TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Ubuntu Security Podcast

    A fortnightly podcast talking about the latest developments and updates from the Ubuntu Security team, including a summary of recent security vulnerabilities and fixes as well as a discussion on some of the goings on in the wider Ubuntu Security community.

    Advertise

    Copyright: © Copyright 2019 Canonical

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Episode 123 Jul 09, 2021
    Show notes

    Overview

    Is npm audit more harm than good? Plus this week we look at security updates for DjVuLibre, libuv, PHP and more.

    This week in Ubuntu Security Updates

    8 unique CVEs addressed

    [USN-4905-2] X.Org X Server vulnerability [00:42]

    • 1 CVEs addressed in Trusty ESM (14.04 ESM)
      • CVE-2021-3472
    • Episode 112 - Local user (X client) could crash the server via Xinput extension and ChangeFeedbackControl request - integer underflow -> heap buffer overflow

    [USN-5005-1] DjVuLibre vulnerability [01:26]

    • 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
      • CVE-2021-3630
    • OOB write via crafted djvu file -> crash -> DoS, RCE

    [USN-5007-1] libuv vulnerability [01:53]

    • 1 CVEs addressed in Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-22918
    • Async event handling library - used by nodejs and others - supports async handling TCP/UDP sockets, DNS resolution, file system operations etc
    • OOB read when converting strings to ASCII -> can be triggered via calls to uv_getaddrinfo() which are done by clients who handle TCP/UDP sockets async (ie nodejs, Julia,, BIND etc)

    [USN-5006-1] PHP vulnerabilities [03:04]

    • 5 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-21705
      • CVE-2021-21704
      • CVE-2021-21702
      • CVE-2020-7071
      • CVE-2020-7068
    • UAF in PHAR archive handling - generally these are trusted so low impact
    • mishandling of URLs with embedded passwords - unspecified impact but could misparse the URL and cause unwanted behaviour
    • Mishandling of XML when processing SOAP server responses -> NULL ptr deref (so malicious server could trigger a crash) -> DoS
    • Ability to bypass Sever Side Request Forgery (SSRF) protections in FILTER_VALIDATE_URL

    Goings on in Ubuntu Security Community

    npm audit broken by design? [04:13]

    • https://overreacted.io/npm-audit-broken-by-design/

    Ubuntu Security Podcast on break for next 2 weeks [07:56]

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 122 Jul 02, 2021
    Show notes

    Overview

    This week we look at some new Linux kernel security features including the Landlock LSM and Core Scheduling plus we cover security updates for RabbitMQ, Ceph, Thunderbird and more.

    This week in Ubuntu Security Updates

    46 unique CVEs addressed

    [USN-5004-1] RabbitMQ vulnerabilities [00:44]

    • 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-22116
      • CVE-2019-11287
    • AMQP server written in Erlang
    • Possible to cause the server to consume excessive memory by sending large values in the X-Reason HTTP header - resource exhaustion - DoS
    • Possible infinite loop - failed to perform sufficient validation - DoS

    [USN-4998-1] Ceph vulnerabilities [01:38]

    • 7 CVEs addressed in Focal (20.04 LTS), Groovy (20.10)
      • CVE-2021-3531
      • CVE-2021-3524
      • CVE-2021-3509
      • CVE-2021-20288
      • CVE-2020-27839
      • CVE-2020-27781
      • CVE-2020-25678
    • May log passwords in clear
    • Exposure of user credentials to unprivileged users in particular configurations
    • 2 different XSS in ceph-dashboard
    • Possible to authenticate as another user since could reuse session keys
    • Crash radosgw through malicious GET requests with crafted swift URLs -> DoS

    [USN-4995-2] Thunderbird vulnerabilities [02:22]

    • 20 CVEs addressed in Bionic (18.04 LTS)
      • CVE-2021-29957
      • CVE-2021-29956
      • CVE-2021-29949
      • CVE-2021-29948
      • CVE-2021-24002
      • CVE-2021-23995
      • CVE-2021-23993
      • CVE-2021-23992
      • CVE-2021-23991
      • CVE-2021-23984
      • CVE-2021-29967
      • CVE-2021-29946
      • CVE-2021-29945
      • CVE-2021-23999
      • CVE-2021-23998
      • CVE-2021-23994
      • CVE-2021-23987
      • CVE-2021-23982
      • CVE-2021-23981
      • CVE-2021-23961
    • Episode 121
    • 78.11.0

    [USN-5000-2] Linux kernel (KVM) vulnerabilities [02:48]

    • 15 CVEs addressed in Focal (20.04 LTS)
      • CVE-2021-3506
      • CVE-2021-33034
      • CVE-2021-32399
      • CVE-2021-31829
      • CVE-2021-23134
      • CVE-2021-23133
      • CVE-2020-26147
      • CVE-2020-26145
      • CVE-2020-26141
      • CVE-2020-26139
      • CVE-2020-24588
      • CVE-2020-24587
      • CVE-2020-24586
      • CVE-2021-33200
      • CVE-2021-3609
    • Episode 121
    • KVM kernel for 20.04 LTS
    • 2 high priority privesc issues fixed - CAN BCM UAFs, eBPF OOB write - plus various others too

    [USN-4997-2] Linux kernel (KVM) vulnerabilities

    • 17 CVEs addressed in Hirsute (21.04)
      • CVE-2021-3543
      • CVE-2021-3506
      • CVE-2021-33034
      • CVE-2021-32399
      • CVE-2021-31829
      • CVE-2021-31440
      • CVE-2021-23134
      • CVE-2021-23133
      • CVE-2020-26147
      • CVE-2020-26145
      • CVE-2020-26141
      • CVE-2020-26139
      • CVE-2020-24588
      • CVE-2020-24587
      • CVE-2020-24586
      • CVE-2021-33200
      • CVE-2021-3609

    Goings on in Ubuntu Security Community

    Landlock released in 5.13 kernel [03:49]

    • Allows unprivileged processes to sandbox themselves - currently only supports file paths - so can specify read/write of files/dirs etc
    • Took 34 revisions of the patch set and it evolved significantly over time - was originally based on attaching BPF programs to LSM hooks but given how fraught unprivileged BPF has been this was NACKd and instead went with a new approach based on a custom API with brand new system calls to support it
    • API is quite low-level compared to say how AppArmor policy is specified so will be interesting to see if there becomes a liblandlock in the future to make this kind of thing easier (cf. libseccomp for doing seccomp BPF programs etc)
    • https://lwn.net/Articles/859908/
    • https://landlock.io/

    Core Scheduling merged for 5.14 kernel [06:43]

    • SMT siblings share lots of microarchitectural state like L1D cache etc - various micro-arch attacks could only be mitigated across different SMT cores - so processes which shared the same core could snoop on each other (eg. L1TF - in the context of virtualisation, a malicious guest VM could snoop on the L1D contents of another VM on the same SMT core) - so the only option was to disable SMT which brings a big performance hit
    • Solution is core scheduling - ie. make the schedular aware of and respect SMT threads on the same core
    • Tag processes via cgroups - this defines the trust boundaries - processes in the same tagged cgroup share a trust boundary and can be scheduled on sibling SMT cores - and by default all processes are in the same group
    • Uses prctl() to allow setting / copying these - and can only set these on processes which you can ptrace
    • https://lwn.net/Articles/820321/
    • https://www.phoronix.com/scan.php?page=news_item&px=Core-Scheduling-Linux-Close

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 121 Jun 25, 2021
    Show notes

    Overview Ubuntu One opens up two-factor authentication for all, plus we cover security updates for Nettle, libxml2, GRUB2, the Linux kernel and more. This week in Ubuntu Security Updates 73 unique CVEs addressed [USN-4989-2] BlueZ vulnerabilities [00:57] 2 CVEs addressed in Xenial ESM (16.04 ESM) CVE-2020-27153 CVE-2020-26558 Episode 120 - bluetooth spec issue around pairing takeover plus a possible double-free in gattool that is likely quite hard to exploit due to time window race between the two free() calls [USN-4990-1] Nettle vulnerabilities [01:27] 2 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04) CVE-2018-16869 CVE-2021-3580 Low level crypto library used by lots of packages - chrony, dnsmasq, lighttpd, qemu, squid, supertuxkart Last covered just a few weeks ago in Episode 112 - is someone taking a closer look at this library? Bleichenbacher type side-channel base on a padding oracle attack in endian conversion of RSA decrypted PKCS#1 v1.5 data - requires to run a process on the same physical core as the victim - but could then allow the plaintext to be extracted RSA algo possible crash which is able to be triggered on decryption of manipulated ciphertext Changes required for both of these are too intrusive to backport for the older releases (e.g. 16.04 ESM) so suggest to upgrade to a newer Ubuntu release if you are using nettle on these older releases and are concerned about possible attacks [USN-4991-1] libxml2 vulnerabilities [03:08] 8 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04) CVE-2021-3541 CVE-2021-3537 CVE-2021-3518 CVE-2021-3516 CVE-2021-3517 CVE-2020-24977 CVE-2019-20388 CVE-2017-8872 Crafted XML could possibly trigger crash -> DoS or RCE [USN-4992-1] GRUB 2 vulnerabilities [03:33] 6 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10) CVE-2021-20233 CVE-2021-20225 CVE-2020-27779 CVE-2020-27749 CVE-2020-25632 CVE-2020-14372 Episode 106 - BootHole 2021 updates published to the security pocket Vulns included the ability to load ACPI tables, UAF in rmmod, buffer overflow in command-line parser, cutmem command boot locking bypass, heap buffer overflow in option parser and menu rendering OOB write -> RCE —>@@ all could lead to a bypass of secure boot protections Includes one grub - ie. same grub efi binary used across all recent Ubuntu releases https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypass2021 [USN-4993-1] Dovecot vulnerabilities [05:13] 2 CVEs addressed in Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04) CVE-2021-33515 CVE-2021-29157 STARTTLS plaintext command injection vuln via SMTP, plus if a local attacker could write files to the disk, they could supply their own keys to validate their own supplied JSON Web Token and hence login as any other user and then access their emails if using OAUTH2 [USN-4994-1, USN-4994-2] Apache HTTP Server vulnerabilities [05:58] 5 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04) CVE-2021-30641 CVE-2021-26691 CVE-2021-26690 CVE-2020-35452 CVE-2020-13950 Various DoS issues where under certain configurations an attacker could issue particular requests and trigger various crashes in Apache [USN-4996-1, USN-4996-2] OpenEXR vulnerabilities [06:16] 5 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS) CVE-2021-3605 CVE-2021-3598 CVE-2021-26260 CVE-2021-23215 CVE-2021-20296 Usual mix of issues for a library which is written in memory unsafe language and handling complex image formats etc Courtesy of OSS-Fuzz [USN-4995-1] Thunderbird vulnerabilities [06:48] 20 CVEs addressed in Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04) CVE-2021-29957 CVE-2021-29956 CVE-2021-29949 CVE-2021-29948 CVE-2021-24002 CVE-2021-23995 CVE-2021-23993 CVE-2021-23992 CVE-2021-23991 CVE-2021-23984 CVE-2021-29967 CVE-2021-29946 CVE-2021-29945 CVE-2021-23999 CVE-2021-23998 CVE-2021-23994 CVE-2021-23987 CVE-2021-23982 CVE-2021-23981 CVE-2021-23961 78.11.0 - usual mix of untrusted content/web framework issues inherited from Firefox, plus fixes for OpenPGP key handling, message signature TOCTTOU-type condition due to writing out signatures to disk that then could be replaced before being verified, UX issue in display of inline signed/encrypted messages with additional unprotected parts [USN-4997-1] Linux kernel vulnerabilities [08:22] 17 CVEs addressed in Hirsute (21.04) CVE-2021-3543 CVE-2021-3506 CVE-2021-33034 CVE-2021-32399 CVE-2021-31829 CVE-2021-31440 CVE-2021-23134 CVE-2021-23133 CVE-2020-26147 CVE-2020-26145 CVE-2020-26141 CVE-2020-26139 CVE-2020-24588 CVE-2020-24587 CVE-2020-24586 CVE-2021-33200 CVE-2021-3609 5.11 Basically the same set of fixes for all kernels, including a couple quite interesting ones: eBPF verifier bypass provides OOB write primitive, could allow a local attacker to perform code execution in the kernel -> privesc Race condition in CAN BCM networking protocol -> various UAFs -> code execution as well Plus others -> Wifi FragAttack fixes, other eBPF verifier fixes, SCTP race condition -> UAF etc [USN-4999-1] Linux kernel vulnerabilities [09:51] 17 CVEs addressed in Focal (20.04 LTS), Groovy (20.10) CVE-2021-31829 CVE-2021-31440 CVE-2021-29155 CVE-2021-23133 CVE-2020-26147 CVE-2020-26145 CVE-2020-26141 CVE-2020-26139 CVE-2020-25673 CVE-2020-25672 CVE-2020-25671 CVE-2020-25670 CVE-2020-24588 CVE-2020-24587 CVE-2020-24586 CVE-2021-33200 CVE-2021-3609 5.8 (groovy, focal hwe) [USN-5000-1] Linux kernel vulnerabilities [10:08] 15 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS) CVE-2021-3506 CVE-2021-33034 CVE-2021-32399 CVE-2021-31829 CVE-2021-23134 CVE-2021-23133 CVE-2020-26147 CVE-2020-26145 CVE-2020-26141 CVE-2020-26139 CVE-2020-24588 CVE-2020-24587 CVE-2020-24586 CVE-2021-33200 CVE-2021-3609 5.4 (focal, bionic hwe) [USN-5001-1] Linux kernel (OEM) vulnerabilities 15 CVEs addressed in Focal (20.04 LTS) CVE-2021-3543 CVE-2021-3506 CVE-2021-33034 CVE-2021-32399 CVE-2021-31440 CVE-2021-23134 CVE-2021-23133 CVE-2020-26147 CVE-2020-26145 CVE-2020-26141 CVE-2020-26139 CVE-2020-24588 CVE-2020-24587 CVE-2020-24586 CVE-2021-3609 5.10 [USN-5002-1] Linux kernel (HWE) vulnerability [10:23] 1 CVEs addressed in Bionic (18.04 LTS) CVE-2021-3609 5.3 CAN BCM [USN-5003-1] Linux kernel vulnerabilities [10:35] 3 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS) CVE-2021-23133 CVE-2021-3600 CVE-2021-3609 4.15 (bionic, xenial esm hwe, trusty esm azure) CAN BCM and eBPF verifier OOB write Goings on in Ubuntu Security Community 2FA coming to Ubuntu One [11:04] https://ubuntu.com/blog/two-factor-authentication-coming-to-ubuntu-one Used for access to discourse.ubuntu.com, Launchpad, ubuntuforums, publishers on the Snap Store etc Allows to use a phone / desktop TOTP app as second factor, or Yubikey TOTP etc Has actually been supported since 2014 but only available to a beta testing group plus for all Canonical employees, due to challenges in account recovery Since Ubuntu One purposefully doesn’t store any real identifying information (name, email, username) we can’t easily verify account holders if they lose the 2FA device The intent is to be robust even in the event that a users email address is compromised Now have a comprehensive code recovery experience including printable backup codes and mechanisms in place to encourage users to exercise backup codes so that users can feel confident in using these if they need to (ie where did I put my backup codes again..?) Get in contact security@ubuntu.com #ubuntu-security on the Libera.Chat IRC network ubuntu-hardened mailing list Security section on discourse.ubuntu.com @ubuntu_sec on twitter

    Full show notes at the publisher

    Episode 120 Jun 18, 2021
    Show notes

    Overview

    In this week’s episode we look at how to get media coverage for your shiny new vulnerability, plus we cover security updates for ExifTool, ImageMagick, BlueZ and more.

    This week in Ubuntu Security Updates

    49 unique CVEs addressed

    [USN-4986-2] rpcbind vulnerability [00:44]

    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM)
      • CVE-2017-8779
    • Episode 119 (bionic) - memory leak on crafted requests

    [USN-4986-3, USN-4986-4] rpcbind regression [01:11]

    • Affecting Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS)
    • Original fix missed follow-up patches to correct problems in the upstream fix - required multiple other bits to work correctly

    [USN-4971-2] libwebp vulnerabilities [01:34]

    • 10 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM)
      • CVE-2020-36331
      • CVE-2020-36330
      • CVE-2020-36329
      • CVE-2020-36328
      • CVE-2018-25014
      • CVE-2018-25013
      • CVE-2018-25012
      • CVE-2018-25011
      • CVE-2018-25010
      • CVE-2018-25009
    • Episode 118

    [USN-4987-1] ExifTool vulnerability [01:50]

    • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-22204
    • Was originally reported to gitlab via hackerone as exiftool is used on image uploads to redact image metadata etc - they coordinated the fix with exiftool upstream. RCE when parsing a malicious DjVu image - uses perl to parse DjVu and in doing so it eval’s certain constructs without properly validating them

    [USN-4988-1] ImageMagick vulnerabilities [03:17]

    • 34 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10)
      • CVE-2021-20176
      • CVE-2020-27776
      • CVE-2020-27775
      • CVE-2020-27774
      • CVE-2020-27773
      • CVE-2020-27772
      • CVE-2020-27771
      • CVE-2020-27770
      • CVE-2020-27769
      • CVE-2020-27768
      • CVE-2020-27767
      • CVE-2020-27766
      • CVE-2020-27765
      • CVE-2020-27764
      • CVE-2020-27763
      • CVE-2020-27762
      • CVE-2020-27761
      • CVE-2020-27760
      • CVE-2020-27759
      • CVE-2020-27758
      • CVE-2020-27757
      • CVE-2020-27756
      • CVE-2020-27755
      • CVE-2020-27754
      • CVE-2020-27753
      • CVE-2020-27751
      • CVE-2020-27750
      • CVE-2020-25676
      • CVE-2020-25675
      • CVE-2020-25674
      • CVE-2020-25666
      • CVE-2020-25665
      • CVE-2020-19667
      • CVE-2017-14528
    • every ~30 weeks we seem to have another ImageMagick update - so that time again ;)
    • DoS, RCE etc

    [USN-4989-1] BlueZ vulnerabilities [03:56]

    • 3 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-3588
      • CVE-2020-27153
      • CVE-2020-26558
    • 1 bluetooth core specification issue - during pairing a nearby attacker could interpose on the pairing process and hence complete the pairing instead of the intended device
    • 2 issues in bluez code itself
      • double free (UAF) + OOB read

    Goings on in Ubuntu Security Community

    How to get media coverage for your Linux vulnerabilities [04:48]

    • In Episode 119 covered an update for polkit - the following day Github published a blog post with significant details of the vuln - then we saw a heap of media coverage
      • https://www.theregister.com/2021/06/11/linux_polkit_package_patched/
      • https://www.zdnet.com/article/nasty-linux-systemd-root-level-security-bug-revealed-and-patched/
    • Why did this vuln get so much coverage when lots of others don’t?
      • Great technical detail from a reputable and popular source (github)
      • Very clearly written and easy to understand
        • Is a simple logic error that can be triggered via a race-condition in a privileged daemon
        • PoC can be implemented as a 1 line bash invocation so is also simple to understand
        • c.f. a complicated memory corruption vuln or similar (ie no need to understand memory management, heap grooming etc etc)
    • Or give it a cool name and logo
      • heartbleed was one of the first to do this and this likely helped it get noticed and patched (plus fame/notoriety for the researchers)
      • Since then we have seen many (shellshock, stagefright, dirty cow, spectre, meltdown, boothole etc) but not all vulns that get names/logos are created equal - impact / exploitability varies greatly - so a name and a logo doesn’t necessarily mean a vuln is critical

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 119 Jun 11, 2021
    Show notes

    Overview

    This week we cover security updates for the Linux kernel, PolicyKit, Intel Microcode and more, plus we look at a report of an apparent malicious snap in the Snap Store and some of the mechanics behind snap confinement.

