Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in Linux
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in Linux
ID: USN-4318-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS
Datum: Di, 7. April 2020, 07:20
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8992
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8428
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8834
Applikationen: Linux

Originalnachricht


--===============8701649092848492209==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="EVF5PPMfhYS0aIcm"
Content-Disposition: inline


--EVF5PPMfhYS0aIcm
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-4318-1
April 06, 2020

linux, linux-hwe vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux: Linux kernel
- linux-hwe: Linux hardware enablement (HWE) kernel

Details:

Al Viro discovered that the vfs layer in the Linux kernel contained a use-
after-free vulnerability. A local attacker could use this to cause a denial
of service (system crash) or possibly expose sensitive information (kernel
memory). (CVE-2020-8428)

Gustavo Romero and Paul Mackerras discovered that the KVM implementation in
the Linux kernel for PowerPC processors did not properly keep guest state
separate from host state. A local attacker in a KVM guest could use this to
cause a denial of service (host system crash). (CVE-2020-8834)

Shijie Luo discovered that the ext4 file system implementation in the Linux
kernel did not properly check for a too-large journal size. An attacker
could use this to construct a malicious ext4 image that, when mounted,
could cause a denial of service (soft lockup). (CVE-2020-8992)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
linux-image-4.15.0-96-generic 4.15.0-96.97
linux-image-4.15.0-96-generic-lpae 4.15.0-96.97
linux-image-4.15.0-96-lowlatency 4.15.0-96.97
linux-image-generic 4.15.0.96.87
linux-image-generic-lpae 4.15.0.96.87
linux-image-lowlatency 4.15.0.96.87
linux-image-powerpc-e500mc 4.15.0.96.87
linux-image-powerpc-smp 4.15.0.96.87
linux-image-powerpc64-emb 4.15.0.96.87
linux-image-powerpc64-smp 4.15.0.96.87
linux-image-virtual 4.15.0.96.87

Ubuntu 16.04 LTS:
linux-image-4.15.0-96-generic 4.15.0-96.97~16.04.1
linux-image-4.15.0-96-generic-lpae 4.15.0-96.97~16.04.1
linux-image-4.15.0-96-lowlatency 4.15.0-96.97~16.04.1
linux-image-generic-hwe-16.04 4.15.0.96.104
linux-image-generic-lpae-hwe-16.04 4.15.0.96.104
linux-image-lowlatency-hwe-16.04 4.15.0.96.104
linux-image-oem 4.15.0.96.104
linux-image-virtual-hwe-16.04 4.15.0.96.104

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4318-1
CVE-2020-8428, CVE-2020-8834, CVE-2020-8992

Package Information:
https://launchpad.net/ubuntu/+source/linux/4.15.0-96.97
https://launchpad.net/ubuntu/+source/linux-hwe/4.15.0-96.97~16.04.1


--EVF5PPMfhYS0aIcm
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEpgY7tWAjCaQ8jrvULwmejQBegfQFAl6LlQgACgkQLwmejQBe
gfSeRg/+LspaJ2rIj26KFXjpg9dm6nI7uiwxz7DsMtRCPs31mginhsw7JSOzgNj9
R6PjdEhRAheev5g1xS4RQmpQv5MbjXUsDPf13GgASpa76WNC5KRCo5H8/cAN+nEy
dNYrlsuCpNanxrW+QGshrTFdBZ58aEYfnM3/zrfWW3JM9mzyI0EZOihI9XXKN1rk
r3eKHQV1xHZ1Ge58r6ECvDKEVvav9KBNtPI0iyBUFJPko859hncOPDbFxcBQ3h2u
P+4ZmrPj2QrzURKarzO4Vxz+Zjt/XN2qHhCNVbvcvhfW+oiKZEo0X2DATIpFpRsH
IWKPl4YDuoAegFpYDk3M4/AjXVxv6z6a8Ma+3NpBtDoRHPq7gFYxoWpLxasiPWp0
oDr0oXMxlERCvEVxN65IbH+N6bP2qKYtS9toJs0mUnOceymMMY7oMHW6YVOIDqzq
P6ISlDZPSRRsr/NIrB6tyUFD9M3p6yzv1Onz4P9JDk9hp2uB8aRGTjJuZpNEmb2X
EJoKL0I7JAHMtQZfJSeLDh95/mOHMS3QNpwFnOFabv+a1l5TReqbtr7z2UJbZr0e
Bgy46EDfV+4vfwV5Ua3PJah6CAGWTWMIqRvx7b5NPjnBfPcCwMl9qy+c75H1q3n4
bZUZM6razJUiH5zO2cUc7rVj+3vahifBbBiC9ika4uec6eUbTbY=
=M4nb
-----END PGP SIGNATURE-----

--EVF5PPMfhYS0aIcm--


--===============8701649092848492209==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung