Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in Linux (Aktualisierung)
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in Linux (Aktualisierung)
ID: USN-7328-3
Distribution: Ubuntu
Plattformen: Ubuntu fail
Datum: Fr, 14. März 2025, 16:29
Referenzen: https://www.cve.org/CVERecord?id=CVE-2024-56672
https://www.cve.org/CVERecord?id=CVE-2025-0927
Applikationen: Linux
Update von: Zwei Probleme in Linux

Originalnachricht

--===============0127520229899996799==
Content-Type: multipart/signed; boundary="=-=-=";
micalg=pgp-sha512; protocol="application/pgp-signature"

--=-=-=
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable


=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Ubuntu Security Notice USN-7328-3
March 14, 2025

linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15
vulnerabilities
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

A security issue affects these releases of Ubuntu and its derivatives:

=2D Ubuntu 22.04 LTS
=2D Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
=2D linux-azure: Linux kernel for Microsoft Azure Cloud systems
=2D linux-azure-fde: Linux kernel for Microsoft Azure CVM cloud systems
=2D linux-azure-5.15: Linux kernel for Microsoft Azure cloud systems
=2D linux-azure-fde-5.15: Linux kernel for Microsoft Azure CVM cloud systems

Details:

Attila Sz=C3=A1sz discovered that the HFS+ file system implementation in the
Linux Kernel contained a heap overflow vulnerability. An attacker could use
a specially crafted file system image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2025-0927)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Block layer subsystem;
(CVE-2024-56672)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
linux-image-5.15.0-1082-azure 5.15.0-1082.91
linux-image-5.15.0-1082-azure-fde 5.15.0-1082.91.1
linux-image-azure-fde-lts-22.04 5.15.0.1082.91.59
linux-image-azure-lts-22.04 5.15.0.1082.80

Ubuntu 20.04 LTS
linux-image-5.15.0-1082-azure 5.15.0-1082.91~20.04.1
linux-image-5.15.0-1082-azure-fde 5.15.0-1082.91~20.04.1.1
linux-image-azure 5.15.0.1082.91~20.04.1
linux-image-azure-cvm 5.15.0.1082.91~20.04.1
linux-image-azure-fde 5.15.0.1082.91~20.04.1.58

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-7328-3
https://ubuntu.com/security/notices/USN-7328-2
https://ubuntu.com/security/notices/USN-7328-1
CVE-2024-56672, CVE-2025-0927

Package Information:
https://launchpad.net/ubuntu/+source/linux-azure/5.15.0-1082.91
https://launchpad.net/ubuntu/+source/linux-azure-fde/5.15.0-1082.91.1
https://launchpad.net/ubuntu/+source/linux-azure-5.15/5.15.0-1082.91~20.0=
4.1
https://launchpad.net/ubuntu/+source/linux-azure-fde-5.15/5.15.0-1082.91~=
20.04.1.1

--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQHZBAEBCgBDFiEEBcMY+nwS2CY71sUWc4vdAqvdlsYFAmfT/iwlHGdpYW1wYW9s
by5mcmVzaS5yb2dsaWFAY2Fub25pY2FsLmNvbQAKCRBzi90Cq92WxgT2DAC2Rba5
dNlF/6Iw3UJcwulvjUGxz/BnFde7tyuvubcx7Cw6rzhMFV3HrgMcEvGMw6raBPKD
M5Cl9vnk/J+nvTCwvGq9SgBvzM+MydGNZwm9eT1Q3JZWLQ2L5ki6FE41jAIHY8Q/
NocmBCGizTJZXFJfUiTccTuFOvkPld5dcGrtrJir46PVfo48hUoJmCE9ONJepf86
dYktNAWNt8F5bVLqzWlbRBZwJpJzCLezcgZMXvvnRzm3nrmnnE1I6u25RQOAs6CA
HMuL67VrDsdfHaaH1toV33u3n3Fvn2ORDtc9Y76Ivmjktc36xa9MpD8+BTqSxm7V
e5/FCNwXtoGAK8G5P7XAimbOj8L1sCw+VmG1+d+QeqWb8iit+/dUZf5VKZdtfBLG
3Z1S2EgNen7t4Kd6Wj5HJyLFtwFIANheErhKvSX3z13CdAK/TDgmcG3PCrZw1Hxe
xxPhRxCaeEHqtGZSlsDOJh8bMBc+6rbxkX+Wv6/VlJRavZONnqi/hQ7lHGg=
=mwEc
-----END PGP SIGNATURE-----
--=-=-=--


--===============0127520229899996799==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline


--===============0127520229899996799==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung