No Image

USN-4185-3: Linux kernel vulnerability and regression

2019-11-14 KENNETH 0

USN-4185-3: Linux kernel vulnerability and regression linux, linux-hwe, linux-oem vulnerability and regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several issues were fixed in the Linux kernel. Software Description linux – Linux kernel linux-oem – Linux kernel for OEM processors linux-hwe – Linux hardware enablement (HWE) kernel Details USN-4185-1 fixed vulnerabilities in the Linux kernel. It was discovered that the kernel fix for CVE-2019-0155 (i915 missing Blitter Command Streamer check) was incomplete on 64-bit Intel x86 systems. Also, the update introduced a regression that broke KVM guests where extended page tables (EPT) are disabled or not supported. This update addresses both issues. We apologize for the inconvenience. Original advisory details: Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Giorgi Maisuradze, Moritz Lipp, [ more… ]

No Image

USN-4183-2: Linux kernel vulnerability

2019-11-14 KENNETH 0

USN-4183-2: Linux kernel vulnerability linux vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Summary Several security issues were fixed in the Linux kernel. Software Description linux – Linux kernel Details USN-4183-1 fixed vulnerabilities in the Linux kernel. It was discovered that the kernel fix for CVE-2019-0155 (i915 missing Blitter Command Streamer check) was incomplete on 64-bit Intel x86 systems. This update addresses the issue. We apologize for the inconvenience. Original advisory details: Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Giorgi Maisuradze, Moritz Lipp, Michael Schwarz, Daniel Gruss, and Jo Van Bulck discovered that Intel processors using Transactional Synchronization Extensions (TSX) could expose memory contents previously stored in microarchitectural buffers to a malicious process that is executing on the same CPU core. A local attacker could use [ more… ]

No Image

USN-4184-2: Linux kernel vulnerability and regression

2019-11-14 KENNETH 0

USN-4184-2: Linux kernel vulnerability and regression linux, linux-hwe, linux-oem-osp1 vulnerability and regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Summary Several issues were fixed in the Linux kernel. Software Description linux – Linux kernel linux-hwe – Linux hardware enablement (HWE) kernel linux-oem-osp1 – Linux kernel for OEM processors Details USN-4184-1 fixed vulnerabilities in the Linux kernel. It was discovered that the kernel fix for CVE-2019-0155 (i915 missing Blitter Command Streamer check) was incomplete on 64-bit Intel x86 systems. Also, the update introduced a regression that broke KVM guests where extended page tables (EPT) are disabled or not supported. This update addresses both issues. We apologize for the inconvenience. Original advisory details: Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Giorgi Maisuradze, Moritz Lipp, Michael [ more… ]

No Image

USN-4190-1: libjpeg-turbo vulnerabilities

2019-11-13 KENNETH 0

USN-4190-1: libjpeg-turbo vulnerabilities libjpeg-turbo vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in libjpeg-turbo. Software Description libjpeg-turbo – library for handling JPEG files Details It was discovered that libjpeg-turbo incorrectly handled certain BMP images. An attacker could possibly use this issue to expose sensitive information. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-14498) It was discovered that libjpeg-turbo incorrectly handled certain JPEG images. An attacker could possibly use this issue to expose sensitive information. This issue only affected Ubuntu 19.04. (CVE-2018-19664) It was discovered that libjpeg-turbo incorrectly handled certain BMP images. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 19.04. (CVE-2018-20330) It was discovered that libjpeg-turbo incorrectly handled certain JPEG [ more… ]

No Image

USN-4189-1: DPDK vulnerability

2019-11-13 KENNETH 0

USN-4189-1: DPDK vulnerability dpdk vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 19.04 Ubuntu 18.04 LTS Summary DPDK could be made to consume resources if it received specially crafted input. Software Description dpdk – set of libraries for fast packet processing Details Jason Wang discovered that DPDK incorrectly handled certain messages. An attacker in a malicious container could possibly use this issue to cause DPDK to leak resources, resulting in a denial of service. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 dpdk – 18.11.4-1ubuntu0.19.10.1 Ubuntu 19.04 dpdk – 18.11.4-1ubuntu0.19.04.1 Ubuntu 18.04 LTS dpdk – 17.11.8-0~ubuntu18.04.2 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update [ more… ]