    This week in Ubuntu Security Updates

    42 unique CVEs addressed

    [USN-4979-1] Linux kernel vulnerabilities [01:04]

    • 13 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS)
      • CVE-2021-3483
      • CVE-2021-3428
      • CVE-2021-33033
      • CVE-2021-31916
      • CVE-2021-29647
      • CVE-2021-28972
      • CVE-2021-28971
      • CVE-2021-28964
      • CVE-2021-28660
      • CVE-2020-25673
      • CVE-2020-25672
      • CVE-2020-25671
      • CVE-2020-25670
    • 4.15 based kernel
    • integer overflow in ext4 extent handling -> could be triggered by mounting an malicious ext4 image -> crash (DoS)
    • reference counting error in firewire packet sniffer driver - UAF
    • NFC LLCP issues above

    [USN-4982-1] Linux kernel vulnerabilities [02:23]

    • 13 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
      • CVE-2021-3483
      • CVE-2021-31916
      • CVE-2021-29647
      • CVE-2021-29264
      • CVE-2021-28972
      • CVE-2021-28971
      • CVE-2021-28964
      • CVE-2021-28950
      • CVE-2021-28688
      • CVE-2020-25673
      • CVE-2020-25672
      • CVE-2020-25671
      • CVE-2020-25670
    • 5.4 based kernel

    [USN-4984-1] Linux kernel vulnerabilities [02:39]

    • 13 CVEs addressed in Focal (20.04 LTS), Groovy (20.10)
      • CVE-2021-3483
      • CVE-2021-33033
      • CVE-2021-31916
      • CVE-2021-30002
      • CVE-2021-29647
      • CVE-2021-28972
      • CVE-2021-28971
      • CVE-2021-28964
      • CVE-2021-28952
      • CVE-2021-28950
      • CVE-2021-28688
      • CVE-2021-28660
      • CVE-2021-28038
    • 5.8 based kernel

    [USN-4977-1] Linux kernel vulnerabilities

    • 6 CVEs addressed in Hirsute (21.04)
      • CVE-2021-3501
      • CVE-2021-29155
      • CVE-2020-25673
      • CVE-2020-25672
      • CVE-2020-25671
      • CVE-2020-25670
    • 5.11 based kernel
    • OOB write in KVM VMX implementation (crash -> DoS, RCE)
    • eBPF Spectre side-channel attack - info leak
    • NFC LLCP (logical link control protocol) - allows to multiplex a single connection between two NFC devices
      • infinite loop on error condition -> DoS
      • memory leak
      • reference count mishandling -> crash -> DoS

    [USN-4983-1] Linux kernel (OEM) vulnerabilities [03:32]

    • 4 CVEs addressed in Focal (20.04 LTS)
      • CVE-2021-3501
      • CVE-2021-31829
      • CVE-2021-29155
      • CVE-2021-33200
    • 5.10 based kernel
    • OOB write in KVM VMX implementation (crash -> DoS, RCE)
    • eBPF Spectre side-channel attacks - verifier fails to stop loading of eBPF programs which could cause speculative loads -> info leak
    • eBPF pointer limit error - OOB read/write - crash / RCE

    [USN-4978-1] Firefox vulnerabilities [03:40]

    • 5 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-29960
      • CVE-2021-29967
      • CVE-2021-29966
      • CVE-2021-29961
      • CVE-2021-29959
    • 89.0 upstream release
      • not only the new visual UI PLUS enhanced private browsing mode via “Total Cookie Protection” - confines cookies to the site where they were created to avoid tracking across sites - PLUS a bunch of security fixes including
        • cached the last filename of a printed file even in private browsing mode - would then surface this next time you choose to print a file
        • Various memory safety issues - RCE / crash etc

    [USN-4980-1] polkit vulnerability [04:43]

    • 1 CVEs addressed in Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-3560
    • Daemons often use policykit to ask whether a user’s application is permitted to perform an action - to do this, they send the DBus name of the process to polkit and it looks up the resulting uid/pid via an internal function polkit_system_bus_name_get_creds_sync() - logic error within policykit when looking if the process in question were to disconnect from DBus at the right time, policykit would return an error but also a boolean TRUE value indicating success (depends on how the daemon interpreted this value with an associated error). This could then allow an application which was not privileged to be able to perform more privileged actions. Fixed to actually return FALSE in this case and avoid any potential confusion.

    [USN-4981-1] Squid vulnerabilities [06:11]

    • 7 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-33620
      • CVE-2021-31808
      • CVE-2021-31807
      • CVE-2021-31806
      • CVE-2021-28662
      • CVE-2021-28652
      • CVE-2021-28651
    • All DoS issues - memory leaks, OOB reads etc, able to be triggered by remote attackers

    [USN-4969-3] DHCP regression [06:28]

    • Affecting Hirsute (21.04)
    • Episode 118 - update for 21.04 only introduced a regression where valid config files would be seen as invalid and rejected and hence isc-dhcp-server would fail to start - actually caused as a result of the newer toolchain used in 21.04 - has stricter aliasing checking and so would treat certain operations introduced in this change as UB and change code-flow as a result. Fixed by disabling this stricter aliasing checking in the build to restore the original behaviour.

    [USN-4937-2] GNOME Autoar regression [07:22]

    • Episode 115
    • Affecting Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
    • upstream regression where when extracting an archive, only an empty directory would be created if an archive contained a file of the same name as the archive itself - fixed to avoid creating this directory first so that files would then actually get created as expected

    [USN-4985-1] Intel Microcode vulnerabilities [07:48]

    • 5 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2020-24513
      • CVE-2020-24512
      • CVE-2020-24511
      • CVE-2017-5715
      • CVE-2021-24489
    • Latest intel-microcode release from upstream, fixes a number of security issues for particular processors PLUS potential stability issues that have been seen in previous microcode releases (processor would hang if tried to load a too new microcode version compared to the one contained within the BIOS)
      • potential cross-domain issue with Intel VT-d (priv esc) plus a fix for an issue which would result in EIBRS (Spectre) mitigations not being applied, cache-lines not being flushed properly and a speculative execution issue specific to Atom processors via micro-arch buffers.

    [USN-4986-1] rpcbind vulnerability [09:02]

    • 1 CVEs addressed in Bionic (18.04 LTS)
      • CVE-2017-8779
    • DoS since would fail to free memory allocated during particular requests - could then be made to crash by allocating too much memory

    Goings on in Ubuntu Security Community

    odrive-unofficial snap investigation [09:20]

    • https://twitter.com/XHaughin/status/1400743600464355331

    The magic behind snap interfaces [12:36]

    • https://ubuntu.com/blog/the-magic-behind-snap-interfaces

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 118 Jun 04, 2021
    Show notes

    Overview

    This week we look at DMCA notices sent against Ubuntu ISOs plus security updates for nginx, DHCP, Lasso, Django, Dnsmasq and more.

    This week in Ubuntu Security Updates

    24 unique CVEs addressed

    [USN-4967-1, USN-4967-2] nginx vulnerability [00:50]

    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-23017
    • 1 byte buffer overflow, able to be trigged by a crafted DNS response - UDP so could possibly be more easily forged than TCP (less state) - crash, RCE

    [USN-4968-1, USN-4968-2] LZ4 vulnerability [01:27]

    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-3520
    • integer overflow -> OOB write -> crash, RCE - crafted lz4 archive

    [USN-4969-1, USN-4969-2] DHCP vulnerability [01:52]

    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-25217
    • Crafted lease file could trigger an OOB read - could be triggered against both dhclient and dhcpd - DoS. In case of dhcpd could also cause that lease to be deleted (and the one that follows it in the lease database). ISC claim impact is LESS is using compiler hardening (stack-protector-strong) - since in this case will trigger an abort - but if not used it will keep running…

    [USN-4970-1] GUPnP vulnerability [03:15]

    • 1 CVEs addressed in Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-33516
    • DNS rebinding attack - able to be exploited by a remote web server - cause the local web browser into triggering actions against local UPnP services that use gupnp library as it would not check that the Host header specified the expected IP address. Could then be used for data exfil / tampering etc.
    • Can be mitigated against by using a DNS resolver that prevents DNS rebinding

    [USN-4971-1] libwebp vulnerabilities [04:11]

    • 11 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2020-36332
      • CVE-2020-36331
      • CVE-2020-36330
      • CVE-2020-36329
      • CVE-2020-36328
      • CVE-2018-25014
      • CVE-2018-25013
      • CVE-2018-25012
      • CVE-2018-25011
      • CVE-2018-25010
      • CVE-2018-25009
    • Google’s image format to relace both jpg/png and be faster (like vp8 video codec using predictive encoding - uses neighboring pixels to predict values in a block and then encodes only the difference)
    • C library :( - memory unsafe
    • OOB reads, heap buffer overflow, UAF, excessive memory allocation etc
      • DoS, RCE etc

    [USN-4972-1] PostgreSQL vulnerabilities [05:05]

    • 3 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-32029
      • CVE-2021-32028
      • CVE-2021-32027
    • Thanks to Christian Ehrhardt from the Ubuntu Server team for preparing these updates
    • Latest upstream point-releases
      • 10.17 - 18.04
      • 12.7 - 20.04 LTS, 20.10
      • 13.3 - 21.04

    [USN-4973-1] Python vulnerability [05:44]

    • 1 CVEs addressed in Focal (20.04 LTS), Groovy (20.10)
      • CVE-2021-29921
    • ipaddress library in the python stdlib mishandled leading zero characters in octets of an IP address - could allow bypass of access controls that are based on IP addresses. Now treats leading zeros as invalid input (before would try and treat them as octal… but could end up confused as a result)

    [USN-4974-1] Lasso vulnerability [06:40]

    • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-28091
    • SAML protocol library
    • Reported by Akamai (uses Lasso in their Enterprise Application Access product) - and coordinated between affected distros and vendors etc
    • Could allow unauthenticated access to applications that use SAMLv2 (Security Assertion Markup Language v2) for authentication
    • If a SAML response contained both a signed and valid assertion, plus additional unsigned assertions appened to this, these unsigned assertions would be treated as valid as well.
    • So could allow an authenticated user to take their own signed SAML assertion and append assertions for other users to the end to then impersonate those other users.
    • https://blogs.akamai.com/2021/06/saml-implementation-vulnerability-impacting-some-akamai-services.html

    [USN-4975-1] Django vulnerabilities [08:19]

    • 3 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-33571
      • CVE-2021-33203
      • CVE-2021-32052
    • URLValidator failed to properly handle newlines, tabs - could be used to inject other headers into responses etc
    • Paths not properly sanitized in the admindocs module - could be used to probe for the existence of files or possibly obtain their contents
    • Leading zeros in IPv4 addresses - basically identical to the Python issue above

    [USN-4976-1] Dnsmasq vulnerability [08:56]

    • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-3448
    • Failed to properly randomise source port (ie used a fixed port) when forwarding queries when configured to use a specific server for a given network interface - could then allow a remote attacker to more easily perform cache poisoning attacks (ie just need to guess the transmission ID once know the source port to get a forged reply accepted)
      • Very similar to the issues that were discovered back in 2008 by Dan Kaminsky - the whole reason source port randomisation was introduced as part of the DNS protocol

    Goings on in Ubuntu Security Community

    Ubuntu user’s DMCA violation [09:58]

    • Last week was reported that a user downloading Ubuntu 20.04.2 iso via bittorrent received a DMCA violation notice from their ISP (Comcast)
    • Clearly absurd given Ubuntu is free (beer & freedom/libre)
    • Also the hash of the iso in question was legit too
    • Sent by “OpSec Online Antipiracy” not Canonical
    • OpSec responded saying their notice sending program was “spoofed” by unknown parties across multiple streaming platforms
    • Not clear then if the user spoofed it directly or if someone else spoofed the notice and sent it to the user…
    • Still being investigated by OpSec apparently - our legal team is also looking into it as well
    • Not the first time this sort of thing has happened - back in 2016 Paramount Pictures used the DMCA to send a takedown request to Google to remove a search result linking to the Ubuntu 12.04.2 alternate ISO at extratorrent.cc - this was listed as apparently being a link to the Transformers: Age of Extinction movie…
      • Google did follow through on this - likely an automated system due to the sheer volume of such requests they get per day (3 million p/d pirate URLs to be removed from search results)

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 117 May 28, 2021
    Show notes

    Overview

    This week we’re talking about moving IRC networks plus security updates for Pillow, Babel, Apport, X11 and more.

    This week in Ubuntu Security Updates

    24 unique CVEs addressed

    [USN-4963-1] Pillow vulnerabilities [00:55]

    • 6 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-28678
      • CVE-2021-28677
      • CVE-2021-28676
      • CVE-2021-28675
      • CVE-2021-25288
      • CVE-2021-25287
    • Python image handling library - used by many other packages for their image handling
    • All DoS issues via OOB read and similar so not critical

    [USN-4962-1] Babel vulnerability [01:31]

    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-20095
    • Internationalisation handling for python apps
    • Directory traversal flaw - could be exploited to load arbitrary locale .dat files - these contain serialized Python objects - so hence can get arbitrary code execution as a result.
    • Could use relative path to specify a file outside the locate-data directory

    [USN-4964-1] Exiv2 vulnerabilities [02:25]

    • 5 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-29623
      • CVE-2021-32617
      • CVE-2021-29473
      • CVE-2021-29464
      • CVE-2021-29463
    • CLI util and library (C++) for reading+modifying metadata in image files - more exiv2 - last only in Episode 115
    • OOB reads on metadata write
    • heap buffer overflow on m w
    • quadratic complexity algorithm on metadata write - DoS
    • stack info leak on m r

    [USN-4965-1, USN-4965-2] Apport vulnerabilities [03:19]

    • 11 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-32557
      • CVE-2021-32556
      • CVE-2021-32555
      • CVE-2021-32554
      • CVE-2021-32553
      • CVE-2021-32552
      • CVE-2021-32551
      • CVE-2021-32550
      • CVE-2021-32549
      • CVE-2021-32548
      • CVE-2021-32547
    • Seems it’s time for more Apport vulns - every quarter or so
    • Arbitrary file read / write vulns discovered by Maik Münch
    • Apport parses various details out of /proc and some of these can be crafted by the process, ie process name, current working dir etc - and then goes to gather files etc - and so if can craft these details can get it to read files which weren’t intended via symlinks etc (mitigated by symlink protections in Ubuntu) - or from injection of data into say dpkg queries to get it to include other files like /etc/passwd since this operation happens as root by apport
    • These end up in the crash dump and this can be read by the regular user
    • Also when uploading via whoopsie, race condition where crash dump can be replaced by a symlink and then the crash dump will be written to the dest of the symlink - file write vuln - but again mitigated by symlink-restriction

    [USN-4966-1, USN-4966-2] libx11 vulnerability [05:57]

    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-31535
    • When looking up a color, failed to properly validate it - app could then get extra X protocol requests sent to the X server - ie. could then disable X server authorisation etc so remote attackers could connect to the local X server and snoop on inputs etc

    Goings on in Ubuntu Security Community

    #ubuntu-hardened -> #ubuntu-security on Libera.Chat [06:45]

    • LWN writeup https://lwn.net/Articles/857140/
    • Volunteer staff resigned en masse after network was taken over by tech entrepreneur
    • Ubuntu IRC council voted and approved a resolution to recommend moving Ubuntu IRC channels from freenode to Libera.Chat
    • Community Council approved this so now all channels have moved to Libera.Chat
    • Almost all of the old channels on freenode have now all been taken over by the new freenode staff
    • irc.ubuntu.com now redirects to irc.libera.chat
    • Finally took the opportunity to rename our channel - #ubuntu-security
    • Come join us

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 116 May 21, 2021
    Show notes

    Overview

    With 60 CVEs fixed across MySQL, Django, Please and the Linux kernel this week we take a look at some of these details, plus look at the recent announcement of 1Password for Linux and some open positions on the team too.

