                                                                                                                                                                                                                                                                                                                                                                                                                              this leaves a huge scope for many CVEs to be possibly assigned - and as a
                                                                                                                                                                                                                                                                                                                                                                                                                                              comparison in total across all software / hardware devices etc in 2023 there
                                                                                                                                                                                                                                                                                                                                                                                                                                              was 29,000 CVEs assigned. So that could mean the kernel itself would possibly
                                                                                                                                                                                                                                                                                                                                                                                                                                              become responsible for at least a quarter of all CVEs in the future.

                                                                                                                                                                                                                                                                                                                                                                                                                                            • Greg has some prior form in this space as well since in 2019 he gave a talk

                                                                                                                                                                                                                                                                                                                                                                                                                                              where he suggested one way the kernel community could help fix the issue of
                                                                                                                                                                                                                                                                                                                                                                                                                                              CVEs being erroneously assigned against the kernel would be to start doing
                                                                                                                                                                                                                                                                                                                                                                                                                                              exactly this and assigning a CVE for every fix applied to the kernel and hence
                                                                                                                                                                                                                                                                                                                                                                                                                                              overwhelm the CVE ecosystem to (in his words) “burn it down”.

                                                                                                                                                                                                                                                                                                                                                                                                                                            • Also the GSD project (Global Security Database - set up as an alternate /

                                                                                                                                                                                                                                                                                                                                                                                                                                              competitor to CVE) was doing exactly this - tracking a huge number of fixes
                                                                                                                                                                                                                                                                                                                                                                                                                                              for the stable trees and assigning them GSD IDs - as per
                                                                                                                                                                                                                                                                                                                                                                                                                                              https://osv.dev/list?ecosystem=Linux it tracks 13573 issues

                                                                                                                                                                                                                                                                                                                                                                                                                                            • Thankfully though, this plan seems to have moderated over the past few days -

                                                                                                                                                                                                                                                                                                                                                                                                                                              after Greg posted a patch set to the LKML documenting the process, he
                                                                                                                                                                                                                                                                                                                                                                                                                                              clarified in a follow-up email that this would not be the case, and instead
                                                                                                                                                                                                                                                                                                                                                                                                                                              that CVEs will only be assigned for commits which appear to have a security
                                                                                                                                                                                                                                                                                                                                                                                                                                              relevant impact. How they actually do that remains to be seen, and his comment
                                                                                                                                                                                                                                                                                                                                                                                                                                              that “we (will) know it when we see it” doesn’t exactly put me at ease (since
                                                                                                                                                                                                                                                                                                                                                                                                                                              it is very easy to miss the security implications of any particular commit) at
                                                                                                                                                                                                                                                                                                                                                                                                                                              least this helps allay the fears that there would be a tidal wave of CVEs
                                                                                                                                                                                                                                                                                                                                                                                                                                              being assigned.

                                                                                                                                                                                                                                                                                                                                                                                                                                            • One outstanding issue which I directly asked Greg about is how they are

                                                                                                                                                                                                                                                                                                                                                                                                                                              actually tracking fixes for CVEs - since in their model, a CVE is equivalent
                                                                                                                                                                                                                                                                                                                                                                                                                                              to the commit which fixes the issue - however for lots of existing kernel CVEs
                                                                                                                                                                                                                                                                                                                                                                                                                                              that get assigned by other CNAs like Canonical or Red Hat etc, the fix
                                                                                                                                                                                                                                                                                                                                                                                                                                              comprises multiple commits

                                                                                                                                                                                                                                                                                                                                                                                                                                            • Greg says the whole process is quite complex and whilst their existing scripts

                                                                                                                                                                                                                                                                                                                                                                                                                                              want a one-to-one mapping from CVEs to commits they do plan to fix this in the
                                                                                                                                                                                                                                                                                                                                                                                                                                              future.

                                                                                                                                                                                                                                                                                                                                                                                                                                            • So will be interesting to see what things they will end up assigning

                                                                                                                                                                                                                                                                                                                                                                                                                                              CVEs. Also will be interesting to see how the interaction with security
                                                                                                                                                                                                                                                                                                                                                                                                                                              researchers plays out. Since their process is heavily skewed to the CVE
                                                                                                                                                                                                                                                                                                                                                                                                                                              corresponding to the fix commit AND they state that this must be in one of the
                                                                                                                                                                                                                                                                                                                                                                                                                                              stable trees for a CVE to be assigned, it doesn’t leave a lot of room for
                                                                                                                                                                                                                                                                                                                                                                                                                                              responsible disclosure. They do say they can assign a CVE for an issue before
                                                                                                                                                                                                                                                                                                                                                                                                                                              it is resolved with a commit to one of the stable trees, but ideally these
                                                                                                                                                                                                                                                                                                                                                                                                                                              details would get disclosed to distros and others ahead of the CVE details
                                                                                                                                                                                                                                                                                                                                                                                                                                              being released to the public. I also asked Greg about this but am awaiting a
                                                                                                                                                                                                                                                                                                                                                                                                                                              response.

                                                                                                                                                                                                                                                                                                                                                                                                                                              Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                              • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                              • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                                                                              • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                                                                                              • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                              • 21 min
                                                                                                                                                                                                                                                                                                                                                                                                                                              • Episode 218
                                                                                                                                                                                                                                                                                                                                                                                                                                                Overview

                                                                                                                                                                                                                                                                                                                                                                                                                                                AppArmor unprivileged user namespace restrictions are back on the agenda this

                                                                                                                                                                                                                                                                                                                                                                                                                                                week as we survey the latest improvements to this hardening feature in the
                                                                                                                                                                                                                                                                                                                                                                                                                                                upcoming Ubuntu 24.04 LTS, plus we discuss SMTP smuggling in Postfix, runC
                                                                                                                                                                                                                                                                                                                                                                                                                                                container escapes and Qualys’ recent disclosure of a privilege escalation
                                                                                                                                                                                                                                                                                                                                                                                                                                                exploit for GNU libc and more.

                                                                                                                                                                                                                                                                                                                                                                                                                                                This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                                                                                39 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                                                                                                [USN-6591-2] Postfix update (00:48)
                                                                                                                                                                                                                                                                                                                                                                                                                                                • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-51764
                                                                                                                                                                                                                                                                                                                                                                                                                                                  • On 18th December (during the holiday break), SEC Consult published a report
                                                                                                                                                                                                                                                                                                                                                                                                                                                  • about a new technique for email spoofing, which they dubbed SMTP Smuggling
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Similar to HTTP Request Smuggling - relies on exploiting differences in how
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • SMTP protocol is interpreted by outbound (originating) vs inbound
                                                                                                                                                                                                                                                                                                                                                                                                                                                      (receiving) SMTP servers. In particular the end-of-data sequence
                                                                                                                                                                                                                                                                                                                                                                                                                                                      . gets interpreted loosely so that it is possible to include
                                                                                                                                                                                                                                                                                                                                                                                                                                                      extra SMTP commands within the message data which would then go on to be
                                                                                                                                                                                                                                                                                                                                                                                                                                                      interpreted as an additional SMTP commands to be executed by the receiving
                                                                                                                                                                                                                                                                                                                                                                                                                                                      server and to cause it to receive two emails when only one was sent in the
                                                                                                                                                                                                                                                                                                                                                                                                                                                      first place, and where the usual SPF checks get bypassed for this second
                                                                                                                                                                                                                                                                                                                                                                                                                                                      email - so can bypass SPF/DMARC policies to spoof emails from various
                                                                                                                                                                                                                                                                                                                                                                                                                                                      domains
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Affected a number of projects including postfix - Upstream postfix released
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • version 3.8.4 with an initial fix on 22nd December
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • We then released USN-6591-1 with that fix
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Then on 21st January released a more robust fix with an additional config
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • option to increase interoperability whilst still preventing SMTP smuggling
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • This second update includes the reworked fix
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-6619-1] runC vulnerability (03:22)
                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-21626
                                                                                                                                                                                                                                                                                                                                                                                                                                                        • “Internal file descriptor leak” - using a specially crafted container image,
                                                                                                                                                                                                                                                                                                                                                                                                                                                        • allows an attacker to cause a newly spawned container to have a working
                                                                                                                                                                                                                                                                                                                                                                                                                                                          directory within the host filesystem namespace which in turn can allow the
                                                                                                                                                                                                                                                                                                                                                                                                                                                          attacker to escape the container - various ways this can be attacked, full
                                                                                                                                                                                                                                                                                                                                                                                                                                                          details on the upstream advisory
                                                                                                                                                                                                                                                                                                                                                                                                                                                          https://github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv
                                                                                                                                                                                                                                                                                                                                                                                                                                                          [USN-6620-1] GNU C Library vulnerabilities (04:17)
                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 3 CVEs addressed in Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6780
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6779
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6246
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Latest round of vulnerabilities from Qualys
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Affect the syslog() system call
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Heap buffer overflow, off-by-one buffer overflow and integer overflow
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Of these the heap buffer overflow is the most severe - Qualys were able to
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • demonstrate they could exploit and up-to-date default install of Fedora 38 to
                                                                                                                                                                                                                                                                                                                                                                                                                                                              escalate privileges from a local unprivileged user to root.
                                                                                                                                                                                                                                                                                                                                                                                                                                                              • uses the value of argv[0] in a call to snprintf() into a fixed size buffer
                                                                                                                                                                                                                                                                                                                                                                                                                                                              • allocated on the stack - snprintf() won’t overflow this but will return a
                                                                                                                                                                                                                                                                                                                                                                                                                                                                value larger than the fixed size buffer - as a result a heap buffer to then
                                                                                                                                                                                                                                                                                                                                                                                                                                                                contain this string would only get allocated with a size of 1 byte but then
                                                                                                                                                                                                                                                                                                                                                                                                                                                                the full expected data would get copied into it - and since the attacker
                                                                                                                                                                                                                                                                                                                                                                                                                                                                controls this value they can write arbitrary data to the heap by just using
                                                                                                                                                                                                                                                                                                                                                                                                                                                                a crafted program name (which is easy to do via the the exec command built
                                                                                                                                                                                                                                                                                                                                                                                                                                                                in to bash etc)
                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Various setuid binaries like /usr/bin/su call syslog() internally and so can
                                                                                                                                                                                                                                                                                                                                                                                                                                                              • be abused in this way
                                                                                                                                                                                                                                                                                                                                                                                                                                                                [USN-6587-4] X.Org X Server regression (07:14)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 6 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-21886
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-21885
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-0409
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-0408
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2024-0229
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-6816
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6621-1] ImageMagick vulnerability (07:28)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-5341
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • ImageMagick is in universe, so these updates are available via Ubuntu Pro
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Heap UAF in BMP decoder - likely DoS but possible code-execution via a
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • crafted BMP file
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [USN-6622-1] OpenSSL vulnerabilities (08:07)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 4 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2024-0727
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-6237
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-6129
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-5678
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Two CPU-based DoS issues where OpenSSL would spend an excessive amount of
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • time trying to check an invalid RSA or X9.42 DH keys
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • NULL ptr deref when parsing a malicious PKCS12 file
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Issue specific to PowerPC (ppc64el arch in Ubuntu) - possible to corrupt
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • application state since the POLY1305 MAC implementation (hand-coded assembly)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            saves the contents of the vector registers in a different order than when they
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            get restored - so some registers will be corrupted when returning to the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            caller
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Only relevant on newer PowerPC processors which support the PowerISA 2.07
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • instructions
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [USN-6592-2] libssh vulnerabilities (09:27)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-6918
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-6004
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Recent libssh update now also available for Ubuntu Pro users on older releases
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6623-1] Django vulnerability (09:34)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-24680
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • ReDoS when using the intcomma template
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-6609-3] Linux kernel (Oracle) vulnerabilities (09:45)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 6 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-0193
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6932
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6931
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6817
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6606
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6040
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Refer back to Episode 217 for most recent kernel vulns
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-6610-2] Firefox regressions (09:57)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 14 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-0746
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-0755
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-0754
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-0753
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-0751
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-0750
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-0749
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-0748
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-0747
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-0745
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-0744
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-0743
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-0742
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-0741
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Similarly, last week I mentioned [USN-6610-1] Firefox vulnerabilities -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • upstream 122.0 release has various minor regressions now fixed in this 122.0.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              release - including an issue if you happened to be using the Yaru-Remix theme
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              in Ubuntu
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Updates for unprivileged user namespace restrictions in Ubuntu 24.04 LTS (10:32)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Previously mentioned this work a few times on the podcast (Call for testing of Unprivileged User Namespace Restrictions on Mantic in Episode 211 and Unprivileged user namespace restrictions via AppArmor in Ubuntu in Episode 205)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Both those times was about user namespace restrictions in Ubuntu 23.10 (the current interim release)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • For those not familiar - user namespaces provide a mechanism for operating as
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • a different UID on a Linux system - in particular, can operate as uid 0 within
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                a namespace which is then constrained by the original parent namespace -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ie. as a normal unprivileged user, I could create a new user namespace and map
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                my UID to 0 within that namespace, which can then allow me to have say
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                CAP_NET_ADMIN within that namespace and so create firewall rules etc that only
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                affect applications within that namespace and not the host system
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Can also be used for isolation etc
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • However, since within the namespace my unprivieleged user now has extra
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • privileges, exposes additional kernel attack surface - various bugs have
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  been found in differetn kernel subsystems that allow an unprivileged user to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  exploit the kernel as a result
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Want a way to provide fine grained controls over unprivileged user namespaces
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Previously, used AppArmor to deny the ability to create a new user namespace
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • unless an application was explicitly tagged via an associated AppArmor profile
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • John and Georgia from the AppArmor team have made a number of enhancements, in
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • particular adding a new default functionality where you can define in AppArmor
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  policy a different AppArmor profile which an application should transition
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  into when it creates a user namespace
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • In particular, we can now do this even for the “unconfined” profile - and then
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • ship a default “unconfined_userns” profile which allows an application to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  create a userns but to not gain any additional capabilities within that by
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  default
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Various sandboxing frameworks behave much more sensibly with this - so instead
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • of just failing when they try and create the userns, they instead are able to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  create one but then if they try and gain additional capabilities (like
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  CAP_NET_ADMIN etc as mentioned before) this is then denied
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • This also matches the semantics which we want to achieve since it is not
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • really the user namespace itself that is the original issue, it is the ability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  to gain additional capabilities within that which the unprivileged user did
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  not have originally
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • In addition, Georgia has been busy testing various applications within the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • archive and across the Linux ecosystem to ensure we ship any required profiles
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  for them out-of-the-box so as many pieces of software continue to work as
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  expected with these restrictions in place
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • AppArmor in noble is already enabling this restriction and these updates are
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • now in the apparmor package in noble-proposed pocket
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Expect to be available in noble within the next few days once automated
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • testing completes
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Requires some additional kernel support - Kernel Team has merged this into
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • their current linux-unstable kernel (available via the Kernel Team’s unstable
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    PPA) which will land eventually land in 24.04 proper
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • On track to have this additional security hardening feature enabled by default
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • for 24.04 LTS at release so we can close off one of the more prevalent sources
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    of kernel privilege escalation bugs in the past few years
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 19 min
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Episode 217
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Overview

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      For the first episode of 2024 we take a look at the case of a raft of bogus FOSS

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      CVEs reported on full-disclosure as well as AppSec tools in Ubuntu and the EOL
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      announcement for 23.04, plus we cover vulnerabilities in the Linux kernel, Puma,
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Paramiko and more.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      81 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [USN-6601-1] Linux kernel vulnerability (01:16)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Trusty ESM (14.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6932
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • UAF in IGMP protocol (allows multiple devices to share the same IPv4 address
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • and hence all receive the same data via multicasting - often used for things
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          like video streaming) - race condition between two different threads in the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          handling of a timer which could cause the timer to be registered on an object
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          that is then later freed by another thread - when the timer then fires the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          thread will try and access the object which has now been freed
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Can be exploited by an unprivileged local user in a user namespace
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-6602-1] Linux kernel vulnerabilities (02:23)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 5 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6932
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6931
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6606
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-45863
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-20588
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • IGMP UAF
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • OOB write in perf - didn’t properly check the size of all events when
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • processing them - direct memory corruption able to be triggered by a local
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              user - and on older kernels like the 4.4 kernel shipped in Ubuntu 16.04 this
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              can be done from userspace directly
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Divide-by-zero error on some AMD processors could return speculative data ->
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • info leak ([USN-6383-1] Linux kernel vulnerabilities from Episode 210)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [USN-6603-1] Linux kernel (AWS) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 3 CVEs addressed in Xenial ESM (16.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-6932
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-6931
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-6606
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6604-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 6 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-6932
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-6931
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-6606
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-45863
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-20588
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-1079
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-6604-2] Linux kernel (Azure) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 6 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6932
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6931
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6606
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-45863
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-20588
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-1079
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-6605-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 4 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6932
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6931
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6606
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6040
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-6605-2] Linux kernel (KVM) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 4 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-6932
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-6931
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-6606
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-6040
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6606-1] Linux kernel (OEM) vulnerabilities (03:04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 5 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-0193
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-6931
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-6817
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-6606
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-51779
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • perf OOB write
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 2 very similar UAFs in netfilter - both require CAP_NET_ADMIN to be able to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • exploit (ie to create a netfilter chain etc) but this can easily be obtained
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      in an unprivileged user namespace -> privesc for unprivileged local user
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [USN-6608-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 5 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-0193
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6932
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6931
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6817
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6606
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-6609-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 6 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-0193
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6932
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6931
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6817
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6606
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6040
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-6609-2] Linux kernel (NVIDIA) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 6 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-0193
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-6932
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-6931
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-6817
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-6606
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-6040
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6607-1] Linux kernel (Azure) vulnerabilities (03:32)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 7 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-0193
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-6932
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-6931
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-6817
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-6606
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-6040
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-5345
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 2 netfilter UAFs, IGMP UAF, perf OOB write
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • UAF in SMB client implementation - local crash / privesc
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-6596-1] Apache::Session::LDAP vulnerability (03:45)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2020-36658
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Would not check the validity of an X.509 certificate since uses the Net::LDAPS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Perl module which by default doesn’t do this and requires applications to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          explicitly instruct it to do so
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [USN-6597-1] Puma vulnerability (04:24)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2024-21647
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • HTTP server for Ruby/Rack applications that uses threading for improved performance
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Vulnerable to a HTTP request smuggling attack since it would fail to properly
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • parse packets with chunked transfer encoding
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Also failed to set a limit on the size of chunk extensions which could then
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • allow a CPU or network-bandwidth based DoS attack
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [USN-6598-1] Paramiko vulnerability (04:58)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-48795
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Fix for Terrapin attack disclosed back in December - flaw in SSH protocol
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • itself which allows an attacker who can interpose on the connection to drop
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  the EXT_INFO message which is sent during the handshake to negotiate various
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  protocol extensions in a way that neither the client or server will notice
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  (since they can just send an empty ignored packet with the same sequence
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  number). This can be done quite easily by an attacker since during this stage
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  of the connection there is no encryption in place. End result is the attacker
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  can cause either a loss of integrity (since this won’t be detected by the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  other party) or potentially to compromise the key exchange itself and hence
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  cause a loss of confidentiality as well
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [USN-6599-1] Jinja2 vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 2 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2024-22195
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2020-28493
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-6600-1] MariaDB vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 2 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-22084
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2022-47015
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-6611-1] Exim vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-51766
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-6610-1] Firefox vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 14 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-0746
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-0755
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-0754
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-0753
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-0751
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-0750
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-0749
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-0748
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-0747
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-0745
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-0744
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-0743
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-0742
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-0741
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6613-1] Ceph vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-43040
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-6612-1] TinyXML vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-34194
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-6614-1] amanda vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-30577
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-6615-1] MySQL vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 22 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20985
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20984
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20983
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20982
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20981
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20978
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20977
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20976
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20974
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20973
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20972
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20971
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20970
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20969
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20967
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20966
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20965
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20964
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20963
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20962
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20961
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2024-20960
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6616-1] OpenLDAP vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-2953
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-6587-3] X.Org X Server regression
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 6 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-21886
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-21885
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-0409
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-0408
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2024-0229
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6816
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-6618-1] Pillow vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 2 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-50447
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-44271
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-6617-1] libde265 vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 14 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-36408
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-21606
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-21598
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-21597
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-21605
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-21604
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-21603
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-21602
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-21601
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-21600
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-21599
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-21596
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-21595
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2020-21594
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Ubuntu 23.04 (Lunar Lobster) EOL (06:48)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Released back in April 2023 - like all interim releases, supported for 9 months
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Reached EOL on 25th January - won’t receive any package updates (security or
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • bug fix) and will be archived to old-releases.ubuntu.com in the coming weeks
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Urge to upgrade to the currently supported interim release 23.10 ASAP as once
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • it does get archived the process to upgrade becomes harder (since you have to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    manually update your apt sources to refer to the old-releases server first)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 23.10 (Mantic Minotaur) will then be supported for about 5 more months until
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • July this year
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Awesome AppSec in Ubuntu (08:22)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • https://discourse.ubuntu.com/t/awesome-appsec-in-ubuntu/41922/1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Andrei has compiled a list of tools available in Ubuntu which can be used by
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • security researchers
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Includes tools for:
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Coordinated Vulnerability Disclosure
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Fuzzing
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • License scanning
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Reverse engineering
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Runtime process analysis
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Security linting
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Symbolic execution
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Threat modelling
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Scanning for vulnerable dependencies
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Web scanning
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Runtime application isolation (sandboxing)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Whether you are an software engineer looking to make your software more secure
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • or a security researcher trying to find vulns or even a security engineer
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        wanting tools to help with vulnerabililty management, there is likely
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        something in the list for you
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • If you find anything missing, send Andrei a PR as the list is hosted on Github
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • full-disclosure spammed with zombie CVEs (09:52)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • full-disclosure mailing list slowly declining in popularity but was once the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • go-to place to discuss and disclose vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • In January, saw a large increase in the number of messages posted (75 compared
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • to 15-30 which was the usual number posted for any month in 2023)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Meng Ruijie from National University in Singapore posted 36 different CVE
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • reports across a large range of OSS projects, including Redis Raft, TinyDTLS,
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Mesa, ncurses, vim, GTK and more - and almost all of them were described as
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          NULL pointer dereferences or buffer overflows etc
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Alan Coppersmith raised this on the oss-security mailing list, since none of
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • these issues had been raised privately with any of these projects but also
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          that most of the CVE descriptions appeared to be quite bogus - e.g. for a CVE
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          in Mesa, where Meng describes them as a NULL pointer deref the associated
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          issue that the CVE points to in the upstream mesa gitlab describes a possible
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          OOB read but where there is no good evidence that this is able to be
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          influenced by the caller and hence there is no evidence that there is a
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          security issue here at all
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • They appear to have been assigned by just looking for either reports in
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • upstream issue trackers that mention possible security issues OR upstream
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          commits that mention words like NULL pointer dereference but without any
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          consideration as to whether these are actual vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • For example - just because some code may potentially dereference a NULL
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • pointer, if the caller cannot influence that to occur then there is no way
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            to trigger it and so it is not an actual vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Likely almost all of these CVEs will get disputed and so provide no real
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • value - also they waste the time of OSS developers to respond to these reports
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            as well as distros and others to investigate them etc
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 16 min
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Episode 216
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Overview

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              For the final episode of 2023 we discuss creating PoCs for vulns in tar and the

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              looming EOL for Ubuntu 23.04, plus we look into security updates for curl,
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              BlueZ, Netatalk, GNOME Settings and a heap more.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              57 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [USN-6535-1] curl vulnerabilities (00:54)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 2 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-46219
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-46218
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Mishandled cookies from domains with mixed case - allowing an attacker to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • create so called “super cookies” that would then get passed back to more
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  domains that what is normally allowed - ie a site can set a cookie which is
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  then sent to different / unrelated sites. Depends on a feature called the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Public Suffix List which is a community initiative (led by Mozilla) to provide
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  an accurate list of domain name suffixes - ie. .com / .org but also .co.uk
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  etc - since there is no good algorithmic way of determining the highest level
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  at which a domain may be registered for a particular TLD as each registrar is
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  different
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • so could set a cookie with domain=co.UK with a URL of say curl.co.uk and
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • this would then get sent to every other .co.uk domain contrary to the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    expectations of the PSL which lists .co.uk as a PSL domain
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [USN-6463-2] Open VM Tools vulnerabilities (02:56)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-34059
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-34058
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • SAML token signature bypass - allows an attacker who already has Guest
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Operation Privileges within a guest VM to elevate their privileges if the VM
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        has been assigned a more privileged Guest Alias
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • File descriptor hijack vulnerability within the vmware-user-suid wrapper - a
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • local user with non-root privileges that is able to hijack the /dev/uinput
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        file descriptor may be able to simulate user inputs
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [USN-6538-1] PostgreSQL vulnerabilities (03:48)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-5870
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-5869
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-5868
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Upgrades to the latest upstream point releases - includes both security and
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • bug fixes etc
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 15.5 (23.10, 23.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 14.10 (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 12.17 (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-6539-1] python-cryptography vulnerabilities (04:14)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 2 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-49083
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-23931
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • NULL pointer dereference / segfault on loading of crafted PKCS7 certificates
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6540-1] BlueZ vulnerability (04:57)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-45866
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Whilst bluetooth discoverable, possible for an attacker to pair a HID device
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • and inject keystrokes etc without any intervention
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Fixed by enabling the existing configuration ClassicBondedOnly=true - this may
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • break some legacy input devices like PS3 controller - in which case, should
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      edit /etc/bluetooth/input.conf and set this back to false but then beware that
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      you may be vulnerable to attack from anyone within bluetooth range when your
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      machines is discoverable - ie. bluetooth settings panel is open
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [USN-6541-1] GNU C Library vulnerabilities (06:30)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 3 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-5156
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-4813
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-4806
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Previous fix for CVE-2023-4806 was not sufficient - UAF in getaddrinfo() -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • possible to still trigger
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [USN-6522-2] FreeRDP vulnerabilities (07:00)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 3 CVEs addressed in Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39356
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39352
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2022-41877
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-6522-1] FreeRDP vulnerabilities from Episode 215
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-6542-1] TinyXML vulnerability (07:08)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-42260
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Infinite loop able to be triggered by a crafted XML document - CPU-based DoS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6543-1] GNU Tar vulnerability (07:18)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-39804
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Stack buffer overflow on parsing a tar archive with an extremely large

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      extended attribute name/value - PAX archive format allows to store extended
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      attributes - on the kernel’s VFS layer these are limited to 255 bytes for the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      name and 64kB for the value - but in a tar these can be basically arbitrary

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • When processing the archive, tar would allocate space for these on the stack -

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      BUT the stack is limited to a maximum size of 8MB normally - so if can specify
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      an xattr name of more than 8MB can overflow the entire stack memory region -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      then into guard pages or even beyond, triggering a segfault or at worst a heap
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      corruption and hence possible RCE -> but in Ubuntu we have enabled stack clash
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      protection since 19.10 - which turns this into a DoS only

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Reminiscent of the original Stack Clash “System Down” vulnerability in systemd
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • $ hardening-check $(which tar)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        /usr/bin/tar:
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Position Independent Executable: yes
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Stack protected: yes
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Fortify Source functions: yes (some protected functions found)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read-only relocations: yes
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Immediate binding: yes
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Stack clash protection: yes
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Control flow integrity: yes
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Speaking from experience, it is not easy to create such an archive - either

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        through a real xattr on disk or through specifying one on the command-line
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        (since you can specify arbitrary attributes be stored for files when adding
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        them to an archive but then you hit the maximum limit of command-line
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        arguments) BUT it is possible - in my case I did this though using sed to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        replace the contents of a xattr name in an existing archive with a crafted one
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        and then doing a bunch of other hacks to fixup all the metadata of the tar
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        archive to match - helpfully, all these attributes in the archive are stored
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        as NUL-terminated strings, so can simply used sed to fix them all up assuming
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        you can calculate the correct values

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Fixed by instead allocating these on the heap which does not have the same

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        arbitrary limitation as the stack

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [USN-6500-2] Squid vulnerabilities (11:35)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-46847
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-46728
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6500-1] Squid vulnerabilities from Episode 214
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6544-1] GNU binutils vulnerabilities (11:44)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 5 CVEs addressed in Trusty ESM (14.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-35205
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2021-46174
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2020-19726
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-4285
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-38533
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Didn’t do bounds checking properly in various places - leading to heap buffer
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • overflows / OOB reads etc in various things like objdump etc
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [USN-6545-1] WebKitGTK vulnerabilities (12:08)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 2 CVEs addressed in Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-42917
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-42916
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Both issues that come from upstream webkit
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • OOB read -> info leak
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Memory corruption that Apple said was being exploited in the wild against
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • various versions of iOS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [USN-6546-1] LibreOffice vulnerabilities (12:45)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 2 CVEs addressed in Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6186
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-6185
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Uses gstreamer to play embedded videos (presumably in presentations etc) - to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • do this, creates a gstreamer pipeline including the filename of the video
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          itself - this was not adequetely escaped, so could allow arbitrary code
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          execution if it contained shell meta characters etc
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Link targets allow arbitrary script execution - similar to historic
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-2255 from [USN-6144-1] LibreOffice vulnerabilities in Episode 198
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [USN-6547-1] Python vulnerability (13:46)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Lunar (23.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-41105
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Issue specific to Python 3.11 where if a path contained an embedded NUL byte
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • and was passed to os.path.normpath() it would get truncated at the NUL byte -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              fixed to remove this behaviour
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [USN-6550-1] PostfixAdmin vulnerabilities (14:19)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 3 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-28447
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2022-31129
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2022-29221
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Issues in various embedded modules - Smarty and Moment.js - allowing possible
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • arbitrary code execution, XSS or DoS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [USN-6551-1] Ghostscript vulnerability (14:37)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-46751
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • UAF on file object on error path
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-6552-1] Netatalk vulnerability (14:43)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-42464
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Apple Filing Protocol (AFP) service - similar to SMB for Windows - allows a
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Ubuntu machine to share files with MacOS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Also implements support for Spotlight to search - using tracker as the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • indexer, metadata store and search engine under-the-hood
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Parser for spotlight RPC packets failed to properly do type checking,
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • resulting in a type confusion bug and possible RCE via memory corruption -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          similar to CVE-2023-34967 for Samba since the code in netatalk originated from
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          that code from Samba ([USN-6238-1] Samba vulnerabilities from Episode 204)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [USN-6554-1] GNOME Settings vulnerability (15:57)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-5616
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • GNOME settings allows the ability to turn on / off remote SSH access from the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • sharing panel within the main settings application in Ubuntu
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Since moving to socket activated SSHd in 22.10, GNOME Settings was never
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • updated in Ubuntu to support this as well
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Would mean that it would always show the machine was not accessible / sharing
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • via SSH even when it was (since it would only check the status of the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ssh.service, not ssh.socket)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Ubuntu specific issue - fixed by extending GNOME settings to check both the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • service and the socket (since it is still a legitimate configuration to use
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              the service over the socket in recent Ubuntu releases)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Also backported to older releases since it is also a supported configuration
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • there to use socket activation (although the sysadmin has to set this up
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              themselves)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [USN-6553-1] Pydantic vulnerability (17:49)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-29510
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Python data validation library
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CPU-based DoS since if passed the value of “infinity” to the validator to be
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • parsed as a date/datetime, would result in an infinite loop
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [USN-6536-1] Linux kernel vulnerabilities (18:10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 6 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-5717
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-5178
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-5158
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-45898
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-42754
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-39189
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-6537-1] Linux kernel (GCP) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 11 CVEs addressed in Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-5717
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-5633
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-5345
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-5178
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-5158
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-5090
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-45898
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-42754
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-4244
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-39189
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-31085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-6548-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 10 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6176
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-5717
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-5178
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-42754
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39194
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39193
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39192
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39189
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-37453
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-3006
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-6549-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 11 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-5717
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-5178
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-5158
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-42754
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-39198
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-39194
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-39193
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-39192
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-39189
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-3773
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-37453
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6534-2] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 12 CVEs addressed in Lunar (23.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-6039
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-5717
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-5178
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-5158
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-42754
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-39198
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-39194
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-39193
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-39192
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-39189
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-3773
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-37453
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-6549-2] Linux kernel (GKE) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 11 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-5717
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-5178
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-5158
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-42754
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-39198
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-39194
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-39193
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-39192
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-39189
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-3773
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-37453
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-6548-2] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 10 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6176
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-5717
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-5178
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-42754
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39194
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39193
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39192
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39189
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-37453
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-3006
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Ubuntu 23.04 (Lunar Lobster) approaching EOL (18:48)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • https://lists.ubuntu.com/archives/ubuntu-security-announce/2023-December/007974.html
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Interim releases receive 9 months of support
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Lunar reaches EOL on 25th January
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Good opportunity over the holiday break to upgrade to 23.10 (Mantic)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • https://help.ubuntu.com/community/ManticUpgrades
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Ubuntu Security team (and rest of Canonical) on break till early January 2024 (19:33)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Various members of the team will be checking in each day to look for any
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • serious issues
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Not planning any new security update releases during this time unless
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • something major happens (we are still wincing from Log4Shell - Log4Shell
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    explodes the internet from Episode 142 in late December 2022)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • As usual, contact us via the normal means if something is particularly urgent
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • and someone should respond
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 22 min
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Episode 215
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Overview

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Mark Esler is our special guest on the podcast this week to discuss the

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      OpenSSF’s Compiler Options Hardening Guide for C/C++ plus we cover
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      vulnerabilities and updates for GIMP, FreeRDP, GStreamer, HAProxy and more.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      65 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [USN-6521-1] GIMP vulnerabilities (00:50)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 6 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-44444
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-44443
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-44442
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-44441
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2022-32990
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2022-30067
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Includes 4 recent issues disclosed via Trend’s ZDI - all found by the same
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • researcher - 2 heap buffer overflows in DDS and PSD parsers, ab integer
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          overflow and a separate off-by-one error in the PSP parser which could
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          apparently lead to remote code execution plus a couple DoS related issues
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          (unhandled exception and an excessive memory allocation) - both leading to a
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          crash
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [USN-6522-1] FreeRDP vulnerabilities (01:39)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39356
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39352
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2022-41877
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Windows RDP client
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Malicious server could send a crafted drive redirect to the client -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • triggering an OOB read, causing the client to disclose memory contents and
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              therefore possibly sensitive info to the server
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Plus an OOB write and an OOB read on crafted image data - both also likely
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • leading to a crash
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [USN-6523-1] u-boot-nezha vulnerability (02:19)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 3 CVEs addressed in Jammy (22.04 LTS), Lunar (23.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2022-30790
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2022-30552
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2022-2347
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • u-boot for the Allwinner Nezha RISC-V board
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Missing length checks in DFU parser -> heap buffer overflow
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 2 other buffer overflows when handling fragmented IP packets
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6524-1] PyPy vulnerability (03:06)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2022-37454
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Integer overflow leading to a buffer overflow in SHA3 - comes from the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • original reference implementation of SHA3
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Has affected a range of packages in Ubuntu
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • PHP, Python itself and now PyPy
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • [USN-6525-1] pysha3 vulnerability (03:06)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2022-37454
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Same as above
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6519-2] EC2 hibagent update
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Affecting Xenial ESM (16.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-6526-1] GStreamer Bad Plugins vulnerabilities (03:16)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 6 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-44446
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-44429
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-40476
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-40475
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-40474
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-37329
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Heap overflow in PGS subtitle overlay decoder
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Various integer overflows -> heap buffer overflows in MXF container handler
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • (Material Exchange Format) - apparently used for delivering advertisements to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  TV stations and for movies in commercial theatres - specifically in handling
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  of files using AES3 audio
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • MXF demuxer UAF
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • AV1 buffer overflow
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Integer overflow -> stack overflow in H.256 parser
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6527-1] OpenJDK vulnerabilities (04:09)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 2 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-22081
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-22025
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 11.0.21 + 17.0.9
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-6528-1] OpenJDK 8 vulnerabilities (04:25)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 4 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-22081
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-22067
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-22025
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2022-40433
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 8u392
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-6509-2] Firefox regressions (04:34)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 10 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6209
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6208
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6207
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6205
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6204
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6213
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6212
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6211
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6210
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-6206
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 120.0.1 - in particular includes a fix where Firefox would crash immediately
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • on startup but only for aarch64 (arm64) on Linux when using page sizes other
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              than 4K - ie. as used in Apple silicon etc
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [USN-6529-1] Request Tracker vulnerabilities (05:25)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 4 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-41260
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-41259
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2022-25802
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2021-38562
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Possible timing attack in the authentication module - could allow to enumerate
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • user accounts
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • XSS plus some info leaks as well
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6530-1] HAProxy vulnerability (06:12)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-45539
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Mishandling of # character in URIs could allow unexpected routing of a URI
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • containing say index.html#.png to a static server (since usually is configured
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      to route .png to a static server, but in this case the request is really for
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      index.html)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [USN-6531-1] Redis vulnerabilities (07:06)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 6 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-45145
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-28856
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-25155
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2022-36021
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2022-35977
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2022-24834
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Heap overflow in cjson library able to be triggered by a Lua script -> RCE
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Race condition on setting permissions on the local unix socket - if using a
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • less restrictive umask could allow a local attacker to race redis on startup
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Also various integer overflows and other issues fixed too
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-6494-2] Linux kernel vulnerabilities (08:08)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 9 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-5717
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-45871
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-45862
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-42754
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39194
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39193
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39192
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39189
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-31085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-6495-2] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 2 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-45871
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-31085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6496-2] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-45871
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-31085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-25775
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-6502-4] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 5 CVEs addressed in Jammy (22.04 LTS), Lunar (23.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-5345
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-5090
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-45871
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-31085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-25775
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-6532-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 10 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-5717
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-45871
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-45862
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-42754
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39194
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39193
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39192
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-39189
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-31085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-20593
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-6533-1] Linux kernel (OEM) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 2 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-46862
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-46813
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6534-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 12 CVEs addressed in Jammy (22.04 LTS), Lunar (23.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-6039
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-5717
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-5178
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-5158
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-42754
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-39198
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-39194
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-39193
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-39192
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-39189
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-3773
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-37453
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Alex discusses the OpenSSF’s Compiler Options Hardening Guide for C/C++ with Mark Esler (08:38)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • https://openssf.org/blog/2023/11/29/strengthening-the-fort-openssf-releases-compiler-options-hardening-guide-for-c-and-c/
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 31 min
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Episode 214
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Overview

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          This week we take a deep dive into the Reptar vuln in Intel processors plus we

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          look into some relic vulnerabilities in Squid and OpenZFS and finally we detail
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          new hardening measures in tracker-miners to keep your desktop safer.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          115 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [USN-6481-1] FRR vulnerabilities (01:21)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 2 CVEs addressed in Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-46753
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-46752
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Two different crashes reported by network pentester from Amazon - appears to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • be fuzzing frr -> DoS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [USN-6482-1] Quagga vulnerabilities (01:42)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 2 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-46753
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2022-37032
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Speaking of BGP daemons - Quagga was the precursor to FRR - also suffers from
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • one of these CVEs, plus and older one that was previously fixed in FRR
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ([USN-5685-1] FRR vulnerabilities from Episode 181) that
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  would lead to an OOB read
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [USN-6483-1] HTML Tidy vulnerability (02:05)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2021-33391
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Implemented parser as a recursive algorithm - so on deeply nested documents,
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • could end up exhausting the stack and causing memory corruption etc.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Fixed by reimplementing the parser as an iterative loop with a heap-based
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • stack
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [USN-6480-1] .NET vulnerabilities (02:42)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 2 CVEs addressed in Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-36049
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-36558
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-6484-1] OpenVPN vulnerabilities (02:51)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 2 CVEs addressed in Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-46850
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-46849
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Two issues which only affected more recent versions of OpenVPN (>= =2.6.0) -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • one UAF and the other a possible divide by zero -> DoS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [USN-6485-1] Intel Microcode vulnerability (03:13)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-23583
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Tavis Ormandy’s latest processor bug - “Reptar” - found again using the same
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • technique as he used to find Zenbleed (AMD) but this time in Intel
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  processors - essentially can be thought of as akin to fuzzing but instead of
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  generating random input to find unexpected behaviour, generate some random
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  input in the form of a set of processor instructions, and then also generate
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  an equivalent version of this by adding random alignment, serialization and
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  memory fence instructions etc. These extra instructions shouldn’t change the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  behaviour of the program being executed, so if a difference is observed then
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  can likely assume the hardware has behaved incorrectly - perhaps some
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  underlying microarchitectural behaviour has been triggered - but either way
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  could indicate the presence of a hardware bug which could in turn be exploited
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  as a vulnerability to cause undesired affects
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • In this case, found a sequence of instructions that in general should be
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • ignored but which could instead cause the processor to hit a machine check
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  exception and halt - even from an unprivileged guest VM - this is the kind of
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  things that cloud providers worry about
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Theorised that since they can cause MCEs by corrupting various internal state
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • of the processor, they could potentially get privilege escalation if they
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  could control that corruption with enough precision but since it is not really
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  possible to debug the microarchitectural state of the processor it is not easy
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  to develop such a PoC
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Reported the issue to Intel who released a microcode update to fix this, and
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Tavis released a PoC tool to test for and reproduce the basic issue
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [USN-6486-1] iniParser vulnerability (06:25)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-33461
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Possible NULL ptr deref on crafted input
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-6487-1] Avahi vulnerabilities (06:36)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 5 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-38473
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-38472
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-38471
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-38470
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2023-38469
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Various assertions were able to be triggered through crafted input - so a
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • local attacker on your network could cause your local avahi daemon to crash
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [USN-6489-1] Tang vulnerability (07:09)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2023-1672
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Race condition when generating keys - would write to a file and then set
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • permissions so only root could read them - small time window then where
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              another process could possibly read the key before the more restrictive
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              permissions are set - fixed by setting a restrictive umask before creating the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              file such that it gets created with the restrictive permissions from the start
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [USN-6488-1] strongSwan vulnerability (07:59)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2023-41913
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-6490-1] WebKitGTK vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 2 CVEs addressed in Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-42852
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2023-41983
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-6491-1] Node.js vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 6 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2022-43548
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2022-35256
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2022-32215
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2022-32214
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2022-32213
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2022-32212
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-6493-1, USN-6493-2] hibagent update
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Affecting Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6492-1] Mosquitto vulnerabilities (08:06)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 6 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-28366
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-3592
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-0809
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2021-41039
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2021-34434
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2021-34431
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Multiple memory leaks which can be triggered through crafted packets -> DoS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Excessive CPU usage when parsing a connect request from a client with a large number of user-properties -> DoS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Logic bug - failed to revoke existing subscriptions when a topic subscription
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • is revoked in some cases - would still get notified after the fact - info / privacy leak
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [USN-6498-1] FRR vulnerabilities (08:55)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 4 CVEs addressed in Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-47235
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-47234
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-38407
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-38406
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • More issues discovered by Iggy Frankovic at Amazon - seemingly through fuzzing
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • of frr - UAF, OOB read etc.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [USN-6499-1] GnuTLS vulnerability (09:13)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-5981
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Timing side-channel during RSA-PSK ClientKeyExchange - response time would
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • vary if given malformed ciphertext compared to when using correct PKCS#1 v1.5
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        padding - very similar to historical CVE-2023-0361 ([USN-5901-1] GnuTLS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        vulnerability from Episode 189) - in that case the same issue was fixed for
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        regular RSA - but no-one noticed that the same problematic code existed for
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        this other case as well
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Old adage - if you want to find a vuln, look near other previous vulns - and
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • by the same token, if a project has a vuln reported, go looking to see if
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        perhaps there are other instances of the same vuln in the code base
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Lots of projects have lots of copy-pasted or duplicated code within themselves
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • [USN-6500-1] Squid vulnerabilities (10:20)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 5 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-46848
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-46847
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-46846
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-46728
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-46724
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Back in early 2021 a security audit was performed on Squid which found 55
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • vulnerabilities - these were reported to the upstream project and some CVEs
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            were assigned but a lot went without any fix
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Unfortunately the Squid project is understaffed and hasn’t had the resources to fix all the issues
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Researchers eventually got tired of waiting (approx 900 days so not
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • surprising) - so released details publicly of all their findings
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • https://megamansec.github.io/Squid-Security-Audit/
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • A mix of CVEs and GHSAs have been assigned for some, but not all issues, so
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • some are still unfixed
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • This update contains fixes for all the CVEs which have been assigned so far -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • expect more updates in the future
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [USN-6494-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 9 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-5717
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-45871
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-45862
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-42754
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-39194
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-39193
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-39192
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-39189
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-31085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • [USN-6495-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 2 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-45871
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-31085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6496-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-45871
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-31085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-25775
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • [USN-6497-1] Linux kernel (OEM) vulnerabilities (11:50)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 3 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-5717
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-5178
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-5090
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Logic issue in handling of x2AVIC MSR in KVM nested virtualisation on AMD
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • processors - could allow an attacker in a guest VM to cause a crash on the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            host kernel and hence a DoS against the whole host
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [USN-6502-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 5 CVEs addressed in Jammy (22.04 LTS), Lunar (23.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-5345
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-5090
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-45871
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-31085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-25775
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • UAF in the error handling code for SMB file system - local attacker could use
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • this to escalate privileges
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [USN-6502-2] Linux kernel (Oracle) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 5 CVEs addressed in Lunar (23.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-5345
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-5090
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-45871
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-31085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-25775
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6502-3] Linux kernel (NVIDIA) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 5 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-5345
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-5090
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-45871
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-31085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-25775
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • [USN-6503-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 5 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-5633
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-5345
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-5090
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-4244
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-31085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6516-1] Linux kernel (Intel IoTG) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 5 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-45871
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-3772
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-31085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-31083
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-25775
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • [USN-6520-1] Linux kernel (StarFive) vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 16 CVEs addressed in Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-5345
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-5090
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-45871
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-44466
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-4134
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-4132
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-3867
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-3866
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-3865
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-3863
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-38432
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-38430
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-3772
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-31085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-31083
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-25775
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [LSN-0099-1] Linux kernel vulnerability (12:49)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 16 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-42753
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-42752
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-40283
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-34319
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-31436
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-5197
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-4881
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-4623
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-4622
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-4004
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-3995
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-3777
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-3776
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-3609
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-3567
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2022-3643
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Kernel type
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        22.04
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        20.04
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        18.04
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        16.04
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        14.04
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        aws
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        aws-5.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        aws-5.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        aws-6.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        aws-hwe
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        azure
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        azure-4.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        azure-5.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        azure-6.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        gcp
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        gcp-4.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        gcp-5.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        gcp-5.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        gcp-6.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        generic-4.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        generic-4.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        generic-5.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        generic-5.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        gke
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        gke-5.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        gkeop
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        hwe-6.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ibm
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ibm-5.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ibm-5.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        linux
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        lowlatency-4.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        lowlatency-4.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        lowlatency-5.15
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        lowlatency-5.4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        99.1
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        —
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        canonical-livepatch status
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [USN-6501-1] RabbitMQ vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-46118
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6504-1] tracker-miners vulnerability (13:30)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 1 CVEs addressed in Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-5557
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Hardening of the seccomp sandbox in tracker
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • [USN-6423-2] CUE vulnerability (07:04) from Episode 211 - libcue vuln from
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Kevin Backhouse at Github exploited this weakness in the existing seccomp
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                sandbox to be able to mount their attack for that vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • At the time I discussed how the tracker developers were deploying additional
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • hardening to ensure all threads used by tracker-miners were sandboxed - this
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                is that fix
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [USN-6505-1] nghttp2 vulnerability (15:20)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-44487
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6438-1, USN-6438-2, USN-6427-2] .NET vulnerabilities from Episode 212
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • HTTP/2 Rapid Reset - affects multiple HTTP/2 implementations
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6506-1] Apache HTTP Server vulnerabilities (15:27)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-45802
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-43622
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-31122
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • DoS against HTTP/2 implemtation - very similar to historical Slow Loris
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • attack - fixing required backporting the entire version of the http/2 module
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        from 2.0.10 back to earlier releases - thanks to Marc for this herculean
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        effort
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [USN-6507-1] GlusterFS vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2022-48340
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6509-1] Firefox vulnerabilities (16:17)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 10 CVEs addressed in Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6209
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6208
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6207
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6205
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6204
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6213
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6212
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6211
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6210
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-6206
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 120.0
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • One issue specific to Linux when running under X11 (and I assume XWayland) -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • when copying text using the Selection API, this would also be copied into the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                primary selection (aka where stuff goes when you highlight it and then paste
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                it with middle mouse button)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [USN-6508-1, USN-6508-2] poppler vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 5 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2022-38349
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2022-37052
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2022-37051
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2022-37050
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2020-23804
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6511-1] OpenZFS vulnerability (17:21)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2013-20001
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Oldest CVE patched in a while - was originally reported to openzfs project
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • back in November 2013 - over 10 years ago
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • When sharing over IPv6 would expose to everyone, not just the intended IPv6
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • address but to everyone
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Issue languished, eventually a CVE was assigned in Feb 2021 and then fixed in
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • October 2021
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [USN-6510-1] Apache HTTP Server vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-31122
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6512-1] LibTIFF vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 2 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-3576
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-40090
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • [USN-6513-1] Python vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 2 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-40217
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2022-48564
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6514-1] Open vSwitch vulnerability (18:18)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 1 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-5366
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Failed to properly handle OpenFlow rules for ICMPv6 Neighbour Advertisements -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • in some circumstances would match against the wrong rules and so could allow
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        an attacker who could load certain rules to then cause other traffic to be
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        redirected contrary to expectations - this would then result in an info leak
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [USN-6515-1] Thunderbird vulnerabilities (18:46)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 7 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-6209
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-6208
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-6207
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-6205
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-6204
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-6212
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2023-6206
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 115.5.0
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6517-1] Perl vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 2 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04), Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2023-47038
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2022-48522
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • [USN-6402-2] LibTomMath vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 1 CVEs addressed in Mantic (23.10)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2023-36328
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-6513-2] Python vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 2 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Lunar (23.04)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2023-40217
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2022-48564
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • [USN-6518-1] AFFLIB vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-8050
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • [USN-6519-1] EC2 hibagent update
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Affecting Bionic ESM (18.04 ESM)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • @[email protected], @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 21 min

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              About Ubuntu Security Podcast

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              From the publisher's feed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              A fortnightly podcast talking about the latest developments and updates from the Ubuntu Security team, including a summary of recent security vulnerabilities and fixes as well as a discussion on some…