Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in Linux (Aktualisierung)
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in Linux (Aktualisierung)
ID: USN-7028-2
Distribution: Ubuntu
Plattformen: Ubuntu 14.04 LTS
Datum: Do, 17. Oktober 2024, 22:01
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52527
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26851
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38570
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-42154
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26733
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40902
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26880
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-42160
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26677
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39495
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38583
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52809
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27398
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48791
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-42228
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-42224
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48863
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26984
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26651
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39480
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27437
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47188
Applikationen: Linux
Update von: Mehrere Probleme in Linux

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============2827642120015254822==
Content-Language: en-US
Content-Type: multipart/signed; micalg=pgp-sha256;
protocol="application/pgp-signature";
boundary="------------jq9HlTvDllqXsNtb9WSZKoeu"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--------------jq9HlTvDllqXsNtb9WSZKoeu
Content-Type: multipart/mixed;
boundary="------------0B15CjkRiGv10gh8i5dzB6IA";
protected-headers="v1"
From: Rodrigo Figueiredo Zaiden <rodrigo.zaiden@canonical.com>
Reply-To: "Security@Ubuntu.com" <Security@ubuntu.com>
To: ubuntu-security-announce@lists.ubuntu.com
Message-ID: <42f5c698-4238-419d-bbcd-96b43bbb7ea8@canonical.com>
Subject: [USN-7028-2] Linux kernel (Azure) vulnerabilities

--------------0B15CjkRiGv10gh8i5dzB6IA
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: base64

==========================================================================
Ubuntu Security Notice USN-7028-2
October 17, 2024

linux-azure vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-azure: Linux kernel for Microsoft Azure Cloud systems

Details:

It was discovered that the JFS file system contained an out-of-bounds read
vulnerability when printing xattr debug information. A local attacker could
use this to cause a denial of service (system crash).

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- GPU drivers;
- Greybus drivers;
- Modular ISDN driver;
- Multiple devices driver;
- Network drivers;
- SCSI drivers;
- VFIO drivers;
- F2FS file system;
- GFS2 file system;
- JFS file system;
- NILFS2 file system;
- Kernel debugger infrastructure;
- Bluetooth subsystem;
- IPv4 networking;
- L2TP protocol;
- Netfilter;
- RxRPC session sockets;
(CVE-2024-42154, CVE-2023-52527, CVE-2024-26733, CVE-2024-42160,
CVE-2021-47188, CVE-2024-38570, CVE-2024-26851, CVE-2024-26984,
CVE-2024-26677, CVE-2024-39480, CVE-2024-27398, CVE-2022-48791,
CVE-2024-42224, CVE-2024-38583, CVE-2024-40902, CVE-2023-52809,
CVE-2024-39495, CVE-2024-26651, CVE-2024-26880, CVE-2024-42228,
CVE-2024-27437, CVE-2022-48863)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS
linux-image-4.15.0-1181-azure 4.15.0-1181.196~14.04.1
Available with Ubuntu Pro
linux-image-azure 4.15.0-1181.196~14.04.1
Available with Ubuntu Pro

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-7028-2
https://ubuntu.com/security/notices/USN-7028-1
CVE-2021-47188, CVE-2022-48791, CVE-2022-48863, CVE-2023-52527,
CVE-2023-52809, CVE-2024-26651, CVE-2024-26677, CVE-2024-26733,
CVE-2024-26851, CVE-2024-26880, CVE-2024-26984, CVE-2024-27398,
CVE-2024-27437, CVE-2024-38570, CVE-2024-38583, CVE-2024-39480,
CVE-2024-39495, CVE-2024-40902, CVE-2024-42154, CVE-2024-42160,
CVE-2024-42224, CVE-2024-42228

--------------0B15CjkRiGv10gh8i5dzB6IA--

--------------jq9HlTvDllqXsNtb9WSZKoeu
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature.asc"

-----BEGIN PGP SIGNATURE-----

wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmcRSsAFAwAAAAAACgkQZ0GeRcM5nt2B
iQf9Hs8dvaSin241pUNI5rh1sSpFxW+tPzASPZQQre7KlkVwmKNh8LfQqTQV5wjB3MHroOnf6Zzt
cbpSQys9LrrA6lsT+yGZ6d2ed/hf8c+TSIRz9WMSEX1kmndCkjHevye/NrGZ2gKxHKtH+3FcRvtJ
rSakQO3oliejo21wn05XlSjgnSNjY39BlSyS9r6wy3knMAx2ZDl6UNCxlxBJygRqXtOPVYIjq4Bk
n5gKWomt01VfJNWjU4JMXqUpecuKIZDf0fAIWiKZ9q47MJFST2lJfzF8t9X0zhIqQNVwpcUr9Ty/
gL+mUl9VNuWJjZci51nIVLRkySmla8X5PLW/IS8Exw==
=zjJa
-----END PGP SIGNATURE-----

--------------jq9HlTvDllqXsNtb9WSZKoeu--


--===============2827642120015254822==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

Cg==

--===============2827642120015254822==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung