No Image

Introducing Surface Laptop Go 2

2022-06-01 KENNETH 0

Introducing Surface Laptop Go 2 Available for preorder today, Surface Laptop Go 2 offers updated features and specs that light up the diverse set of experiences that have come to define the Windows 11 PC, all for the incredible starting price of $599. When we first introduced Surface Laptop Go in 2020, the world was navigating profound changes in the way each of us connects both to people and experiences. The Windows PC became more essential than ever for work, school, play, and social connection. Through innovative hardware and software experiences, our product makers at Surface created something that exceeded expectations and was delightful to use. Whether we were browsing the web, managing tasks across work, school and life, or relaxing with a favorite TV show, Surface Laptop Go brought the premium PC experience that we expect from Surface to [ more… ]

No Image

LSN-0086-1: Kernel Live Patch Security Notice

2022-06-01 KENNETH 0

LSN-0086-1: Kernel Live Patch Security Notice It was discovered that a race condition existed in the network scheduling subsystem of the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.(CVE-2021-39713) Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the Linux kernel did not properly restrict access to the cgroups v1 release_agent feature. A local attacker could use this to gain administrative privileges.(CVE-2022-0492) It was discovered that the network traffic control implementation in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.(CVE-2022-1055) Bing-Jhong Billy Jheng discovered that the io_uring subsystem in the Linux kernel contained in integer overflow. A local attacker could use this [ more… ]

No Image

USN-5457-1: WebKitGTK vulnerabilities

2022-06-01 KENNETH 0

USN-5457-1: WebKitGTK vulnerabilities A large number of security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Source: USN-5457-1: WebKitGTK vulnerabilities

No Image

USN-5443-2: Linux kernel vulnerabilities

2022-06-01 KENNETH 0

USN-5443-2: Linux kernel vulnerabilities Kyle Zeng discovered that the Network Queuing and Scheduling subsystem of the Linux kernel did not properly perform reference counting in some situations, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-29581) Jann Horn discovered that the Linux kernel did not properly enforce seccomp restrictions in some situations. A local attacker could use this to bypass intended seccomp sandbox restrictions. (CVE-2022-30594) Source: USN-5443-2: Linux kernel vulnerabilities

No Image

USN-5442-2: Linux kernel vulnerabilities

2022-06-01 KENNETH 0

USN-5442-2: Linux kernel vulnerabilities Kyle Zeng discovered that the Network Queuing and Scheduling subsystem of the Linux kernel did not properly perform reference counting in some situations, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-29581) Bing-Jhong Billy Jheng discovered that the io_uring subsystem in the Linux kernel contained in integer overflow. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-1116) Jann Horn discovered that the Linux kernel did not properly enforce seccomp restrictions in some situations. A local attacker could use this to bypass intended seccomp sandbox restrictions. (CVE-2022-30594) Source: USN-5442-2: Linux kernel vulnerabilities