Ubuntu releases important update will fix nine vulnerabilities

Canonical has released a new Linux kernel security update for all supported Ubuntu operating systems, addressing a total of nine vulnerabilities discovered by various researchers.

The newly patched Linux kernel vulnerabilities affect Ubuntu 17.10 (Artful Aardvark), Ubuntu 17.04 (Zesty Zapus), Ubuntu 16.04 LTS (Xenial Xerus), Ubuntu 14.04 LTS (Trusty Tahr) and Ubuntu 12.04 (Precise Pangolin) ESM (Extended Security Maintenance) and All official derivatives, including Kubuntu, Lubuntu, etc.

They include the post-release vulnerabilities discovered by Mohamed Ghannam in the Netlink subsystem (XFRM) of the Linux kernel, and the Linux kernel’s inability to properly handle large page memory copies (CoW), which affects all supported Ubuntu versions and their derivatives. Version.

The Linux kernel's associative array implementation is also a problem, it sometimes does not properly handle adding a new entry, and an out-of-bounds reading found in the GTCO digitizer USB driver of the Linux kernel, which affects Ubuntu 17.10 and Ubuntu 16.04 LTS versions.

The contention in the Linux kernel driver subsystem has been fixed. This update only affects Ubuntu 17.04. The updated address solves the null pointer reference error in the PowerPC KVM implementation of the Linux kernel and the contention in the key management subsystem, and only affects Ubuntu 17.10.

It is recommended that all Ubuntu users update and install as soon as possible

Andrey Konovalov discovered another security vulnerability in the USB subsystem of the Linux kernel. The subsystem could not correctly verify the USB BOS metadata, thus affecting the Ubuntu 17.10 machine and allowing attackers with physical access to pass a denial of service (DoS attack). ) To crash the system.

Finally, this update supplements a security vulnerability discovered by Eric Biggers in the key management subsystem of the Linux kernel. This vulnerability cannot properly restrict the addition of keys that already exist but have not been instantiated, which may cause local attackers to execute arbitrary code. Or crash a vulnerable system.

Canonical urges all Ubuntu users to immediately update their systems to the new kernel version, namely linux-image 4.13.0.19.22 for Ubuntu 17.10, Linux-image-raspi2 4.13.0.1008.6 for Ubuntu 17.10, and Raspberry Pi 2, linux-image Ubuntu 17.04 is 4.10.0.42.46, Ubuntu 17.04 is Raspberry Pi 2 is linux-image-raspi2 4.10.0.1023.24.

In addition, Ubuntu 16.04 LTS users need to update their kernel to linux-image 4.4.0.103.108 on 64-bit and 32-bit machines, and update Ubuntu 16.04 LTS for Raspberry Pi 2 users to linux-image-raspi2 4.4.0.1079.79 , And users of Ubuntu 14.04 LTS to linux-image-3.13.0-137-generic 3.13.0-137.186. Ubuntu 16.04.3 LTS, Ubuntu 14.04.5 LTS and Ubuntu 12.04 ESM users can also use the updated HWE kernel.

Recommended Posts

Ubuntu releases important update will fix nine vulnerabilities