    This week in Ubuntu Security Updates

    60 unique CVEs addressed

    [USN-4952-1] MySQL vulnerabilities [00:58]

    • 33 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-2308
      • CVE-2021-2307
      • CVE-2021-2305
      • CVE-2021-2304
      • CVE-2021-2301
      • CVE-2021-2300
      • CVE-2021-2299
      • CVE-2021-2298
      • CVE-2021-2293
      • CVE-2021-2278
      • CVE-2021-2232
      • CVE-2021-2230
      • CVE-2021-2226
      • CVE-2021-2217
      • CVE-2021-2215
      • CVE-2021-2212
      • CVE-2021-2208
      • CVE-2021-2203
      • CVE-2021-2201
      • CVE-2021-2196
      • CVE-2021-2194
      • CVE-2021-2193
      • CVE-2021-2180
      • CVE-2021-2179
      • CVE-2021-2172
      • CVE-2021-2171
      • CVE-2021-2170
      • CVE-2021-2169
      • CVE-2021-2166
      • CVE-2021-2164
      • CVE-2021-2162
      • CVE-2021-2154
      • CVE-2021-2146
    • Latest upstream point releases - includes both security and bug fixes and possibly incompatible changes etc
    • MySQL has been updated to 8.0.25 in Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04. Ubuntu 18.04 LTS has been updated to MySQL 5.7.34.

    [USN-4932-2] Django vulnerability [01:37]

    • 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS)
      • CVE-2021-31542
    • Episode 114 - directory traversal via file upload

    [USN-4953-1] AWStats vulnerabilities [01:56]

    • 3 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10)
      • CVE-2017-1000501
      • CVE-2020-35176
      • CVE-2020-29600
    • A-W-Stats - Advanced Web Statistics - log analyzer etc
    • Incomplete fix for old CVE-2017-1000501 - this itself was incomplete too - hence CVE-2020-35176
      • Could be used to read an arbitrary file on the webserver via the config parameter - and this could allow code execution as this was not sanitised properly

    [USN-4954-1] GNU C Library vulnerabilities [03:00]

    • 2 CVEs addressed in Xenial (16.04 LTS)
      • CVE-2009-5155
      • CVE-2020-6096
    • ARMv7 specific issue - memcpy() undefined behaviour if a negative length were specified
    • DoS (assertion failure + abort) via crafted regex - so should not be passing untrusted regular expressions to posix regex implementation

    [USN-4628-3] Intel Microcode vulnerabilities [04:08]

    • 3 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2020-8698
      • CVE-2020-8696
      • CVE-2020-8695
    • Episode 96 - RAPL side-channel etc - corresponding update for some Xeon processors

    [USN-4955-1] Please vulnerabilities [04:44]

    • 3 CVEs addressed in Hirsute (21.04)
      • CVE-2021-31155
      • CVE-2021-31154
      • CVE-2021-31153
    • sudo replacement written in rust
    • Code analysis by Matthias Gerstner @ SuSE -
      • arbitrary file existence test and open (eg could open /dev/zero and consume memory -> OOM)
      • unsafe permissions for token directory - create world-writable - can allow an unprivileged user to get root privileges quite easily by creating their own token as though they had authenticated
      • pleaseedit uses predictable paths in /tmp - without symlink protections could allow a user to change ownership of arbitrary files as it would follow symlinks
    • rust is not a panacea - not all vulnerabilities are memory corruption and writing setuid root binaries is always going to be challenging

    [LSN-0077-1] Linux kernel vulnerability [07:04]

    • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
      • CVE-2021-3492
    • shiftfs specific vuln reported via ZDI (found by Vincent Dehors) - Ubuntu carry this as an out-of-tree patch so doesn’t affect upstream kernel (used by LXD etc for UID mapping in containers)
    • Failed to handle faults in copy_from_user() -> double-free or possible memory leak -> code execution/DoS

    [USN-4956-1] Eventlet vulnerability [08:05]

    • 1 CVEs addressed in Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-21419
    • Python eventlet (concurrent networking library)
    • Used by a lot of other packages including openstack etc
    • websocket peer could DoS via memory exhaustion by sending very large websocket frames

    [USN-4957-1, USN-4957-2] DjVuLibre vulnerabilities [08:31]

    • 5 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-3500
      • CVE-2021-32493
      • CVE-2021-32492
      • CVE-2021-32491
      • CVE-2021-32490
    • document format alternative to pdf - for storing scanned documents etc
    • c++ - memory corruption vulns
      • heap buffer overflow
      • oob write
      • stack buffer overflow
      • oob read
      • integer overflow
      • DoS/RCE

    [USN-4958-1] Caribou vulnerability [09:27]

    • Affecting Focal (20.04 LTS), Groovy (20.10)
    • Caribou on-screen keyboard could crash if given crafted input - in some cases, this would then cause the screensaver to crash -> unauthenticated access to a desktop session
      • Thanks to Fabio Fantoni and Joshua Peisach (itzswirlz) from the Ubuntu community for preparing these updates

    [USN-4959-1] GStreamer Base Plugins vulnerability [10:11]

    • 1 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10)
      • CVE-2021-3522
    • OOB read on crafted input since failed to properly check size -> DoS

    [USN-4945-2] Linux kernel (Raspberry Pi) vulnerabilities [10:18]

    • 7 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS)
      • CVE-2021-30002
      • CVE-2021-29650
      • CVE-2021-29265
      • CVE-2021-28660
      • CVE-2021-28375
      • CVE-2021-28038
      • CVE-2020-25639
    • Episode 115 - regular kernels for Ubuntu 20.04 / 18.04 LTS
    • Update also for the raspi specific kernel build

    Goings on in Ubuntu Security Community

    1Password for Linux officially released [10:43]

    • Episode 86 (August 2020) - beta was announced
    • Now officially released, includes integration with browser extension to stay unlocked across both, use of regular desktop authentication to unlock as well - e.g. fingerprint / yubikey etc - both opt-in features.
    • Great desktop integration, theme, clipboard, GNOME Keyring / KDE Wallet, kernel keyring, DBUS API, integration with system lock / idle etc
    • Feature parity with Windows and MacOS clients PLUS extra features like Secure file attachment, Watchtower, item archiving / deletion, quick find and more
    • Uses kernel keyring to store the key used to establish the connection between the browser and the desktop client
    • Backend and lots of underlying libs written in Rust - UI is React
    • Native packages for Ubuntu (Debian. CentOS, Fedora, RHEL)
    • Snap

    Hiring [13:56]

    Linux Cryptography and Security Engineer

    • https://canonical.com/careers/2612092/linux-cryptography-and-security-engineer-remote

    Security Engineer - Ubuntu

    • https://canonical.com/careers/2925180/security-engineer-ubuntu-remote

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 115 May 14, 2021
    Show notes

    Overview This week we look at some details of the 90 unique CVEs addressed across the supported Ubuntu releases and more. This week in Ubuntu Security Updates 90 unique CVEs addressed [USN-4934-2] Exim vulnerabilities [00:41] 16 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS) CVE-2021-27216 CVE-2020-28025 CVE-2020-28024 CVE-2020-28022 CVE-2020-28020 CVE-2020-28017 CVE-2020-28016 CVE-2020-28015 CVE-2020-28014 CVE-2020-28013 CVE-2020-28012 CVE-2020-28011 CVE-2020-28009 CVE-2020-28008 CVE-2020-28007 CVE-2020-28026 Episode 114 [USN-4937-1] GNOME Autoar vulnerability [01:00] 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10) CVE-2021-28650 Directory traversal due to failure to properly handle symlinks (result of incomplete fix for previous CVE-2020-36241) [USN-4936-1] Thunderbird vulnerabilities [01:47] 5 CVEs addressed in Focal (20.04 LTS), Groovy (20.10) CVE-2021-29950 CVE-2021-23978 CVE-2021-23973 CVE-2021-23969 CVE-2021-23968 78.8.1 If used a PGP key but then a failure occurred, TB would keep the decrypted key in memory - on Ubuntu we enable Yama ptrace restrictions (ptrace_scope) - so this means processes can only ptrace their descendents by default and hence even other user-level processes cannot dump the memory of another process to say extract this private key Various other CVEs inherited from Firefox [USN-4938-1] Unbound vulnerabilities [03:21] 13 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS) CVE-2020-28935 CVE-2019-25042 CVE-2019-25041 CVE-2019-25040 CVE-2019-25039 CVE-2019-25038 CVE-2019-25037 CVE-2019-25036 CVE-2019-25035 CVE-2019-25034 CVE-2019-25033 CVE-2019-25032 CVE-2019-25031 Validating, recursive DNS resolver Remote DoS, command injection, RCE, local file overwrite etc [USN-4939-1] WebKitGTK vulnerabilities [03:48] 3 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10) CVE-2021-1871 CVE-2021-1844 CVE-2021-1788 1 logic issue, 2 memory corruption bugs - all leading to possible RCE [USN-4940-1] PyYAML vulnerability [04:12] 1 CVEs addressed in Focal (20.04 LTS), Groovy (20.10) CVE-2020-14343 RCE when processing untrusted YAML - due to incomplete fix for previous CVE-2020-1747 - that CVE not specifically patched in Ubuntu as either the versions of pyyaml were too old to be affected or were based on upstream releases that had already patched it [USN-4941-1] Exiv2 vulnerabilities [04:35] 4 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04) CVE-2021-3482 CVE-2021-29470 CVE-2021-29458 CVE-2021-29457 EXIF/IPTC/XMP metadata manipulation tool Heap buffer overflow or OOB read when writing metadata - so not so likely to be triggered by applications that are just extracting metadata etc Heap buffer overflow for handling EXIF in JPG images [USN-4942-1] Firefox vulnerability [05:09] 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04) CVE-2021-29952 88.0.1 Race condition on destruction of WebRender components -> UAF? -> possible RCE [USN-4943-1] XStream vulnerabilities [05:32] 14 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04) CVE-2021-21351 CVE-2021-21350 CVE-2021-21349 CVE-2021-21348 CVE-2021-21347 CVE-2021-21346 CVE-2021-21345 CVE-2021-21344 CVE-2021-21343 CVE-2021-21342 CVE-2021-21341 CVE-2020-26259 CVE-2020-26258 CVE-2020-26217 Episode 102 - B+F - corresponding fixes for those 3 CVEs for G Also a heap of others - denial of service, arbitrary code execution, arbitrary file deletion and server-side forgery attacks [USN-4944-1] MariaDB vulnerabilities [06:04] Affecting Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04) Latest upstream point releases rolling in a large number of security fixes: Ubuntu 18.04 LTS has been updated to MariaDB 10.1.48. Ubuntu 20.04 LTS has been updated to MariaDB 10.3.29. Ubuntu 20.10 has been updated to MariaDB 10.3.29. Ubuntu 21.04 has been updated to MariaDB 10.5.10. Thanks to Otto Kekäläinen from the MariaDB foundation for contributing and preparing these updates [USN-4945-1] Linux kernel vulnerabilities [06:33] 7 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS) CVE-2021-30002 CVE-2021-29650 CVE-2021-29265 CVE-2021-28660 CVE-2021-28375 CVE-2021-28038 CVE-2020-25639 5.4 (standard kernel for 20.04 LTS, HWE for 18.04 LTS) [USN-4946-1] Linux kernel vulnerabilities 9 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS) CVE-2021-30002 CVE-2021-29650 CVE-2021-29265 CVE-2021-29264 CVE-2021-28688 CVE-2021-28038 CVE-2021-26931 CVE-2021-26930 CVE-2021-20292 4.15 (standard kernel for 18.04 LTS, HWE for 16.04 ESM, Azure for 14.04 ESM) [USN-4947-1] Linux kernel (OEM) vulnerabilities 5 CVEs addressed in Focal (20.04 LTS) CVE-2021-30002 CVE-2021-29650 CVE-2021-29646 CVE-2021-28375 CVE-2020-35519 5.6 (OEM for 20.04 LTS) [USN-4948-1] Linux kernel (OEM) vulnerabilities 21 CVEs addressed in Focal (20.04 LTS) CVE-2021-3483 CVE-2021-31916 CVE-2021-29657 CVE-2021-29650 CVE-2021-29649 CVE-2021-29647 CVE-2021-29646 CVE-2021-29266 CVE-2021-29264 CVE-2021-28972 CVE-2021-28971 CVE-2021-28964 CVE-2021-28952 CVE-2021-28951 CVE-2021-28688 CVE-2020-25672 CVE-2020-25671 CVE-2020-25670 CVE-2021-3491 CVE-2021-3490 CVE-2021-3489 5.10 (OEM for 20.04 LTS) 3 Pwn2Own vulnerabilities Ryota Shiga - eBPF ring buffer Manfred Paul - eBPF bounds tracking on bitwise operations Billy Jheng Bing-Jhong - io_uring All OOB writes + info leaks -> local priv esc + code execution as root [USN-4949-1] Linux kernel vulnerabilities 12 CVEs addressed in Focal (20.04 LTS), Groovy (20.10) CVE-2021-29650 CVE-2021-29646 CVE-2021-29266 CVE-2021-29265 CVE-2021-29264 CVE-2021-28375 CVE-2021-26931 CVE-2021-26930 CVE-2020-25639 CVE-2021-3491 CVE-2021-3490 CVE-2021-3489 5.8 (standard kernel for 20.10, HWE for 20.04 ESM, Azure for 14.04 ESM) [USN-4950-1] Linux kernel vulnerabilities 3 CVEs addressed in Hirsute (21.04) CVE-2021-3491 CVE-2021-3490 CVE-2021-3489 5.11 Plus CAN ISOTP race condition - discovered by a Norbert Slusarek (high school student in Germany) - local privilege escalation Introduced via recent broadcast mode support (normally a CAN socket registers a particular CAN ID to receive and only gets those frames - was only in 5.11 kernel so only affected hirsute) - this support has been removed from the hirsute kernel until a proper fix comes from upstream [USN-4951-1] Flatpak vulnerability [10:16] 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10) CVE-2021-21381 File forwarding issue which could allow an attacker to get access to files that are not normally provided by the permissions granted to an app Use special tokens in the Exec line of the desktop file for an app could trick flatpak runtime into providing access to a file as though this had been explicitly granted by the user snapd generates desktop files so less likely to be affected by this sort of issue - less untrusted input in general (but perhaps also less flexible) Goings on in Ubuntu Security Community Hiring [11:47] Linux Cryptography and Security Engineer https://canonical.com/careers/2612092/linux-cryptography-and-security-engineer-remote Security Engineer - Ubuntu https://canonical.com/careers/2925180/security-engineer-ubuntu-remote Get in contact security@ubuntu.com #ubuntu-security on the Libera.Chat IRC network ubuntu-hardened mailing list Security section on discourse.ubuntu.com @ubuntu_sec on twitter

    Full show notes at the publisher

    Episode 114 May 07, 2021
    Show notes

    Overview

    This week we look at the response from the Linux Technical Advisory Board to the UMN Linux kernel incident, plus we cover the 21Nails Exim vulnerabilities as well as updates for Bind, Samba, OpenVPN and more.

    This week in Ubuntu Security Updates

    40 unique CVEs addressed

    [USN-4928-1] GStreamer Good Plugins vulnerabilities [00:40]

    • 2 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10)
      • CVE-2021-3498
      • CVE-2021-3497
    • UAF or heap corruption when handling crafted Matroska files - crash / RCE

    [USN-4929-1] Bind vulnerabilities [01:18]

    • 3 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-25216
      • CVE-2021-25215
      • CVE-2021-25214
    • 2 possible crasher bugs (failed assertions) -> DoS, 1 buffer over-read or possible overflow -> crash / RCE

    [USN-4930-1] Samba vulnerability [02:08]

    • 1 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-20254
    • Failed to properly handle negative idmap cache entries - could then end up with incorrect group entries and as such could possibly allow a user to access / modify files they should not have access to

    [USN-4931-1] Samba vulnerabilities [02:51]

    • 4 CVEs addressed in Trusty ESM (14.04 ESM)
      • CVE-2021-20254
      • CVE-2020-14383
      • CVE-2020-14323
      • CVE-2020-14318
    • negative idmap cache entries issue plus some older vulns (Episode 95)

    [LSN-0076-1] Linux kernel vulnerability [03:03]

    • 2 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS)
      • CVE-2021-29154
      • CVE-2021-3493
    • 2 local user privesc vulns fixed:
      • BPF JIT branch displacement issue (Episode 112)
      • Overlayfs / file system capabilities interaction

    [USN-4918-3] ClamAV regression [03:52]

    • 3 CVEs addressed in Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-1405
      • CVE-2021-1404
      • CVE-2021-1252
    • Previous clamav update (back in April ) introduced a regression where clamdscan would crash if called with –multiscan and –fdpass AND you had an ExcludePath configured in the configuration - backported the upstream commit from the development branch to fix this

    [USN-4932-1] Django vulnerability [04:30]

    • 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-31542
    • Directory traversal via uploaded files with crafted names

    [USN-4933-1] OpenVPN vulnerabilities [04:47]

    • 2 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2020-15078
      • CVE-2020-11810
    • Race condition in handling of data packets could allow an attacker to inject a packet using a victim’s peer-id before the crypto channel is properly initialised - could cause the victim’s connection to be dropped (DoS) but doesn’t appear to expose any sensitive info etc
    • Attackers could possibly bypass auth on control channel and hence leak info

    [USN-4934-1] Exim vulnerabilities [05:39]

    • 21 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-27216
      • CVE-2020-28026
      • CVE-2020-28025
      • CVE-2020-28024
      • CVE-2020-28023
      • CVE-2020-28022
      • CVE-2020-28021
      • CVE-2020-28020
      • CVE-2020-28019
      • CVE-2020-28018
      • CVE-2020-28017
      • CVE-2020-28016
      • CVE-2020-28015
      • CVE-2020-28014
      • CVE-2020-28013
      • CVE-2020-28012
      • CVE-2020-28011
      • CVE-2020-28010
      • CVE-2020-28009
      • CVE-2020-28008
      • CVE-2020-28007
    • Qualsys - 21Nails - various vulns which could be chained together to get full remote unauthenticated RCE and root privesc
      • Full write-up
    • Possibly 60% of internet mail servers run exim and 4 million are publicly accessible
    • Previously has been a target of Sandworm
    • In the process of preparing the updates for 16.04 / 14.04 ESM - expect to be available in the next day or 2 so most likely will already be out by the time you are listening to this

    [USN-4935-1] NVIDIA graphics drivers vulnerabilities [07:58]

    • 2 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10), Hirsute (21.04)
      • CVE-2021-1077
      • CVE-2021-1076
    • Not much detail from NVIDIA
      • improper access control -> DoS, infoleak or data corruption -> privesc etc
      • incorrect use of reference counting -> DoS (crash?) (UAF?)

    Goings on in Ubuntu Security Community

    Linux Technical Advisory Board response to UMN incident [08:56]

    • Covered in Episode 113
    • https://lore.kernel.org/lkml/202105051005.49BFABCE@keescook/
    • Kees Cook (previously inaugural Tech Lead of Ubuntu Security Team) posted to LKML the Tab’s report (various folks from across the Linux Kernel community, including from Red Hat, Google, Canonical and others)
    • Detailed timeline of events, identification of the “hypocrite” commits in question
    • Recommendations going forward
      • UMN must improve quality of their submissions since even for a lot of what were good-faith patches, they actually had issues and either didn’t fix the purported issue or tried to fix a non-issue
      • TAB will create a best-practices document for all research groups when working with the kernel or other open source projects

    Hiring [11:36]

    AppArmor Security Engineer

    • https://canonical.com/careers/2114847/apparmor-security-engineer-remote

    Linux Cryptography and Security Engineer

    • https://canonical.com/careers/2612092/linux-cryptography-and-security-engineer-remote

    Security Engineer - Ubuntu

    • https://canonical.com/careers/2925180/security-engineer-ubuntu-remote

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Previous 1 11 12 13 14 15 25 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights