TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Ubuntu Security Podcast

    A fortnightly podcast talking about the latest developments and updates from the Ubuntu Security team, including a summary of recent security vulnerabilities and fixes as well as a discussion on some of the goings on in the wider Ubuntu Security community.

    Advertise

    Copyright: © Copyright 2019 Canonical

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Episode 233 Aug 02, 2024
    Show notes

    Overview This week we take a look at the recent Crowdstrike outage and what we can learn from it compared to the testing and release process for security updates in Ubuntu, plus we cover details of vulnerabilities in poppler, phpCAS, EDK II, Python, OpenJDK and one package with over 300 CVE fixes in a single update. This week in Ubuntu Security Updates 462 unique CVEs addressed [USN-6915-1] poppler vulnerability (01:35) 1 CVEs addressed in Jammy (22.04 LTS), Noble (24.04 LTS) CVE-2024-6239 Installed by default in Ubuntu due to use by cups PDF document format describes a Catalog which has a tree of destinations - essentially hyperlinks within the document. These can be either a page number etc or a named location within the document. If open a crafted document with a missing name property for a destination - name would then be NULL and would trigger a NULL ptr deref -> crash -> DoS [USN-6913-1] phpCAS vulnerability (02:26) 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2022-39369 Authentication library for PHP to allow PHP applications to authenticates users against a Central Authentication Server (ie. SSO). When used for SSO, a client who is trying to use a web application gets directed to the CAS. The CAS then authenticates the user and returns a service ticket - the client then needs to validate this ticket with the CAS since it could have possibly been injected via the application. To do this, pass the ticket along with its own service identifier to CAS - and if this succeeds is provided with the details of which user was authenticated etc. For clients, previously would use HTTP headers to determine where the CAS server was to authenticate the ticket. Since these can be manipulated by a malicious application, could essentially redirect the client to send the ticket to the attacker who could then use that to impersonate the client and login as the user. Fix requires a refactor to include an additional API parameter which specifies either a fixed CAS server for the client to use, or a mechanism to auto-discover this in a secure way - either way, applications using phpCAS now need to be updated. [USN-6914-1] OCS Inventory vulnerability 1 CVEs addressed in Jammy (22.04 LTS) CVE-2022-39369 Same as above since has an embedded copy of phpCAS [USN-6916-1] Lua vulnerabilities (04:44) 2 CVEs addressed in Jammy (22.04 LTS) CVE-2022-33099 CVE-2022-28805 Heap buffer over-read and a possible heap buffer over-flow via recursive error handling - looks like both require to be interpreting malicious code [USN-6920-1] EDK II vulnerabilities (05:04) 5 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM) CVE-2019-0160 CVE-2018-3613 CVE-2018-12183 CVE-2018-12182 CVE-2017-5731 UEFI firmware implementation in qemu etc Various missing bounds checks -> stack and heap buffer overflows -> DoS or code execution in BIOS context -> privilege escalation within VM [USN-6928-1] Python vulnerabilities (05:49) 2 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2024-4032 CVE-2024-0397 Memory race in the ssl module - can call into various functions to get certificate information at the same time as certs are loaded if happening to be doing a TLS handshake with a certificate directory configured - all via different threads. Python would then possibly return inconsistent results leading to various issues Occurs since ssl module is implemented in C to interface with openssl and did not properly lock access to the certificate store [USN-6929-1, USN-6930-1] OpenJDK 8 and OpenJDK 11 vulnerabilities (06:52) 6 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS) CVE-2024-21147 CVE-2024-21145 CVE-2024-21144 CVE-2024-21140 CVE-2024-21138 CVE-2024-21131 Latest upstream releases of OpenJDK 8 and 11 8u422-b05-1, 11.0.24+8 Fixes various issues in the Hotspot and Concurrency components [USN-6931-1, USN-6932-1] OpenJDK 17 and OpenJDK 21 vulnerabilities (07:11) 5 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS) CVE-2024-21147 CVE-2024-21145 CVE-2024-21140 CVE-2024-21138 CVE-2024-21131 Latest upstream releases of OpenJDK 17 and 21 17.0.12+7, 21.0.4+7 Fixes the same issues in the Hotspot component [USN-6934-1] MySQL vulnerabilities (07:29) 15 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS) CVE-2024-21185 CVE-2024-21179 CVE-2024-21177 CVE-2024-21173 CVE-2024-21171 CVE-2024-21165 CVE-2024-21163 CVE-2024-21162 CVE-2024-21142 CVE-2024-21134 CVE-2024-21130 CVE-2024-21129 CVE-2024-21127 CVE-2024-21125 CVE-2024-20996 Also latest upstream release 8.0.39 Bug fixes, possible new features and incompatible changes - consult release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-38.html https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-39.html https://www.oracle.com/security-alerts/cpujul2024.html [USN-6917-1] Linux kernel vulnerabilities (07:57) 156 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2024-35933 CVE-2024-35910 CVE-2024-27393 CVE-2024-27004 CVE-2024-27396 CVE-2024-36029 CVE-2024-26955 CVE-2024-35976 CVE-2024-26966 CVE-2024-26811 CVE-2024-35871 CVE-2023-52699 CVE-2024-35796 CVE-2024-35851 CVE-2024-35885 CVE-2024-35813 CVE-2024-35789 CVE-2024-35825 CVE-2024-26994 CVE-2024-35815 CVE-2024-27395 CVE-2024-26981 CVE-2024-35886 CVE-2024-26931 CVE-2024-35791 CVE-2024-35849 CVE-2024-35978 CVE-2024-35895 CVE-2024-35918 CVE-2024-35902 CVE-2024-26926 CVE-2024-35934 CVE-2024-35807 CVE-2024-35805 CVE-2024-36008 CVE-2024-26950 CVE-2024-26973 CVE-2024-35898 CVE-2024-35955 CVE-2024-36004 CVE-2024-36006 CVE-2024-35990 CVE-2024-35944 CVE-2024-36007 CVE-2024-35896 CVE-2024-35819 CVE-2024-26988 CVE-2024-35872 CVE-2024-36025 CVE-2024-26957 CVE-2024-35897 CVE-2024-27016 CVE-2024-35806 CVE-2024-35927 CVE-2022-48808 CVE-2024-35960 CVE-2024-27001 CVE-2024-35970 CVE-2024-35988 CVE-2024-36005 CVE-2024-35821 CVE-2024-35925 CVE-2024-26961 CVE-2024-35817 CVE-2024-26922 CVE-2024-26976 CVE-2024-35899 CVE-2024-35984 CVE-2024-26929 CVE-2024-27018 CVE-2024-35907 CVE-2024-35884 CVE-2023-52488 CVE-2024-35982 CVE-2024-26934 CVE-2024-26935 CVE-2024-35973 CVE-2024-26958 CVE-2024-27008 CVE-2024-35809 CVE-2024-26951 CVE-2024-35900 CVE-2024-35888 CVE-2024-26965 CVE-2024-26828 CVE-2024-35935 CVE-2024-35857 CVE-2024-26642 CVE-2024-26989 CVE-2024-35893 CVE-2024-35877 CVE-2024-27009 CVE-2024-35785 CVE-2024-35905 CVE-2024-27020 CVE-2024-35901 CVE-2024-26956 CVE-2024-26977 CVE-2024-26969 CVE-2024-26810 CVE-2024-26813 CVE-2024-35930 CVE-2024-26970 CVE-2024-26687 CVE-2024-27015 CVE-2024-35847 CVE-2024-26999 CVE-2024-35940 CVE-2024-35890 CVE-2024-26814 CVE-2024-35958 CVE-2024-35804 CVE-2024-26629 CVE-2024-26974 CVE-2023-52880 CVE-2024-26937 CVE-2024-35922 CVE-2024-35854 CVE-2024-27013 CVE-2024-35853 CVE-2024-27000 CVE-2024-35989 CVE-2024-35852 CVE-2024-35823 CVE-2024-36020 CVE-2024-36031 CVE-2024-26923 CVE-2024-26654 CVE-2024-26925 CVE-2024-35855 CVE-2024-35997 CVE-2024-35822 CVE-2024-27019 CVE-2024-35938 CVE-2024-35915 CVE-2024-35912 CVE-2024-35936 CVE-2024-35969 CVE-2024-27059 CVE-2024-26964 CVE-2024-27437 CVE-2024-26960 CVE-2024-35950 CVE-2024-26817 CVE-2024-26984 CVE-2024-26812 CVE-2024-35879 CVE-2024-26996 CVE-2024-26993 CVE-2024-25739 CVE-2024-24861 CVE-2024-24859 CVE-2024-24858 CVE-2024-24857 CVE-2024-23307 CVE-2022-38096 5.15 - Azure + FDE (CVM) [USN-6918-1] Linux kernel vulnerabilities 180 CVEs addressed in Noble (24.04 LTS) CVE-2024-24859 CVE-2024-24858 CVE-2024-24857 CVE-2024-35932 CVE-2024-35937 CVE-2024-27006 CVE-2024-35960 CVE-2024-27011 CVE-2024-35924 CVE-2024-35946 CVE-2024-35942 CVE-2024-35921 CVE-2024-35908 CVE-2024-26811 CVE-2024-27008 CVE-2024-35871 CVE-2024-36019 CVE-2024-35965 CVE-2024-35973 CVE-2024-26981 CVE-2024-27009 CVE-2024-27019 CVE-2024-36022 CVE-2024-35910 CVE-2024-35907 CVE-2024-35860 CVE-2024-35951 CVE-2024-26924 CVE-2024-26921 CVE-2024-35901 CVE-2024-35972 CVE-2024-35889 CVE-2024-27017 CVE-2024-35913 CVE-2024-35936 CVE-2024-36025 CVE-2024-35961 CVE-2024-35977 CVE-2024-35902 CVE-2024-26817 CVE-2024-26994 CVE-2023-52699 CVE-2024-35868 CVE-2024-35899 CVE-2024-35888 CVE-2024-26995 CVE-2024-35865 CVE-2024-26993 CVE-2024-35863 CVE-2024-35970 CVE-2024-35943 CVE-2024-35875 CVE-2024-35978 CVE-2024-27005 CVE-2024-35909 CVE-2024-35957 CVE-2024-35950 CVE-2024-26986 CVE-2024-36020 CVE-2024-35952 CVE-2024-26928 CVE-2024-35878 CVE-2024-35954 CVE-2024-26998 CVE-2024-36024 CVE-2024-26936 CVE-2024-27018 CVE-2024-35900 CVE-2024-35940 CVE-2024-35985 CVE-2024-35944 CVE-2024-35958 CVE-2024-35864 CVE-2024-35975 CVE-2024-27002 CVE-2024-36018 CVE-2024-35974 CVE-2024-26926 CVE-2024-35877 CVE-2024-35916 CVE-2024-35934 CVE-2024-35930 CVE-2024-35898 CVE-2024-35893 CVE-2024-35887 CVE-2024-35929 CVE-2024-26923 CVE-2024-35911 CVE-2024-35919 CVE-2024-26984 CVE-2024-27016 CVE-2024-35926 CVE-2024-35872 CVE-2024-35922 CVE-2024-27007 CVE-2024-35931 CVE-2024-36021 CVE-2024-35953 CVE-2024-27004 CVE-2024-27001 CVE-2024-27014 CVE-2024-35866 CVE-2024-27021 CVE-2024-35870 CVE-2024-35925 CVE-2024-35891 CVE-2024-26982 CVE-2024-35879 CVE-2024-35979 CVE-2024-35912 CVE-2024-35982 CVE-2024-27015 CVE-2024-26985 CVE-2024-35861 CVE-2024-35939 CVE-2024-27003 CVE-2024-35945 CVE-2024-35967 CVE-2024-35966 CVE-2024-26983 CVE-2024-35894 CVE-2024-35896 CVE-2024-36027 CVE-2024-35895 CVE-2024-26987 CVE-2024-35873 CVE-2024-26996 CVE-2024-26991 CVE-2024-27013 CVE-2024-36026 CVE-2024-26922 CVE-2024-35897 CVE-2024-35917 CVE-2024-35968 CVE-2024-35890 CVE-2024-35904 CVE-2024-35867 CVE-2024-35933 CVE-2024-35918 CVE-2024-35920 CVE-2024-26997 CVE-2024-35981 CVE-2024-35963 CVE-2024-26989 CVE-2024-26999 CVE-2024-35892 CVE-2024-27010 CVE-2024-26992 CVE-2024-35935 CVE-2024-27022 CVE-2024-35971 CVE-2024-35956 CVE-2024-35862 CVE-2024-35969 CVE-2024-27012 CVE-2024-26990 CVE-2024-35885 CVE-2024-26925 CVE-2024-35905 CVE-2024-35914 CVE-2024-35884 CVE-2024-35927 CVE-2024-35882 CVE-2024-26980 CVE-2024-35964 CVE-2024-35955 CVE-2024-27020 CVE-2024-35980 CVE-2024-35903 CVE-2024-35976 CVE-2024-35886 CVE-2024-35883 CVE-2024-35959 CVE-2024-35915 CVE-2024-35880 CVE-2024-27000 CVE-2024-35938 CVE-2024-35869 CVE-2024-36023 CVE-2024-26988 6.8 - Oracle [USN-6919-1] Linux kernel vulnerabilities 304 CVEs addressed in Jammy (22.04 LTS) CVE-2024-35976 CVE-2023-52880 CVE-2024-35849 CVE-2024-27073 CVE-2024-35934 CVE-2024-27038 CVE-2024-26973 CVE-2024-35853 CVE-2024-27047 CVE-2024-36007 CVE-2024-27024 CVE-2024-26750 CVE-2024-26833 CVE-2024-26960 CVE-2024-26929 CVE-2023-52488 CVE-2024-27417 CVE-2024-26922 CVE-2024-26863 CVE-2024-35890 CVE-2024-27015 CVE-2024-27395 CVE-2024-26779 CVE-2024-27419 CVE-2024-27013 CVE-2024-26981 CVE-2024-26798 CVE-2024-26895 CVE-2024-35922 CVE-2023-52699 CVE-2024-26883 CVE-2024-35871 CVE-2024-27410 CVE-2024-26884 CVE-2024-26885 CVE-2024-27074 CVE-2024-26751 CVE-2024-26857 CVE-2024-26848 CVE-2024-26901 CVE-2024-35844 CVE-2024-35809 CVE-2024-26687 CVE-2024-35988 CVE-2024-26835 CVE-2024-26764 CVE-2024-27020 CVE-2024-35907 CVE-2024-35886 CVE-2024-27077 CVE-2024-26787 CVE-2024-26950 CVE-2024-26974 CVE-2024-35905 CVE-2024-27008 CVE-2024-26744 CVE-2024-35935 CVE-2024-26988 CVE-2024-26748 CVE-2024-26776 CVE-2024-26907 CVE-2024-27053 CVE-2024-35970 CVE-2024-35950 CVE-2024-35854 CVE-2024-35822 CVE-2024-26961 CVE-2024-26733 CVE-2024-26773 CVE-2024-27390 CVE-2024-35888 CVE-2024-36029 CVE-2024-26643 CVE-2024-35821 CVE-2024-35819 CVE-2024-26809 CVE-2024-35984 CVE-2024-26851 CVE-2024-35940 CVE-2024-26654 CVE-2024-35910 CVE-2024-26891 CVE-2024-26793 CVE-2024-35938 CVE-2024-26736 CVE-2024-26583 CVE-2024-26870 CVE-2024-35828 CVE-2024-35885 CVE-2024-35958 CVE-2024-26889 CVE-2024-35899 CVE-2024-26839 CVE-2024-26894 CVE-2024-26937 CVE-2024-35925 CVE-2024-35933 CVE-2024-26771 CVE-2024-26923 CVE-2024-26852 CVE-2024-26924 CVE-2024-26872 CVE-2024-26774 CVE-2024-35930 CVE-2024-27065 CVE-2024-26993 CVE-2024-27034 CVE-2024-36020 CVE-2024-26802 CVE-2024-26976 CVE-2022-48808 CVE-2024-35847 CVE-2024-26996 CVE-2024-36025 CVE-2023-52652 CVE-2024-27403 CVE-2023-52447 CVE-2024-27037 CVE-2024-27413 CVE-2024-26749 CVE-2024-26956 CVE-2024-26958 CVE-2024-26754 CVE-2024-26812 CVE-2024-26772 CVE-2024-27436 CVE-2024-27437 CVE-2024-35912 CVE-2024-35805 CVE-2024-26845 CVE-2024-35990 CVE-2024-35791 CVE-2024-26906 CVE-2024-27039 CVE-2024-26915 CVE-2024-26970 CVE-2024-26782 CVE-2024-26813 CVE-2023-52645 CVE-2024-26935 CVE-2024-27076 CVE-2024-35823 CVE-2024-26743 CVE-2024-26846 CVE-2024-26811 CVE-2024-26989 CVE-2024-26642 CVE-2024-26659 CVE-2024-26766 CVE-2024-27393 CVE-2024-26859 CVE-2024-35898 CVE-2024-35893 CVE-2023-52640 CVE-2024-26795 CVE-2024-27009 CVE-2024-26791 CVE-2024-27043 CVE-2024-26934 CVE-2024-27051 CVE-2024-26804 CVE-2024-26878 CVE-2024-27030 CVE-2024-27000 CVE-2024-26777 CVE-2024-35825 CVE-2024-27415 CVE-2024-27001 CVE-2024-27004 CVE-2024-26769 CVE-2024-26816 CVE-2024-35807 CVE-2024-35900 CVE-2024-35851 CVE-2024-27052 CVE-2024-26805 CVE-2024-35804 CVE-2024-35944 CVE-2024-35895 CVE-2024-26897 CVE-2024-27045 CVE-2024-26814 CVE-2024-26801 CVE-2024-26874 CVE-2024-35982 CVE-2024-35915 CVE-2024-26820 CVE-2024-26603 CVE-2024-35997 CVE-2024-26688 CVE-2024-27054 CVE-2024-26828 CVE-2024-35857 CVE-2023-52662 CVE-2024-35989 CVE-2024-36005 CVE-2024-35785 CVE-2024-27396 CVE-2024-35884 CVE-2023-52650 CVE-2024-26882 CVE-2024-26879 CVE-2024-26898 CVE-2024-27388 CVE-2024-35879 CVE-2024-35918 CVE-2024-35978 CVE-2024-26585 CVE-2024-35872 CVE-2023-52497 CVE-2024-26778 CVE-2024-26999 CVE-2024-27046 CVE-2023-52434 CVE-2024-26862 CVE-2024-26810 CVE-2024-35796 CVE-2024-35960 CVE-2024-35969 CVE-2024-26966 CVE-2024-26856 CVE-2024-35936 CVE-2024-35955 CVE-2024-26763 CVE-2024-35806 CVE-2024-27059 CVE-2024-35855 CVE-2024-36008 CVE-2024-27075 CVE-2023-52620 CVE-2024-26931 CVE-2024-35813 CVE-2024-26788 CVE-2024-27412 CVE-2024-26861 CVE-2024-36004 CVE-2024-26951 CVE-2024-26903 CVE-2024-26584 CVE-2024-35877 CVE-2024-26792 CVE-2024-27416 CVE-2024-27432 CVE-2024-26651 CVE-2024-35852 CVE-2024-35973 CVE-2023-52656 CVE-2024-26965 CVE-2024-26969 CVE-2024-26840 CVE-2024-26817 CVE-2024-27028 CVE-2024-26752 CVE-2024-27016 CVE-2023-52641 CVE-2024-35789 CVE-2024-27078 CVE-2024-26994 CVE-2024-26629 CVE-2024-26803 CVE-2024-26977 CVE-2024-35830 CVE-2024-27019 CVE-2024-26957 CVE-2024-36006 CVE-2024-35817 CVE-2024-26601 CVE-2024-35845 CVE-2024-35897 CVE-2024-27414 CVE-2024-26855 CVE-2024-26877 CVE-2024-35829 CVE-2024-35896 CVE-2024-26875 CVE-2024-27405 CVE-2024-26747 CVE-2023-52644 CVE-2024-26881 CVE-2024-26735 CVE-2024-26843 CVE-2024-26926 CVE-2024-26880 CVE-2024-26964 CVE-2024-27044 CVE-2024-26737 CVE-2024-27431 CVE-2024-26955 CVE-2024-26790 CVE-2024-26925 CVE-2024-26838 CVE-2024-26984 CVE-2024-25739 CVE-2024-24861 CVE-2024-24859 CVE-2024-24858 CVE-2024-24857 CVE-2024-23307 CVE-2024-22099 CVE-2024-21823 CVE-2024-0841 CVE-2023-7042 CVE-2023-6270 CVE-2022-38096 5.15 - Raspi [USN-6922-1] Linux kernel vulnerabilities 4 CVEs addressed in Jammy (22.04 LTS) CVE-2024-25739 CVE-2024-24859 CVE-2024-24858 CVE-2024-24857 6.5 - NVIDIA [USN-6923-1, USN-6923-2] Linux kernel vulnerabilities 6 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2024-36016 CVE-2024-27017 CVE-2023-52752 CVE-2024-26952 CVE-2024-26886 CVE-2024-25742 5.15 - generic, AWS, GCP, GKE, HWE, Intel-IOTG, KVM, LowLatency, NVIDIA, Oracle, IBM, Raspi [USN-6921-1, USN-6921-2] Linux kernel vulnerabilities 7 CVEs addressed in Noble (24.04 LTS) CVE-2024-36016 CVE-2024-36008 CVE-2024-35984 CVE-2024-35992 CVE-2024-35997 CVE-2024-35990 CVE-2024-25742 6.8 - generic, AWS, GCP, GKE, IBM, NVIDIA, OEM, Raspi, LowLatency [USN-6924-1, USN-6924-2] Linux kernel vulnerabilities 7 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS) CVE-2024-26583 CVE-2022-48655 CVE-2024-26907 CVE-2021-47131 CVE-2024-26585 CVE-2024-36016 CVE-2024-26584 5.4 - generic, AWS, Azure, Bluefield, GCP, GKE, HWE, IBM, IOT, KVM, Raspi, Xilinx-ZynqMP [USN-6925-1] Linux kernel vulnerability 1 CVEs addressed in Trusty ESM (14.04 ESM) CVE-2024-26882 3.13 - generic, lowlatency, server, virtual [USN-6926-1] Linux kernel v…

    Full show notes at the publisher

    Episode 232 Jul 05, 2024
    Show notes

    Overview This week we deep-dive into one of the best vulnerabilities we’ve seen in a long time regreSSHion - an unauthenticated, remote, root code-execution vulnerability in OpenSSH. Plus we cover updates for Plasma Workspace, Ruby, Netplan, FontForge, OpenVPN and a whole lot more. This week in Ubuntu Security Updates 39 unique CVEs addressed [USN-6843-1] Plasma Workspace vulnerability (01:23) 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-36041 KDE Session Manager - used for restoring previously running applications at next boot Provides ability to clients to connect to it via Inter-Client Exchange (ICE) protocol - protocol within X for allowing X clients to interact with one-another Since X supports remote clients, is important to authenticate connections - in this case KDE SM would authenticate to ensure the connection was coming from the local machine - but this could then allow any local user to connect to another users SM and hence use the session management features to set some arbitrary application to be run when the session is restored - as that other user [USN-6852-1, USN-6852-2] Wget vulnerability (02:42) 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-38428 mishandled semicolons in userinfo of a URL - this is the user@host:port combination - so would possibly then use a different hostname than the one the user expected [USN-6853-1] Ruby vulnerability (03:12) 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-27280 Provides methods ungetbyte()/ungetc() to push-back characters on an IO stream - would possibly read beyond the end of the buffer - OOB read [USN-6851-1] Netplan vulnerabilities (03:37) 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2022-4968 Two different issues When configuring a Wireguard interface, would write the wireguard private key into the netplan interface configuration - but would then leave this with world-readable permissions This can either be specified as the filename to the private key OR the private key itself - so if had chosen to specify the actual private key, this is now world-readable to any other user Fixed to use restrictive permissions on the generated configuration files and to fixup any existing ones as well Failed to escape control characters in various backend files - a malicious application that is able to create a netplan configuration could then abuse this to get code execution as netplan [USN-6851-2] Netplan regression Affecting Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) Failed to properly do the permissions fixup on already existing files [USN-6854-1] OpenSSL vulnerability (05:10) 1 CVEs addressed in Jammy (22.04 LTS) CVE-2022-40735 Related to a historical vulnerability - https://dheatattack.gitlab.io/ - CVE-2002-20001 DoS against Diffie-Hellman key exchange protocol - during key negotiation a client can trigger expensive CPU calculations -> CPU-based DoS [USN-6856-1] FontForge vulnerabilities (05:50) 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-25082 CVE-2024-25081 Uses various external utilities to do things like decompress archive files etc However, would do this via the system() system-call - which spawns a shell - so if a filename contained any shell metacharacters, could then just easily get arbitrary code execution Changed to use the utility functions from glib that do not spawn a shell and instead just exec() the expected command directly [USN-6857-1] Squid vulnerabilities (06:48) 6 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM) CVE-2024-25617 CVE-2023-50269 CVE-2023-49286 CVE-2023-49285 CVE-2022-41318 CVE-2021-28651 [USN-6566-2] SQLite vulnerability 1 CVEs addressed in Bionic ESM (18.04 ESM) CVE-2023-7104 [USN-5615-3] SQLite vulnerability 3 CVEs addressed in Trusty ESM (14.04 ESM) CVE-2021-20223 CVE-2020-35527 CVE-2020-35525 [USN-6855-1] libcdio vulnerability (06:58) 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-36600 ISO file parser - used strcpy() instead of strncpy() so could be made to quite easily achieve buffer overflow and hence possible code-execution [USN-6858-1] eSpeak NG vulnerabilities (07:33) 5 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2023-49994 CVE-2023-49993 CVE-2023-49992 CVE-2023-49991 CVE-2023-49990 speech synthesiser - pass file to it and it will read it aloud various buffer overflows when parsing different formats - found by a researcher via fuzzing [USN-6844-2] CUPS regression (07:51) Affecting Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) [USN-6844-1] CUPS vulnerability from Episode 231 [USN-6860-1] OpenVPN vulnerabilities (07:57) 2 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-5594 CVE-2024-28882 Client was able to keep the session alive even when the server had been instructed to disconnect the client Client was able to send junk/non-printable characters in the control channel since would then get logged and possibly allow to corrupt the log file or cause high CPU load [USN-6862-1] Firefox vulnerabilities (08:27) 13 CVEs addressed in Focal (20.04 LTS) CVE-2024-5696 CVE-2024-5695 CVE-2024-5694 CVE-2024-5688 CVE-2024-5701 CVE-2024-5700 CVE-2024-5699 CVE-2024-5698 CVE-2024-5697 CVE-2024-5693 CVE-2024-5691 CVE-2024-5690 CVE-2024-5689 127.0.2 [USN-6859-1] OpenSSH vulnerability 1 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-6387 Goings on in Ubuntu Security Community Deep-dive into regreSSHion - Remote Unauthenticated Code Execution Vulnerablity in OpenSSH https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt https://ubuntu.com/blog/ubuntu-regresshion-security-fix First notified late last week by Qualys of a pending update for OpenSSH which fixes a newly discovered unauthenticated remote code execution vulnerability - as root - this is about as bad as it can get Exactly the kind of thing that “Jia Tan” spent all that time working on in xz-utils to try and achieve (xz-utils backdoor and Ubuntu from Episode 224) Qualys are quite specific to note that this only affects OpenSSH on glibc (so distros which use say musl are not affected) - due to the intricacies of the vulnerablity and how they exploit it Also OpenSSH is quite carefully designed - employs privilege separation to try keep the privileged part as minimal as possible - but in this case, the vuln is in this privielged part, hence why code execution as root OpenSSH developers released 9.8p1 on Monday this week which has some quite significant refactoring to help address this vuln - in particular it includes functionality similar to fail2ban to penalise clients that appear to be malicious AND it employs even more privilege separation than before Qualys are quite careful to say that they think OpenSSH is one of the most secure pieces of software in the world “near-flawless implementation” with inspirational defense-in-depth - but clearly bugs still slip through In this case is a signal handler race condition Diversion - what are signals? signal (7) simple, asynchronous form of IPC which allows sending a single piece of information - the type of signal many different types - e.g. SIGSEGV for invalid memory access, or SIGFPE for a math error - or can be sent by other processes - SIGTERM / SIGKILL / SIGINT process can then set itself up so that a particular signal handler function of its choosing is invoked for a given signal when a signal is sent to a process, it is queued up and then delivered to a process the next time the kernel returns from kernel space to that process - ie. when returning from a system-call or scheduling of that process to deliver it, kernel constructs an entirely new stack frame and passes execution to the signal handler function - this runs and then eventually returns control back to the original thread of the process Signal handlers are special - since they run on their own special stack and outside of the normal thread of execution of the process, they can potentially cause issues if they do things which modify the global state of the process - many regular functions are off-limits within signal handlers since they can inadvertently modify such global state only some functions are hence async-signal-safe (7) list contains a lot of functions BUT many which might ordinarily get used are not included - in particular malloc()/free() This vuln was caused then by use of one of these async unsafe functions OpenSSH has a functionality called LoginGraceTime which allows an admin to configure how long OpenSSH will allow a client to take to login - if they don’t log in in that time then it closes the connection Since this code is all single-threaded, can’t just have the code which is listening to the client connection bail out easily - so instead this is implemented via the SIGALARM signal - used by the alarm (2) system call to configure the SIGALARM signal to be delivered to a process some number of seconds later Unfortunately in the signal handler function for this SIGALARM, OpenSSH can end up calling syslog() when trying to which is one of those unsafe functions in glibc syslog() will potentially call malloc()/free() which as we mentioned earlier is not async safe it is possible that the original thread may be in the middle of a call to malloc() / free() and then SIGALARM signal is delivered (since malloc()/free() calls brk (2) system call under the hood and so a pending signal SIGALARM may be delivered on return from brk()) both the original thread and the signal handler are then calling malloc() at the same time - corrupting the global state of the heap etc as we know, if can corrupt the heap state ‘correctly’ can get code execution but requires the ability to win this race In fact, this is a reoccurrence of historical CVE-2006-5051 - discovered by Mark Dowd but subsequently fixed code in question was refactored in October 2020 and released in OpenSSH 8.5p1 which would then call syslog() during the SIGALARM signal handler To exploit this, Qualys take inspiration from a 2001 paper by Michal Zalewski (aka lcamtuf previously Director of Information Security Engineering at Google and now VP Security Engineering at Snap (ie Snapchat etc)) Even so, it is an incredibly difficult path to get to a working exploit - both since this is a race-condition so it is very hard to get the right timing conditions and second due to defence-in-depth measures like ASLR First develop an exploit for the original 2006 CVE against a couple older versions OpenSSH 3.4p1 on Debian Woody even on i386 which has much worse ASLR than amd64, takes 10,000 tries to win the race - even then with 10 concurrent connections and each with a LoginGraceTime of 5 minutes - ~1week to get a remote root shell OpenSSH 4.2p1 on Ubuntu 6.06 (Dapper Drake) - first LTS version of Ubuntu - this vuln was patched during the lifetime of 6.06 release but original install media still contains the unpatched version Similarly, takes ~10,000 tries to win the race - with LoginGraceTime of only 2 minutes can reduce the time to get a remote root shell to 1-2 days Finally, OpenSSH 9.2p1 from current Debian stable on i386 10,000 tries - now 100 connections with 2 minutes grace time - in practice still ~6-8 hours since still have to guess the address used by glibc and due to ASLR is only 50% accurate All of these are lab conditions - VMs with quite stable network - and only on i386 - but Qualys say they were starting on an exploit even for amd64 but didn’t continue after they noticed a related bug report about this async-unsafe signal handling - so decided that may draw attention to the issue and others may discover the vuln and start exploiting it - so best to disclose it in its current state For Ubuntu, since this only affects version since 8.5p1, only 22.04 LTS onwards were affected - we released patches on Monday - unattended-upgrades is enabled by default on all relases since 16.04 LTS anyway - checks for and installs security updates every 24 hours - so any affected Ubuntu users would likely have been automatically patched within ~24 of the vuln becoming public (and the restart logic in OpenSSH would have restarted the service when it got upgraded as well) Other thing which is more internal for Ubuntu is that Qualys explicitly called out OpenSSH in 24.04 LTS as having a deficiency in the enablement of ASLR - since we are using systemd socket activation we disable reexec support for OpenSSH - so it never reexecutes itself for its child processes - so they never get the benefit of ASLR - BUT by chance it also makes this unexploitable since it changes the use of syslog() within OpenSSH so that syslog() gets called early on in the use of OpenSSH and so then when it gets called in the SIGALARM signal handler it doesn’t do the same memory allocation and hence can’t be used to corrupt memory and get code execution Get in contact security@ubuntu.com #ubuntu-security on the Libera.Chat IRC network ubuntu-hardened mailing list Security section on discourse.ubuntu.com @ubuntusecurity@fosstodon.org, @ubuntu_sec on twitter

    Full show notes at the publisher

    Episode 231 Jun 28, 2024
    Show notes

    Overview A look into CISA’s Known Exploited Vulnerability Catalogue is on our minds this week, plus we look at vulnerability updates for gdb, Ansible, CUPS, libheif, Roundcube, the Linux kernel and more. This week in Ubuntu Security Updates 175 unique CVEs addressed [USN-6842-1] gdb vulnerabilities (01:10) 6 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2023-39130 CVE-2023-39129 CVE-2023-39128 CVE-2023-1972 CVE-2022-4285 CVE-2020-16599 a couple of these are inherited from binutils as they share that code - parsing of crafted ELF executables -> NULL ptr deref or possible heap based buffer overflow -> DoS/RCE other stack and heap buffer overflows as well - parsing of crafted ada files and crafted debug info files as well -> DoS/RCE [USN-6845-1] Hibernate vulnerability (02:12) 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS) CVE-2020-25638 Object relational-mapping (ORM) library for Java SQL injection in the JPA Criteria API implementation - could allow unvalidated literals when they are used in the SQL comments of a query when logging is enabled - fixed by properly escaping comments in this case [USN-6846-1] Ansible vulnerabilities (02:46) 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2023-5764 CVE-2022-3697 Possibly would leak the password into log file when using the AWS EC2 module since failed to validate the tower_callback (nowadays is called aap_callback - Ansible Automation Platform) parameter appropriately Allows to mark variables as unsafe - in that they may come from an external, untrusted source - won’t get evaluated/expanded when used to avoid possible info leaks etc - various issues where ansible would fail to respect this and essentially forget they were tagged as unsafe and end up exposing secrets as a result [USN-6844-1] CUPS vulnerability (04:08) 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-35235 When starting, cups would arbitrarily chmod the socket specified as the Listen parameter to make it world-writable - if this was a symlink, would then make the target of the symlink world-readable - in general the cups config file is only writable by root so requires some other vuln to be able to exploit it where you can get write access to the config file to exploit it OR be able to replace the regular cups socket path with a user-controlled symlink - but if you can, then you can even change the cups config itself to be world-writable and hence modify other parameters like the user and group that cups should run as, as well as a crafted FoomaticRIPCommandLine then can run arbitrary commands as root [USN-6849-1] Salt vulnerabilities (06:20) 2 CVEs addressed in Trusty ESM (14.04 ESM) CVE-2020-11652 CVE-2020-11651 Failed to properly validate paths in some methods and also failed to restrict access to other methods, allowing them to be used without authentication - could then either allow arbitrary directory access or the ability to retrieve tokens from the master or run arbitrary commands on minions [USN-6746-2] Google Guest Agent and Google OS Config Agent vulnerability (06:44) 1 CVEs addressed in Noble (24.04 LTS) CVE-2024-24786 A vuln in the embedded golang protobuf module - when parsing JSON could end up in an infinite loop -> DoS [USN-6850-1] OpenVPN vulnerability (07:04) 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM) CVE-2022-0547 [USN-5347-1] OpenVPN vulnerability from Episode 155 - possibly gets confused when using multiple authentication plugins and deferred authentication [USN-6847-1] libheif vulnerabilities (07:36) 8 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2023-49464 CVE-2023-49463 CVE-2023-49462 CVE-2023-49460 CVE-2023-29659 CVE-2023-0996 CVE-2020-23109 CVE-2019-11471 First time to mention libheif on the podcast - High Efficiency Image File Format - part of the MPEG-H standard - container format used to store images or sequences of images Commonly seen due to its use by Apple for images on iPhone C++ - usual types of issues UAF, buffer overflows, floating point exception etc most found through fuzzing [USN-6848-1] Roundcube vulnerabilities (08:21) 4 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-37384 CVE-2024-37383 CVE-2023-47272 CVE-2023-5631 webmail front-end for IMAP 2 different possible XSS issues due to mishandling of SVG - email containing an SVG could embed JS that then gets loaded when the email is viewed Also possible XSS through a crafted user preference value - similarly through a crafted Content-Type/Content-Disposition header which can be used for attachment preview/download [USN-6819-4] Linux kernel (Oracle) vulnerabilities (09:21) 149 CVEs addressed in Jammy (22.04 LTS) CVE-2024-26631 CVE-2023-52694 CVE-2023-52685 CVE-2023-52682 CVE-2024-35835 CVE-2023-52446 CVE-2023-52487 CVE-2023-52619 CVE-2023-52627 CVE-2023-52674 CVE-2024-26598 CVE-2023-52679 CVE-2023-52455 CVE-2024-26671 CVE-2023-52444 CVE-2023-52683 CVE-2023-52690 CVE-2024-35842 CVE-2023-52610 CVE-2024-26607 CVE-2023-52445 CVE-2023-52497 CVE-2023-52488 CVE-2024-26623 CVE-2023-52607 CVE-2023-52677 CVE-2023-52457 CVE-2024-26673 CVE-2024-26594 CVE-2024-26638 CVE-2023-52621 CVE-2023-52594 CVE-2023-52468 CVE-2024-26647 CVE-2023-52492 CVE-2023-52452 CVE-2024-26615 CVE-2023-52448 CVE-2023-52698 CVE-2023-52443 CVE-2023-52614 CVE-2023-52494 CVE-2024-35837 CVE-2024-26582 CVE-2023-52632 CVE-2023-52680 CVE-2023-52595 CVE-2023-52626 CVE-2023-52495 CVE-2023-52451 CVE-2023-52583 CVE-2023-52469 CVE-2023-52584 CVE-2023-52450 CVE-2024-26608 CVE-2023-52609 CVE-2023-52464 CVE-2023-52591 CVE-2024-26645 CVE-2024-35838 CVE-2023-52470 CVE-2023-52456 CVE-2023-52589 CVE-2024-26585 CVE-2023-52696 CVE-2023-52633 CVE-2023-52462 CVE-2023-52597 CVE-2023-52587 CVE-2024-26584 CVE-2024-26636 CVE-2023-52491 CVE-2023-52493 CVE-2024-26627 CVE-2023-52465 CVE-2023-52687 CVE-2023-52593 CVE-2024-26595 CVE-2024-26629 CVE-2024-35840 CVE-2023-52666 CVE-2024-26633 CVE-2023-52686 CVE-2023-52467 CVE-2023-52667 CVE-2023-52449 CVE-2023-52473 CVE-2023-52670 CVE-2024-26649 CVE-2023-52498 CVE-2023-52693 CVE-2024-26583 CVE-2023-52678 CVE-2023-52675 CVE-2023-52489 CVE-2024-26640 CVE-2024-26618 CVE-2023-52599 CVE-2024-26634 CVE-2023-52608 CVE-2024-26625 CVE-2023-52486 CVE-2024-26632 CVE-2023-52669 CVE-2023-52676 CVE-2023-52635 CVE-2023-52664 CVE-2024-35841 CVE-2023-52598 CVE-2023-52458 CVE-2024-26644 CVE-2023-52697 CVE-2023-52617 CVE-2024-26612 CVE-2023-52672 CVE-2023-52490 CVE-2024-35839 CVE-2024-26610 CVE-2024-26616 CVE-2023-52588 CVE-2023-52623 CVE-2024-26669 CVE-2023-52692 CVE-2024-26620 CVE-2023-52606 CVE-2024-26592 CVE-2023-52616 CVE-2024-26641 CVE-2023-52622 CVE-2023-52611 CVE-2023-52453 CVE-2023-52681 CVE-2024-26586 CVE-2023-52472 CVE-2024-26646 CVE-2024-26670 CVE-2023-52454 CVE-2024-26668 CVE-2023-52447 CVE-2023-52463 CVE-2023-52618 CVE-2023-52691 CVE-2024-26808 CVE-2023-52612 CVE-2024-24860 CVE-2024-23849 CVE-2023-6536 CVE-2023-6535 CVE-2023-6356 Of all these CVEs, 6 had a high priority rating many are due to bugs in the async handling of cryto operations in the in-kernel TLS implementation CVE-2024-26582 and CVE-2024-26584 - both reported by Google kernelCTF program (talked about back in [USN-6766-2] Linux kernel vulnerabilities from Episode 228) first is UAF in TLS handling of scattter/gather arrays second is UAF when crypto requests get backlogged and the underlying crypto engine can’t process them all in time - can then end up having the async callback invoked twice CVE-2024-26585 very similar - UAF in handling of crypto operations from TLS - thread which handles the socket could close this before all the operations had been scheduled CVE-2024-26583 - similarly, race between async notify event and socket close -> UAF UAF in BPF and a UAF in netfilter - also reported via Google kernelCTF - both able to be triggered via an unpriv userns Goings on in Ubuntu Security Community Discussion of CISA KEV US Gov Cybersecurity & Infrastructure Security Agency “America’s Cyber Defense Agency” National Coordinator for Critical Infrastructure Security and Resilience Publish various guidance for organisations around topics of cybersecurity for instance, recently published a report “Exploring Memory Safety in Critical Open Source Projects” Joint guidance (FBI, ASD / ACSC & Candadian CSC) Builds on the previous case for memory safe roadmaps by looking at the prevalence of memory unsafe languages in various critical open source projects Also maintain the KEV - Known Exploitable Vulnerabilities Catalog “authoritative source of vulnerabilities that have been exploited in the wild” Mandates for federal civilian agencies in the US to remediate KEV vulns within various timeframes Also recommend that anyone else monitors this list and immediately addresses these vulns as part of the vuln remediation plan List of vilns that are causing immediate harm based on observed adversarial activity Various requirements to be listed in the KEV: CVE ID assigned Evidence it has been or is being actively exploited reliable evidence that execution of malicious code was performed on a system by an unauthorised actor also includes both attempted and successful exploitation (e.g. includes honeypots as well as real systems) Clear remediation guidelines An update is available and should be applied OR Vulnerable component should be removed from networks etc if it is EOL and cannot be updated available as CSV or JSON Currently lists 1126 CVEs including: Accellion File Transfer Appliances Adobe Reader, Flash Player Apache HTTP Server, Struts (Solarwinds), Log4j Huge number of Apple iOS etc (WebKit and more) Atlassian Confluence Citrix Gateways Exim Fortinet Gitlab Google Chromium ImageMagick Microsoft Windows and Exchange Mozilla Firefox Ivanti Pulse Connect Security SaltStack VMWare WordPress Oldest CVEs are 2 against Windows from 2002 and 2004 Newest include 26 2024 CVEs - various Chromium, Windows, Android Pixel, Ivanti and more interestingly includes ARM Mali GPU Driver CVE-2024-4610 - this affects the Bifrost and Valhall drivers - in Ubuntu we only ship the related Midgard driver back in bionic and focal so not affected by this one but as you may have noticed, lots that we potentially are affected by Apache HTTP Server, Exim, Firefox, Thunderbird - plus OpenJDK, GNU C Library, Bash, Roundcube (mentioned earlier but not this particular vuln), WinRAR (unrar), not to mention a number against the Linux kernel all for Linux kernel are privesc - most against either netfilter or various other systems like perf, AF_PACKET, tty, ptrace, futex and others For Ubuntu, not surprisingly, we prioritise these vulnerabilities in our patching process Get in contact security@ubuntu.com #ubuntu-security on the Libera.Chat IRC network ubuntu-hardened mailing list Security section on discourse.ubuntu.com @ubuntusecurity@fosstodon.org, @ubuntu_sec on twitter

    Full show notes at the publisher

    Episode 230 Jun 20, 2024
    Show notes

    Overview

    This week we bring you a special edition of the podcast, featuring an interview between Ijlal Loutfi and Karen Horovitz who deep-dive into Confidential Computing. Ranging from a high-level discussion of the need for and the features provided by confidential computing, through to the specifics of how this is implemented in Ubuntu and a look at similar future security technologies that are on the horizon.

    Confidential Computing with Ijlal Loutfi and Karen Horovitz (01:17)

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntusecurity@fosstodon.org, @ubuntu_sec on twitter

    Episode 229 May 31, 2024
    Show notes

    Overview As the podcast winds down for a break over the next month, this week we talk about RSA timing side-channel attacks and the recently announced DNSBomb vulnerability as we cover security updates in VLC, OpenSSL, Netatalk, WebKitGTK, amavisd-new, Unbound, Intel Microcode and more. This week in Ubuntu Security Updates 152 unique CVEs addressed [USN-6783-1] VLC vulnerabilities (00:54) 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2023-47360 CVE-2023-47359 integer underflow and a heap buffer overflow -> RCE [USN-6663-3] OpenSSL update (01:40) Affecting Noble (24.04 LTS) [USN-6663-1] OpenSSL update from Episode 220 - hardening improvement to return deterministic random bytes instead of an error when an incorrect padding length is detected during PKCS#1 v1.5 RSA to avoid this being used for possible Bleichenbacher timing attacks [USN-6673-3] python-cryptography vulnerability (02:32) 1 CVEs addressed in Noble (24.04 LTS) CVE-2024-26130 [USN-6673-1] python-cryptography vulnerabilities from Episode 220 - counterpart to the OpenSSL update mentioned earlier [USN-6736-2] klibc vulnerabilities (02:43) 4 CVEs addressed in Noble (24.04 LTS) CVE-2022-37434 CVE-2018-25032 CVE-2016-9841 CVE-2016-9840 [USN-6736-1] klibc vulnerabilities from Episode 228 [USN-6784-1] cJSON vulnerabilities (02:58) 3 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-31755 CVE-2023-50472 CVE-2023-50471 2 different researchers fuzzing cJSON APIs all different NULL ptr deref - requires particular / “incorrect” or possible misuse use of the APIs (like passing in purposefully corrupted values) so unlikely to be an issue in practice [USN-6785-1] GNOME Remote Desktop vulnerability (03:52) 1 CVEs addressed in Noble (24.04 LTS) CVE-2024-5148 Discovered by a member of the SUSE security team when reviewing g-r-d Exposed various DBus services that were able to be called by any unprivileged user which would then return the SSL private key used to encrypt the connection - so could allow a local user to possibly spy on the sessions of other users remotely connected to the system [USN-6786-1] Netatalk vulnerabilities (04:45) 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2022-22995 Apple file sharing implementation for Linux If the same path was shared via both AFP and SMB then a remote attacker could combine various operations through both file-systems (like creating a crafted symlink, which would then be followed during a second operation where a file is renamed) to allow them to overwrite arbirary files and hence achieve arbitrary code execution on the host [USN-6788-1] WebKitGTK vulnerabilities (05:48) 1 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-27834 Possible pointer authentication bypass - used on arm64 in particular - demonstrated at Pwn2Own earlier this year by Manfred Paul - $60k [USN-6789-1] LibreOffice vulnerability (06:28) 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-3044 Unchecked script execution triggered when clicking on a graphic - allows to run arbitrary scripts without the usual prompt [USN-6790-1] amavisd-new vulnerability (07:09) 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-28054 MTA / AV interface - often used in conjunction with Postfix, not just for AV but also can be used to do DKIM verification and integration with spamassassin etc Misinterpreted MIME message boundaries in emails, allowing email parts to possibly bypass usual checks [USN-6791-1] Unbound vulnerability (07:46) 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-33655 DNSBomb attack announced recently at IEEE S&P - affecting multiple different DNS implementations including BIND, Unbound, PowerDNS, Knot, DNSMasq and others Unbound itself was not necessarily vulnerable to such an attack specifically, but could be used to generate such an attack against others - in particular Unbound had the highest amplification factor of ~22k times - next highest was DNSMasq at ~3k times Fix involves introducing a number of timeout parameters for various operations and discarding operations if they take longer than this to avoid the ability to “store up” responses to be released at a later time [USN-6793-1] Git vulnerabilities (09:31) 5 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-32465 CVE-2024-32021 CVE-2024-32020 CVE-2024-32004 CVE-2024-32002 [USN-6792-1] Flask-Security vulnerability 1 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2021-23385 [USN-6794-1] FRR vulnerabilities 4 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-34088 CVE-2024-31951 CVE-2024-31950 CVE-2024-31948 [USN-6777-4] Linux kernel (HWE) vulnerabilities (09:40) 17 CVEs addressed in Xenial ESM (16.04 ESM) CVE-2023-52583 CVE-2024-26801 CVE-2024-26805 CVE-2024-26735 CVE-2024-26622 CVE-2021-46981 CVE-2023-52566 CVE-2023-52604 CVE-2024-26704 CVE-2024-26614 CVE-2023-52602 CVE-2024-26635 CVE-2023-52439 CVE-2023-52601 CVE-2023-52530 CVE-2023-52524 CVE-2023-47233 [USN-6777-1] Linux kernel vulnerabilities from Episode 228 AWS HWE kernel (4.15) [USN-6795-1] Linux kernel (Intel IoTG) vulnerabilities (10:00) 95 CVEs addressed in Jammy (22.04 LTS) CVE-2023-52588 CVE-2023-52622 CVE-2024-26920 CVE-2023-52607 CVE-2023-52530 CVE-2023-52435 CVE-2023-52615 CVE-2024-26684 CVE-2024-26829 CVE-2024-26614 CVE-2023-52489 CVE-2023-52642 CVE-2023-52583 CVE-2024-26696 CVE-2024-26627 CVE-2024-26636 CVE-2024-26663 CVE-2024-26702 CVE-2024-26685 CVE-2024-26715 CVE-2024-26668 CVE-2023-52492 CVE-2023-52498 CVE-2024-26825 CVE-2023-52587 CVE-2024-26615 CVE-2023-52608 CVE-2024-26660 CVE-2023-52601 CVE-2024-26910 CVE-2024-26676 CVE-2023-52493 CVE-2024-26673 CVE-2024-26707 CVE-2024-26698 CVE-2024-26641 CVE-2023-52494 CVE-2023-52595 CVE-2024-26697 CVE-2023-52617 CVE-2024-26675 CVE-2024-26610 CVE-2024-26606 CVE-2023-52614 CVE-2024-26712 CVE-2023-52635 CVE-2024-26689 CVE-2024-26916 CVE-2024-26665 CVE-2023-52623 CVE-2024-26635 CVE-2024-26602 CVE-2023-52597 CVE-2023-52619 CVE-2024-26808 CVE-2024-26600 CVE-2024-26826 CVE-2024-26644 CVE-2024-26695 CVE-2023-52604 CVE-2024-26625 CVE-2023-52618 CVE-2024-26664 CVE-2024-26593 CVE-2023-52633 CVE-2023-52606 CVE-2024-26640 CVE-2023-52486 CVE-2023-52631 CVE-2024-26720 CVE-2023-52599 CVE-2024-26671 CVE-2024-26722 CVE-2023-52602 CVE-2024-26645 CVE-2023-52637 CVE-2024-26704 CVE-2023-52638 CVE-2024-26717 CVE-2024-26592 CVE-2023-52491 CVE-2023-52627 CVE-2023-52598 CVE-2024-26594 CVE-2023-52643 CVE-2024-26622 CVE-2023-52594 CVE-2024-26608 CVE-2024-26679 CVE-2023-52616 CVE-2024-23849 CVE-2024-2201 CVE-2022-0001 CVE-2024-1151 CVE-2023-47233 Very similar to [USN-6766-2] Linux kernel vulnerabilities from Episode 228 5.15 Intel IOTG - optimisations for various Intel IOT platforms like NUCs and Atom-based devices - low power x86 [USN-6779-2] Firefox regressions (10:30) 14 CVEs addressed in Focal (20.04 LTS) CVE-2024-4770 CVE-2024-4367 CVE-2024-4764 CVE-2024-4778 CVE-2024-4777 CVE-2024-4776 CVE-2024-4775 CVE-2024-4774 CVE-2024-4773 CVE-2024-4772 CVE-2024-4771 CVE-2024-4769 CVE-2024-4768 CVE-2024-4767 126.0.1 - drag-and-drop was broken in 126.0 [USN-6787-1] Jinja2 vulnerability (10:48) 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-34064 Incorrect handling of various HTML attributes - attacker could then possibly inject arbitrary HTML attrs/values and hence inject JS code to peform XSS attacks etc [USN-6797-1] Intel Microcode vulnerabilities (11:22) 9 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2023-46103 CVE-2023-47855 CVE-2023-45745 CVE-2023-45733 CVE-2023-43490 CVE-2023-39368 CVE-2023-38575 CVE-2023-28746 CVE-2023-22655 Latest release from upstream - mitigates against various hardware vulns A couple issues in SGX/TDX on different Intel Xeon processors: Invalid restrictions -> local root -> super-privesc Invalid input on TDX -> local root -> super-privesc Invalid SGX base key calculation -> info leak Transient execution attacks to read privileged information DoS through bus lock mishandling or through invalid instruction sequences Get in contact security@ubuntu.com #ubuntu-security on the Libera.Chat IRC network ubuntu-hardened mailing list Security section on discourse.ubuntu.com @ubuntusecurity@fosstodon.org, @ubuntu_sec on twitter

    Full show notes at the publisher

    Episode 228 May 24, 2024
    Show notes

    Overview The team is back from Madrid and this week we bring you some of our plans for the upcoming Ubuntu 24.10 release, plus we talk about Google’s kernelCTF project and Mozilla’s PDF.js sandbox when covering security updates for the Linux kernel, Firefox, Spreadsheet::ParseExcel, idna and more. This week in Ubuntu Security Updates 121 unique CVEs addressed [USN-6766-2] Linux kernel vulnerabilities (01:07) 92 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2024-26697 CVE-2023-52489 CVE-2024-26644 CVE-2024-26702 CVE-2023-52492 CVE-2023-52616 CVE-2024-26808 CVE-2024-26920 CVE-2023-52494 CVE-2024-26698 CVE-2024-26695 CVE-2023-52635 CVE-2024-26707 CVE-2024-26715 CVE-2023-52597 CVE-2023-52435 CVE-2024-26668 CVE-2023-52598 CVE-2024-26593 CVE-2023-52643 CVE-2024-26717 CVE-2023-52604 CVE-2024-26602 CVE-2024-26664 CVE-2023-52491 CVE-2024-26635 CVE-2024-26640 CVE-2024-26696 CVE-2024-26627 CVE-2023-52623 CVE-2024-26641 CVE-2024-26829 CVE-2024-26679 CVE-2024-26600 CVE-2024-26916 CVE-2024-26606 CVE-2023-52614 CVE-2024-26675 CVE-2024-26712 CVE-2023-52587 CVE-2023-52642 CVE-2024-26636 CVE-2023-52615 CVE-2024-26615 CVE-2024-26722 CVE-2023-52608 CVE-2023-52607 CVE-2023-52631 CVE-2023-52486 CVE-2024-26645 CVE-2023-52617 CVE-2024-26660 CVE-2023-52595 CVE-2023-52599 CVE-2024-26592 CVE-2024-26610 CVE-2024-26608 CVE-2024-26704 CVE-2024-26671 CVE-2024-26676 CVE-2023-52583 CVE-2024-26689 CVE-2024-26910 CVE-2023-52619 CVE-2023-52498 CVE-2023-52638 CVE-2024-26685 CVE-2024-26673 CVE-2023-52602 CVE-2023-52627 CVE-2024-26614 CVE-2024-26720 CVE-2024-26625 CVE-2024-26594 CVE-2023-52606 CVE-2024-26825 CVE-2023-52637 CVE-2023-52588 CVE-2023-52618 CVE-2024-26663 CVE-2024-26684 CVE-2023-52633 CVE-2023-52493 CVE-2024-26665 CVE-2023-52622 CVE-2024-26826 CVE-2023-52601 CVE-2023-52594 CVE-2024-23849 CVE-2024-2201 CVE-2022-0001 CVE-2024-1151 5.15 - raspi kernel on 22.04 and OEM or optional HWE on 20.04 Linux kernel CNA has been quite busy assigning both historical and recent CVEs against the kernel As discussed previously Linux kernel becomes a CNA from Episode 219 Follow up to Linux kernel CNA from Episode 220, the impact of these CVEs is often not apparent so it makes it quite hard to assign a proper priority - even the kernel CNA themselves are not assigning a CVSS score - so for now we have little information which we can glean for each of these As such, the USNs contain quite little detail and are very generic - and for each we will be assigning just a medium priority unless we have some good evidence otherwise One example here is CVE-2024-26808 - UAF in netfilter - was reported via Google’s kernelCTF (not to be confused with their kCTF which is their kubernetes-based CTF hosting platform - but which also has a vulnerabilities reward program (VRP)) - kernelCTF - program to offer rewards for exploits against the kernel - but not just any exploits - can’t use io_uring or nftables since they were disabled in their target kernel configuration due to high number of historical vulns in both subsystems base reward of $21k, $10k bonus if is reliable more than 90% of the time, additional $20k bonus if works without using unprivileged user namespaces, and a final additional $20k bonus if it is 0-day (ie not patched in the mainline tree and not disclosed anywhere - including via syzkaller) So in this case, we rated this CVE with a high priority since it is known exploitable can see it listed in their public spreadsheet [USN-6766-3] Linux kernel (AWS) vulnerabilities (04:48) 92 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2024-26697 CVE-2023-52489 CVE-2024-26644 CVE-2024-26702 CVE-2023-52492 CVE-2023-52616 CVE-2024-26808 CVE-2024-26920 CVE-2023-52494 CVE-2024-26698 CVE-2024-26695 CVE-2023-52635 CVE-2024-26707 CVE-2024-26715 CVE-2023-52597 CVE-2023-52435 CVE-2024-26668 CVE-2023-52598 CVE-2024-26593 CVE-2023-52643 CVE-2024-26717 CVE-2023-52604 CVE-2024-26602 CVE-2024-26664 CVE-2023-52491 CVE-2024-26635 CVE-2024-26640 CVE-2024-26696 CVE-2024-26627 CVE-2023-52623 CVE-2024-26641 CVE-2024-26829 CVE-2024-26679 CVE-2024-26600 CVE-2024-26916 CVE-2024-26606 CVE-2023-52614 CVE-2024-26675 CVE-2024-26712 CVE-2023-52587 CVE-2023-52642 CVE-2024-26636 CVE-2023-52615 CVE-2024-26615 CVE-2024-26722 CVE-2023-52608 CVE-2023-52607 CVE-2023-52631 CVE-2023-52486 CVE-2024-26645 CVE-2023-52617 CVE-2024-26660 CVE-2023-52595 CVE-2023-52599 CVE-2024-26592 CVE-2024-26610 CVE-2024-26608 CVE-2024-26704 CVE-2024-26671 CVE-2024-26676 CVE-2023-52583 CVE-2024-26689 CVE-2024-26910 CVE-2023-52619 CVE-2023-52498 CVE-2023-52638 CVE-2024-26685 CVE-2024-26673 CVE-2023-52602 CVE-2023-52627 CVE-2024-26614 CVE-2024-26720 CVE-2024-26625 CVE-2024-26594 CVE-2023-52606 CVE-2024-26825 CVE-2023-52637 CVE-2023-52588 CVE-2023-52618 CVE-2024-26663 CVE-2024-26684 CVE-2023-52633 CVE-2023-52493 CVE-2024-26665 CVE-2023-52622 CVE-2024-26826 CVE-2023-52601 CVE-2023-52594 CVE-2024-23849 CVE-2024-2201 CVE-2022-0001 CVE-2024-1151 5.15 - AWS on both 22.04 and 20.04 [USN-6774-1] Linux kernel vulnerabilities (05:01) 13 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10) CVE-2024-26801 CVE-2023-52601 CVE-2024-26622 CVE-2024-26635 CVE-2023-52602 CVE-2024-26614 CVE-2023-52604 CVE-2024-26805 CVE-2023-52615 CVE-2024-26704 CVE-2024-2201 CVE-2022-0001 CVE-2023-47233 6.5 - all on 23.10, HWE (all) on 22.04 [USN-6775-1] Linux kernel vulnerabilities 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2023-52530 CVE-2024-26622 CVE-2023-47233 5.15 all on 22.04, HWE (all) on 20.04 [USN-6775-2] Linux kernel vulnerabilities 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2023-52530 CVE-2024-26622 CVE-2023-47233 5.15 AWS/GKE [USN-6776-1] Linux kernel vulnerabilities 4 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS) CVE-2024-26622 CVE-2023-52530 CVE-2024-26614 CVE-2023-47233 5.4 all on 20.04, HWE (all) on 18.04 [USN-6777-1] Linux kernel vulnerabilities 17 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM) CVE-2023-52583 CVE-2024-26801 CVE-2024-26805 CVE-2024-26735 CVE-2024-26622 CVE-2021-46981 CVE-2023-52566 CVE-2023-52604 CVE-2024-26704 CVE-2024-26614 CVE-2023-52602 CVE-2024-26635 CVE-2023-52439 CVE-2023-52601 CVE-2023-52530 CVE-2023-52524 CVE-2023-47233 4.15 - all on 18.04, HWE (all) on 16.04 [USN-6777-2] Linux kernel (Azure) vulnerabilities 17 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM) CVE-2023-52583 CVE-2024-26801 CVE-2024-26805 CVE-2024-26735 CVE-2024-26622 CVE-2021-46981 CVE-2023-52566 CVE-2023-52604 CVE-2024-26704 CVE-2024-26614 CVE-2023-52602 CVE-2024-26635 CVE-2023-52439 CVE-2023-52601 CVE-2023-52530 CVE-2023-52524 CVE-2023-47233 4.15 - azure [USN-6777-3] Linux kernel (GCP) vulnerabilities 17 CVEs addressed in Xenial ESM (16.04 ESM) CVE-2023-52583 CVE-2024-26801 CVE-2024-26805 CVE-2024-26735 CVE-2024-26622 CVE-2021-46981 CVE-2023-52566 CVE-2023-52604 CVE-2024-26704 CVE-2024-26614 CVE-2023-52602 CVE-2024-26635 CVE-2023-52439 CVE-2023-52601 CVE-2023-52530 CVE-2023-52524 CVE-2023-47233 [USN-6778-1] Linux kernel vulnerabilities 14 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM) CVE-2023-52524 CVE-2023-52530 CVE-2023-52604 CVE-2024-26614 CVE-2021-46939 CVE-2024-26704 CVE-2023-52566 CVE-2024-26801 CVE-2023-52602 CVE-2024-26635 CVE-2024-26805 CVE-2024-26622 CVE-2023-52601 CVE-2023-47233 4.4 - all on 16.04, HWE on 14.04 [USN-6773-1] .NET vulnerabilities (05:34) 2 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-30046 CVE-2024-30045 dotnet 7 and 8 [USN-6779-1] Firefox vulnerabilities (05:54) 14 CVEs addressed in Focal (20.04 LTS) CVE-2024-4770 CVE-2024-4367 CVE-2024-4764 CVE-2024-4778 CVE-2024-4777 CVE-2024-4776 CVE-2024-4775 CVE-2024-4774 CVE-2024-4773 CVE-2024-4772 CVE-2024-4771 CVE-2024-4769 CVE-2024-4768 CVE-2024-4767 126.0 UAF due to multiple WebRTC threads trying to use an audio input device if it was just added type confusion bug in handling of missing fonts -> arbitrary JS execution via PDF.js (this is in the context of PDF.js which uses the quickjs JS engine inside the standard ComponentUtils.Sandbox implementation - which is the same sandbox used to execute JS from websites etc in firefox) - unrelated to this vuln but PDFs can contain JavaScript (e.g. in a form, to calculate values based on user input) also PDF.js doesn’t implement the PDF APIs related to network or disk etc to avoid possible security issues [USN-6782-1] Thunderbird vulnerabilities (07:29) 6 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-4770 CVE-2024-4367 CVE-2024-4777 CVE-2024-4769 CVE-2024-4768 CVE-2024-4767 115.11.0 same PDF.js issues and others as above from Firefox [USN-6781-1] Spreadsheet::ParseExcel vulnerability (07:51) 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2023-7101 RCE vuln via the use of eval() on untrusted user input - high profile, disclosed by Mandiant - high profile since it affected Barracuda email gateway devices and was publicly reported as being exploited against these by a Chinese APT group [USN-6780-1] idna vulnerability (08:59) 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-3651 Python module for handling internationalised domain names (RFC 5895) CPU-based DoS due to inefficient algorithm when encoding a domain name Goings on in Ubuntu Security Community Ubuntu Security Plans for 24.10 Development Cycle (09:33) Progressing the FIPS certification for 24.04 though NIST Implementation of OpenVEX and OSV data formats for machine readable vulnerability information Historically have generated OVAL data for this purpose XML-based format, existed for over 20 years more recently, OpenVEX and OSV have appeared which also serve the same purpose and have a more vibrant community around them Similarly, next version of the SPDX format will also support vulnerability descriptions too Finally, given the recent announcement that CIS has relinquished the role in sponsoring OVAL project and there doesn’t appear to be any other sponsor on the horizon, thought it was prudent to develop a “second-supplier” approach given this uncertain future for OVAL upstream likely will have more to say on this in the future Improvements to the process the team uses for working with the snap store and doing reviews etc AppArmor profile development across the 24.10 release Get in contact security@ubuntu.com #ubuntu-security on the Libera.Chat IRC network ubuntu-hardened mailing list Security section on discourse.ubuntu.com @ubuntusecurity@fosstodon.org, @ubuntu_sec on twitter

    Full show notes at the publisher

    Episode 227 May 03, 2024
    Show notes

    Overview Ubuntu 24.04 LTS is finally released and we cover all the new security features it brings, plus we look at security vulnerabilities in, and updates for, FreeRDP, Zabbix, CryptoJS, cpio, less, JSON5 and a heap more. This week in Ubuntu Security Updates 61 unique CVEs addressed [USN-6749-1] FreeRDP vulnerabilities (00:45) 7 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-32459 CVE-2024-32460 CVE-2024-32458 CVE-2024-32041 CVE-2024-32040 CVE-2024-32039 CVE-2024-22211 Bunch of issues all reported by researcher from Kaspersky - usual sorts of issues in this package - written in C etc OOB reads, heap buffer overflow, integer overflow / underflow -> OOB write [USN-6752-1] FreeRDP vulnerabilities (01:41) 4 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-32661 CVE-2024-32660 CVE-2024-32659 CVE-2024-32658 Not long after those - more CVEs announced OOB read, NULL ptr deref and memory exhaustion [USN-6657-2] Dnsmasq vulnerabilities (01:54) 3 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM) CVE-2023-28450 CVE-2023-50868 CVE-2023-50387 [USN-6657-1] Dnsmasq vulnerabilities from Episode 220 [USN-6743-3] Linux kernel (Azure) vulnerabilities (02:13) 5 CVEs addressed in Jammy (22.04 LTS) CVE-2023-52603 CVE-2024-26581 CVE-2024-26591 CVE-2024-26589 CVE-2023-52600 [USN-6750-1] Thunderbird vulnerabilities (02:19) 8 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-3861 CVE-2024-3859 CVE-2024-3857 CVE-2024-3854 CVE-2024-3302 CVE-2024-3864 CVE-2024-3852 CVE-2024-2609 115.10.1 [USN-6751-1] Zabbix vulnerabilities (02:54) 2 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS) CVE-2022-35230 CVE-2022-35229 First time Zabbix has featured in the podcast! Fixes 2 reflected XSS issues - in newer versions both require the attacker to be able to specify the user’s specific CSRF token - but in older versions only there was only a session ID which is easier to guess [USN-6753-1] CryptoJS vulnerability (03:38) 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2023-46233 Insecure default config - uses older parameters for the implementation of PBKDF2 - SHA1 with a single iteration - makes any passwords protected via PBKDF2 in crypto-js easier to brute-force from the hashed value - instead updated to use SHA256 with 250,000 rounds [USN-6754-1] nghttp2 vulnerabilities (04:32) 4 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-28182 CVE-2023-44487 CVE-2019-9513 CVE-2019-9511 Fixes for most recent issue in HTTP/2 (plus a few older HTTP/2 issues for ESM releases - HTTP/2 Rapid Reset and 2 disclosed by Netflix back in 2019 which we covered back in [USN-4099-1] nginx vulnerabilities from Episode 49 - all DoS attacks) HTTP/2 continuation frames - no proper limit on the amount of these frames which can be sent in a single stream - attacker can send many to cause a DoS on the server either through CPU by lots of processing or memory by storing all these headers in memory [USN-6755-1] GNU cpio vulnerabilities (05:42) 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2023-7207 Path traversal vuln - possible to write outside of the target directory Specific to Debian/Ubuntu etc since reverted part of the fix for historic CVE-2015-1197 - path traversal via inclusion of a malicious symlink in the archive - since it broke the use of the --no-absolute-filenames CLI argument Was reverted back in 2.13+dfsg-2 - this was included in all releases of Ubuntu since focal Now use more correct fix from upstream (April 2023) [USN-6756-1] less vulnerability (07:10) 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-32487 Second vuln in less in the last 10 weeks or so - [USN-6664-1] less vulnerability from Episode 220 Similar issue - this time in the use of LESSOPEN environment variable - failed to properly quote newlines embedded in a filename - could then allow for arbitrary code execution if ran less on some untrusted file LESSOPEN is automatically set in Debian/Ubuntu via lesspipe - allows to run less on say a gz compressed log file or even on a tar.gz tarball to list the files etc [USN-6757-1] PHP vulnerabilities (08:41) 3 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2024-3096 CVE-2024-2756 CVE-2022-4900 Incomplete fix for historic CVE-2022-31629 - ability for an attacker on the same network/site could set a cookie via HTTP with one name, which then gets used by sessions using HTTPS and when using a different cookie name - is a problem since certain cookie names (like __Host- and __Secure-) have specific meanings which in general should be allowed to be specified by the network but only by the browser itself - so can be used to bypass usual restrictions (apparently this issue was reported upstream by the original reported of the 2022 vuln but it got ignored by upstream till now…) password_verify() function would sometimes return true for wrong passwords - ie if the actual password started with a NUL byte and the specified a password was the empty string would verify as true (unlikely to be an issue in practice) Heap buffer overflow due to a large PHP_CLI_SERVER_WORKERS env var value - integer overflow -> wraparound -> allocate small amount of memory for a large number of values -> buffer overflow (low priority since would need to be able to set this env var first) [USN-6761-1] Anope vulnerability (11:15) 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10), Noble (24.04 LTS) CVE-2024-30187 Failed to deny ability to reset the password of a suspended account and hence gain access again [USN-6758-1] JSON5 vulnerability (11:37) 1 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2022-46175 NodeJS module for the JSON5 format - “JSON for humans” - much more similar to yaml, does away with a lot of the usual quotes etc Protoype pollution vuln - when parsing would fail to restrict use of the __proto__ key and hence would allow the ability to set arbitrary keys etc within the returned object -> RCE [LSN-0103-1] Linux kernel vulnerability (12:46) 7 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2024-26597 CVE-2024-1086 CVE-2024-1085 CVE-2024-0193 CVE-2023-51781 CVE-2023-6817 CVE-2023-4569 Kernel type 22.04 20.04 18.04 aws 103.3 103.3 — aws-5.15 — 103.3 — aws-5.4 — — 103.3 aws-6.5 103.1 — — azure 103.3 103.3 — azure-5.4 — — 103.3 azure-6.5 103.1 — — gcp 103.3 103.3 — gcp-5.15 — 103.3 — gcp-5.4 — — 103.3 gcp-6.5 103.1 — — generic-5.15 — 103.3 — generic-5.4 — 103.3 103.3 gke 103.3 103.3 — hwe-6.5 103.1 — — ibm 103.3 — — ibm-5.15 — 103.3 — linux 103.3 — — lowlatency-5.15 — 103.3 — lowlatency-5.4 — 103.3 103.3 canonical-livepatch status [USN-6760-1] Gerbv vulnerability (13:01) 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2023-4508 Vuln found by the Ubuntu Security team - David and (former member) Andrei - Andrei found this whilst patching Gerbv back in 2023 and doing a bunch of testing with ASan enabled - crafted filename -> crash [USN-6759-1] FreeRDP vulnerabilities (13:41) 5 CVEs addressed in Noble (24.04 LTS) CVE-2024-32662 CVE-2024-32661 CVE-2024-32660 CVE-2024-32659 CVE-2024-32658 [USN-6737-2] GNU C Library vulnerability 1 CVEs addressed in Noble (24.04 LTS) CVE-2024-2961 [USN-6729-3] Apache HTTP Server vulnerabilities 3 CVEs addressed in Noble (24.04 LTS) CVE-2024-27316 CVE-2024-24795 CVE-2023-38709 [USN-6718-3] curl vulnerabilities 2 CVEs addressed in Noble (24.04 LTS) CVE-2024-2398 CVE-2024-2004 [USN-6733-2] GnuTLS vulnerabilities 2 CVEs addressed in Noble (24.04 LTS) CVE-2024-28835 CVE-2024-28834 [USN-6734-2] libvirt vulnerabilities 2 CVEs addressed in Noble (24.04 LTS) CVE-2024-2494 CVE-2024-1441 [USN-6744-3] Pillow vulnerability 1 CVEs addressed in Noble (24.04 LTS) CVE-2024-28219 Goings on in Ubuntu Security Community Ubuntu 24.04 LTS (Noble Numbat) released (14:27) https://ubuntu.com/blog/canonical-releases-ubuntu-24-04-noble-numbat https://ubuntu.com/blog/ubuntu-desktop-24-04-noble-numbat-deep-dive https://ubuntu.com/blog/whats-new-in-security-for-ubuntu-24-04-lts Up to 12 years of support via Ubuntu Pro + Legacy Support Add-on New security features / improvements: Unprivileged user namespace restrictions Binary hardening AppArmor 4 Disabling of old TLS versions Upstream Kernel Security Features Intel shadow stack support Secure virtualisation with AMD SEV-SNP and Intel TDX Strict compile-time bounds checking Get in contact security@ubuntu.com #ubuntu-security on the Libera.Chat IRC network ubuntu-hardened mailing list Security section on discourse.ubuntu.com @ubuntusecurity@fosstodon.org, @ubuntu_sec on twitter

    Full show notes at the publisher

    Episode 226 Apr 19, 2024
    Show notes

    Overview John and Georgia are at the Linux Security Summit presenting on some long awaited developments in AppArmor and we give you all the details in a sneak peek preview as well as some of the other talks to look out for, plus we cover security updates for NSS, Squid, Apache, libvirt and more and we put out a call for testing of a pending AppArmor security fix too. This week in Ubuntu Security Updates 86 unique CVEs addressed [USN-6727-1, USN-6727-2] NSS vulnerabilities + regression (01:02) 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2023-6135 CVE-2023-5388 CVE-2023-4421 All various different timing side channels - two were effectively the same since the original fix was incomplete - mishandling of padding in PKCS#1 (RSA) certificate checks - possible to infer the length of the encrypted message and other properties to eventually infer secret key by sending a large number of attacker-chosen ciphertexts, the other when using various NIST curves (elliptic curve cryptography) Original fix caused some issues with loading NSS security modules so published a second update to fix that on focal+jammy [USN-6728-1, USN-6728-2] Squid vulnerabilities + regression (02:05) 5 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-25617 CVE-2024-25111 CVE-2024-23638 CVE-2023-5824 CVE-2023-49288 All found by the same researcher (Joshua Rogers) who performed a security audit of Squid back in 2021 - https://megamansec.github.io/Squid-Security-Audit/ - first mentioned by us in [USN-6500-1] Squid vulnerabilities in Episode 214 back in December 2023 Then we mentioned how squid was under-resourced and so hadn’t be able to fix all the identified issues - over time upstream has published fixes for more issues and we are now incorporating those into squid in Ubuntu All of these were various DoS issues where could either cause squid to crash or stop responding One of these fixes was problematic and caused squid to crash itself so was reverted [USN-6729-1] Apache HTTP Server vulnerabilities (03:01) 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-27316 CVE-2024-24795 CVE-2023-38709 2 different issues that could result in HTTP request splitting attacks - similar to HTTP request smuggling which is a more specific version of this attack, relies on different parsing/interpretation of HTTP request messages by an intermediate (load balancer/proxy/WAF etc.) to split a single HTTP request into multiple HTTP requests at the backend - allowing to bypass restrictions along the way - usually involves the use of injected CR/LF/TAB/SPC etc in headers Plus memory-based DoS in handling of HTTP/2 - client could just keep sending more headers, buffered by the server so it can generate an informative response, until it exhausts memory limit to just 100 headers before bailing with such an error [USN-6730-1] Apache Maven Shared Utils vulnerability 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2022-29599 [USN-6731-1] YARD vulnerabilities 3 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-27285 CVE-2019-1020001 CVE-2017-17042 [USN-6732-1] WebKitGTK vulnerabilities 8 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10) CVE-2024-23284 CVE-2024-23280 CVE-2024-23263 CVE-2024-23254 CVE-2024-23252 CVE-2023-42956 CVE-2023-42950 CVE-2023-42843 [USN-6733-1] GnuTLS vulnerabilities (04:57) 2 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-28835 CVE-2024-28834 Timing side-channel in ECDSA Crash when verifying crafted PEM bundles -> DoS [USN-6734-1] libvirt vulnerabilities (05:13) 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-2496 CVE-2024-2494 CVE-2024-1441 off-by-one in handling of udev interface names - unpriv client could then abuse this to send crafted udev data to the libvirt daemon, triggering a crash -> DoS NULL ptr deref in same code - race condition, need to detach a host interface whilst calling into the function Crash in RPC handling - pass a negative length value, would then try and allocate a negative number of array indices - uses underlying g_new0() from glib which expects an unsigned value -> tries to allocate an extremely large amount of memory -> crash [USN-6735-1] Node.js vulnerabilities 3 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2023-30590 CVE-2023-30589 CVE-2023-30588 [USN-6736-1] klibc vulnerabilities (06:33) 4 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2022-37434 CVE-2018-25032 CVE-2016-9841 CVE-2016-9840 All old memory corruption issues in zlib - vendored within klibc [USN-6724-2] Linux kernel vulnerabilities 12 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10) CVE-2023-52438 CVE-2023-52439 CVE-2023-52435 CVE-2023-52436 CVE-2023-52434 CVE-2024-23850 CVE-2024-22705 CVE-2023-6610 CVE-2024-23851 CVE-2023-52429 CVE-2023-50431 CVE-2023-46838 [USN-6725-2] Linux kernel (AWS) vulnerabilities 46 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2023-52470 CVE-2023-52469 CVE-2023-52451 CVE-2023-52610 CVE-2023-52441 CVE-2023-52467 CVE-2023-52449 CVE-2024-26591 CVE-2023-52458 CVE-2024-26597 CVE-2024-26633 CVE-2023-52436 CVE-2023-52444 CVE-2024-26589 CVE-2024-26586 CVE-2024-26598 CVE-2023-52612 CVE-2023-52439 CVE-2024-26631 CVE-2023-52442 CVE-2023-52443 CVE-2023-52480 CVE-2023-52438 CVE-2023-52454 CVE-2023-52456 CVE-2023-52464 CVE-2023-52457 CVE-2023-52448 CVE-2023-52609 CVE-2023-52462 CVE-2023-52445 CVE-2023-52463 CVE-2024-24860 CVE-2024-23850 CVE-2024-22705 CVE-2024-23851 CVE-2023-52429 CVE-2023-52340 CVE-2023-46838 CVE-2023-3867 CVE-2023-38431 CVE-2023-38430 CVE-2023-38427 CVE-2023-32258 CVE-2023-32254 CVE-2023-1194 [USN-6726-2] Linux kernel (IoT) vulnerabilities 23 CVEs addressed in Focal (20.04 LTS) CVE-2023-52438 CVE-2023-52436 CVE-2023-52454 CVE-2023-52470 CVE-2023-52451 CVE-2023-52445 CVE-2023-52469 CVE-2023-52609 CVE-2023-52444 CVE-2023-52449 CVE-2024-26597 CVE-2024-26633 CVE-2023-52612 CVE-2023-52439 CVE-2023-52443 CVE-2023-52457 CVE-2023-52448 CVE-2023-52464 CVE-2024-0607 CVE-2024-23851 CVE-2023-52429 CVE-2023-52340 CVE-2023-46838 [USN-6726-3] Linux kernel (Xilinx ZynqMP) vulnerabilities 23 CVEs addressed in Focal (20.04 LTS) CVE-2023-52438 CVE-2023-52436 CVE-2023-52454 CVE-2023-52470 CVE-2023-52451 CVE-2023-52445 CVE-2023-52469 CVE-2023-52609 CVE-2023-52444 CVE-2023-52449 CVE-2024-26597 CVE-2024-26633 CVE-2023-52612 CVE-2023-52439 CVE-2023-52443 CVE-2023-52457 CVE-2023-52448 CVE-2023-52464 CVE-2024-0607 CVE-2024-23851 CVE-2023-52429 CVE-2023-52340 CVE-2023-46838 Goings on in Ubuntu Security Community Linux Security Summit NA 2024 (07:22) https://events.linuxfoundation.org/linux-security-summit-north-america/ Unprivileged Access Control in AppArmor - John Johansen & Georgia Garcia, Canonical https://static.sched.com/hosted_files/lssna24/97/AppArmor%20-%20Unprivileged%20Application%20Policy.pdf Friday 19th @ 9.15am PDT - live stream at https://www.youtube.com/watch?v=S-RQZGRoQFY AppArmor - MAC - sysadmin defines policy Allowing applications to define and load their own policy APIs in libapparmor to allow this to be done from static policy OR to build up policy over time policy is compiled in userspace and loaded into the kernel as usual To then stop a compromised application from unloading its policy, can mark it immutable so it can’t be further modified / removed Any further restrictions though can then be stacked against the immutable policy to say allow it to be confined futher On kernel side sysctl to allow/deny applications to load their own policy checks on the amount of memory able to be used to avoid apps DoSing system verification of compiled policy by kernel state machine policy only applies to the task and its children Various complexities in handling credentials/labels across tasks (ie. processes) and how these interact with the userspace processes/threads etc Also still have to resolve whether to use prctl vs syscall as the interface since we can’t use the LSM syscalls May result in an AppArmor specific syscall But for now just using a prctl Application profiles then stack against any relevant system policy ie. if there is system policy, and policy loaded by the application itself is bounded by the system policy Demo of implementing pledge() and unveil() from OpenBSD pledge is similar to seccomp() on linux - allows an application to restrict what it can do by declaring what subsystems it should be allowed access to “promises” stdio, inet, bpf, unix, audio, video and many others map these to equivalent AppArmor permissions (although this is not a perfect mapping but WIP) also since this is at the LSM layer, we are not necessarily blocking syscalls as is done by pledge (since it is more akin to seccomp) but can use seccomp to plug any gaps to fully emulate this also need to emulate the return value - since on OpenBSD if the application violates the promise, deliver a SIGABRT - whereas LSMs return EACCES can do this via a new profile flag called kill along with the associated signal to deliver further complications to this since not always SIGABRT, sometimes is an errno (ENOSYS/EACCES) too extend apparmor policy to allow to specify priorities of what action should be taken in various cases can use the aforementioned immutable profile flag and stacking to then implement the promise reduction feature of pledge() unveil is used to remove visibility of parts of the file-system maps quite cleanly to apparmor file rules Full video of the session should be available soon Lots of other interesting talks: Stacked LSMs and User Space - Casey Schaufler, The Smack Project LSM syscalls and associated liblsm to provide an easier API plus emulation for older systems https://static.sched.com/hosted_files/lssna24/1a/2024-04-LSSNA-liblsm.pdf Mitigating Integer Overflow in C - Kees Cook, Google LKSPP - latest efforts to mitigate integer overflows within the kernel through the use of compiler sanitizers https://static.sched.com/hosted_files/lssna24/fb/Mitigating%20Integer%20Overflow%20in%20C.pdf Enhancing Kernel Bug Discovery with Large Language Models - Zahra Tarkhani, Microsoft SandBox Mode (SBM) - New Execution Mode Between Kernel and User Space - Petr Tesarik, Self-employed Upcoming AppArmor Security update for CVE-2016-1585 https://discourse.ubuntu.com/t/upcoming-apparmor-security-update-for-cve-2016-1585/44268/1 https://bugs.launchpad.net/apparmor/+bug/1597017 Get in contact security@ubuntu.com #ubuntu-security on the Libera.Chat IRC network ubuntu-hardened mailing list Security section on discourse.ubuntu.com @ubuntusecurity@fosstodon.org, @ubuntu_sec on twitter

    Full show notes at the publisher

    Episode 225 Apr 12, 2024
    Show notes

    Overview This week we cover the recent reports of a new local privilege escalation exploit against the Linux kernel, follow-up on the xz-utils backdoor from last week and it’s the beta release of Ubuntu 24.04 LTS - plus we talk security vulnerabilities in the X Server, Django, util-linux and more. This week in Ubuntu Security Updates 76 unique CVEs addressed [LSN-0102-1] Linux kernel vulnerability (00:53) 6 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2024-1086 CVE-2024-0646 CVE-2023-51781 CVE-2023-6176 CVE-2023-4569 CVE-2023-1872 All covered in previous episodes netfilter UAF ([USN-6700-1] Linux kernel vulnerabilities from Episode 223) OOB write in KTLS ([USN-6648-1] Linux kernel vulnerabilities from Episode 220) UAF in AppleTalk network driver ([USN-6648-1] Linux kernel vulnerabilities from Episode 220) NULL ptr deref in TLS impl ([LSN-0100-1] Linux kernel vulnerability from Episode 219) Memory leak in netfilter ([USN-6383-1] Linux kernel vulnerabilities from Episode 210) Kernel type 22.04 20.04 18.04 16.04 14.04 aws 102.1 102.1 102.1 102.1 — aws-5.15 — 102.1 — — — aws-5.4 — — 102.1 — — aws-6.5 102.1 — — — — aws-hwe — — — 102.1 — azure 102.1 102.1 — 102.1 — azure-4.15 — — 102.1 — — azure-5.4 — — 102.1 — — azure-6.5 102.1 — — — — gcp 102.1 102.1 — 102.1 — gcp-4.15 — — 102.1 — — gcp-5.15 — 102.1 — — — gcp-5.4 — — 102.1 — — gcp-6.5 102.1 — — — — generic-4.15 — — 102.1 102.1 — generic-4.4 — — — 102.1 102.1 generic-5.15 — 102.1 — — — generic-5.4 — 102.1 102.1 — — gke 102.1 102.1 — — — gke-5.15 — 102.1 — — — gkeop — 102.1 — — — hwe-6.5 102.1 — — — — ibm 102.1 102.1 — — — ibm-5.15 — 102.1 — — — linux 102.1 — — — — lowlatency 102.1 — — — — lowlatency-4.15 — — 102.1 102.1 — lowlatency-4.4 — — — 102.1 102.1 lowlatency-5.15 — 102.1 — — — lowlatency-5.4 — 102.1 102.1 — — canonical-livepatch status [USN-6710-2] Firefox regressions (01:54) 2 CVEs addressed in Focal (20.04 LTS) CVE-2024-29944 CVE-2024-29943 124.0.2 In particular fixes to allow firefox when installed directly from Mozilla to work under 24.04 LTS with the new AppArmor userns restrictions As discussed in previous episodes, default profile allows to use userns but then to be blocked on getting additional capabilities - Firefox would previously try and do both a new userns and a new PID NS in one call - which would be blocked - now split this into two separate calls so the userns can succeed but pidns will be denied (since requires CAP_SYS_ADMIN) - but then firefox correctly detects this and falls back to the correct behaviour [USN-6721-1] X.Org X Server vulnerabilities (04:11) 4 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-31083 CVE-2024-31082 CVE-2024-31081 CVE-2024-31080 Various OOB reads -> crash / info leaks when handling byte-swapped length values - able to be easily triggered by a client who is using a different endianness than the X server UAF in glyph handling -> crash / RCE [USN-6721-2] X.Org X Server regression 4 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-31083 CVE-2024-31082 CVE-2024-31081 CVE-2024-31080 [USN-6722-1] Django vulnerability (05:19) 1 CVEs addressed in Trusty ESM (14.04 ESM) CVE-2019-19844 Possible account takeover - would use a case transformation on unicode of the email address - so if an attacker can register an email address that is the same as the intended targets email address after this case transformation - fix simply just discards the transformed email address and sends to the one registered by the user [USN-6723-1] Bind vulnerabilities (06:11) 2 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM) CVE-2023-50868 CVE-2023-50387 [USN-6633-1] Bind vulnerabilities from Episode 219 [USN-6724-1] Linux kernel vulnerabilities (06:27) 12 CVEs addressed in Jammy (22.04 LTS), Mantic (23.10) CVE-2023-52438 CVE-2023-52439 CVE-2023-52435 CVE-2023-52436 CVE-2023-52434 CVE-2024-23850 CVE-2024-22705 CVE-2023-6610 CVE-2024-23851 CVE-2023-52429 CVE-2023-50431 CVE-2023-46838 [USN-6725-1] Linux kernel vulnerabilities 46 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2023-52470 CVE-2023-52469 CVE-2023-52451 CVE-2023-52610 CVE-2023-52441 CVE-2023-52467 CVE-2023-52449 CVE-2024-26591 CVE-2023-52458 CVE-2024-26597 CVE-2024-26633 CVE-2023-52436 CVE-2023-52444 CVE-2024-26589 CVE-2024-26586 CVE-2024-26598 CVE-2023-52612 CVE-2023-52439 CVE-2024-26631 CVE-2023-52442 CVE-2023-52443 CVE-2023-52480 CVE-2023-52438 CVE-2023-52454 CVE-2023-52456 CVE-2023-52464 CVE-2023-52457 CVE-2023-52448 CVE-2023-52609 CVE-2023-52462 CVE-2023-52445 CVE-2023-52463 CVE-2024-24860 CVE-2024-23850 CVE-2024-22705 CVE-2024-23851 CVE-2023-52429 CVE-2023-52340 CVE-2023-46838 CVE-2023-3867 CVE-2023-38431 CVE-2023-38430 CVE-2023-38427 CVE-2023-32258 CVE-2023-32254 CVE-2023-1194 [USN-6726-1] Linux kernel vulnerabilities 23 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS) CVE-2023-52438 CVE-2023-52436 CVE-2023-52454 CVE-2023-52470 CVE-2023-52451 CVE-2023-52445 CVE-2023-52469 CVE-2023-52609 CVE-2023-52444 CVE-2023-52449 CVE-2024-26597 CVE-2024-26633 CVE-2023-52612 CVE-2023-52439 CVE-2023-52443 CVE-2023-52457 CVE-2023-52448 CVE-2023-52464 CVE-2024-0607 CVE-2024-23851 CVE-2023-52429 CVE-2023-52340 CVE-2023-46838 [USN-6701-4] Linux kernel (Azure) vulnerabilities 12 CVEs addressed in Trusty ESM (14.04 ESM) CVE-2024-24855 CVE-2024-1086 CVE-2024-0775 CVE-2023-6121 CVE-2023-51781 CVE-2023-46838 CVE-2023-4132 CVE-2023-39197 CVE-2023-34256 CVE-2023-3006 CVE-2023-23000 CVE-2023-2002 [USN-6719-2] util-linux vulnerability (07:08) 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-28085 Initial fix in [USN-6719-1] util-linux vulnerability from Episode 224 tried to escape output to avoid shell command injection - as is often the case, turned out to be insufficient, so instead have now just removed the setgid permission from the wall/write binaries - can then only send to yourself rather than all users Goings on in Ubuntu Security Community Reports of a new local root privilege escalation exploit against Linux kernel (08:32) https://github.com/YuriiCrimson/ExploitGMStr Ukrainian hacker YuriiCrimson Has generated a lot of interest since whilst there are always vulns / CVEs in the kernel we don’t always see full PoCs much anymore Originally developed an exploit against the n_gsm driver in the 6.4 and and 6.5 kernels Says they were contacted by another hacker jmpeax (Jammes) - who wanted to purchase the exploit After selling it to them, seems they tried to pass it off as their own https://github.com/jmpe4x/GSM_Linux_Kernel_LPE_Nday_Exploit https://jmpeax.dev/The-tale-of-a-GSM-Kernel-LPE.html commit timestamps of the purported copy by Jammes are all dated over 3 weeks ago but the original is only is only 1 week ago so on the surface would appear the other way around however, Yurii posted a video of their interaction with Jammes on Telegram to try and prove their side looking at repo metadata https://api.github.com/repos/jmpe4x/GSM_Linux_Kernel_LPE_Nday_Exploit shows the so-called copy was created on 22nd March whereas the Yurii’s is 6th April - so would appear that perhaps Jammes is the original author also can compare the two exploits and see they are almost identical - but Jammes has an extra target for the 6.5.0-26-generic kernel from mantic diff -w <(curl https://raw.githubusercontent.com/jmpe4x/GSM_Linux_Kernel_LPE_Nday_Exploit/main/main.c) <(curl https://raw.githubusercontent.com/YuriiCrimson/ExploitGSM/main/ExploitGSM_6_5/main.c) who the actual author is remains unclear (also I don’t have telegram so couldn’t check the video)… Regarding the actual vulnerability - turns out there is at least 2 if not 3 in this module Old CVE-2023-6546 - written up https://github.com/Nassim-Asrir/ZDI-24-020/ Fixed in 6.5-rc7 Yurii / Jammes Additional exploit by Yurii apparently targeting 5.15-6.1 - also in n_gsm Mixed reports about this last exploit but report the one from Yurii/Jammes does work even on the latest upstream kernel Waiting on a fix from upstream to then integrate in Ubuntu kernels Interesting these exploits all used the same basic info leak from xen via /sys/kernel/notes which leaks the symbol of the xen_startup function and allows to break KASLR Reports this was known since at least 2020 Many eyes…? Ubuntu 24.04 LTS (Noble Numbat) Beta released (14:01) https://lists.ubuntu.com/archives/ubuntu-announce/2024-April/000300.html https://discourse.ubuntu.com/t/noble-numbat-release-notes/ Also releases for all the flavours Edubuntu, Kubuntu, Lubuntu, Ubuntu Budgie, Ubuntu Cinnamon, UbuntuKylin, Ubuntu MATE, Ubuntu Studio, Ubuntu Unity, Xubuntu Final release scheduled for 25th April (just under 2 weeks) Update on xz-utils (15:18) When we talked about xz-utils last week, didn’t really talk much about the main upstream developer Lasse Collin Thought it could be interesting to dive into how they essentially got compromised by this actor - but that is perhaps done better by others - go listen to the latest episode of Between Two Nerds from Tom Uren and The Grugq (https://risky.biz/BTN74/) talking about the tradecraft used to infiltrate the project and comparing this against the more traditional HUMINT elements Lasse Collin’s github account and the Github project for xz was reinstated Backdoor removed Great sense of humour: The executable payloads were embedded as binary blobs in the test files. This was a blatant violation of the Debian Free Software Guidelines. On machines that see lots bots poking at the SSH port, the backdoor noticeably increased CPU load, resulting in degraded user experience and thus overwhelmingly negative user feedback. The maintainer who added the backdoor has disappeared. Backdoors are bad for security. Also removed the ifunc (indirect function) support - ostensibly used to allow a developer to create multiple implementations of a given function and select between then at runtime - in this case was for an optimised version of CRC calculation - but abused by the backdoor to be able to hook into and replace functions in the global symbol table before it gets made read-only by the dynamic loader Says this was not for security reasons but since it makes the code harder to maintain but is clearly a good win for security Lasse still plans to make to write an article on the backdoor etc but is more focused on cleaning up the upstream repo first - next version is likely to be 5.8.0 Watch this space… Get in contact security@ubuntu.com #ubuntu-security on the Libera.Chat IRC network ubuntu-hardened mailing list Security section on discourse.ubuntu.com @ubuntusecurity@fosstodon.org, @ubuntu_sec on twitter

    Full show notes at the publisher

    Episode 224 Apr 05, 2024
    Show notes

    Overview It’s been an absolutely manic week in the Linux security community as the news and reaction to the recent announcement of a backdoor in the xz-utils project was announced late last week, so we dive deep into this issue and discuss how it impacts Ubuntu and give some insights for what this means for the open source and Linux communities in the future. This week in Ubuntu Security Updates 20 unique CVEs addressed [USN-6718-2] curl vulnerability 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM) CVE-2024-2398 [USN-6719-1] util-linux vulnerability 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-28085 [USN-6686-5] Linux kernel (Intel IoTG) vulnerabilities 9 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2024-0607 CVE-2024-0340 CVE-2023-6121 CVE-2023-51782 CVE-2023-51779 CVE-2023-46862 CVE-2023-46343 CVE-2023-4134 CVE-2023-22995 [USN-6715-1] unixODBC vulnerability 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10) CVE-2024-1013 [USN-6704-4] Linux kernel (Intel IoTG) vulnerabilities 5 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS) CVE-2024-24855 CVE-2024-1086 CVE-2024-1085 CVE-2023-32247 CVE-2023-23000 [USN-6707-4] Linux kernel (Azure) vulnerabilities 4 CVEs addressed in Jammy (22.04 LTS) CVE-2024-26599 CVE-2024-26597 CVE-2024-1086 CVE-2024-1085 [USN-6720-1] Cacti vulnerability 1 CVEs addressed in Jammy (22.04 LTS) CVE-2023-39361 Goings on in Ubuntu Security Community xz-utils backdoor and Ubuntu https://www.openwall.com/lists/oss-security/2024/03/29/4 Late last week, 28th / 29th March backdoor in liblzma from xz-utils was disclosed to the open source community via oss-security mailing list - this was in the recent 5.6.0/5.6.1 releases from late Feb/early March this year initially the impact was not entirely clear - assumed initially that it may impact only xz-utils and so only in handling of xz compressed data / files - but even with that assumption that perhaps it could then infect anything that got compressed/decompressed within a few hours though became clear that the primary target was not xz-utils/liblzma itself but openssh - and the affect was to provide a backdoor into openssh that would allow the attacker to get remote access to any machine running ssh server with this backdoor liblzma installed To paint a picture - this was all unfolding on late Thursday / Friday of the Easter break, so lots of folks were either EOD or on leave etc - and trying to grapple with a threat that we knew could possibly impact the impedending 24.04 LTS release Good news: TL;DR for Ubuntu, this version was only ever in the -proposed pocket for the currently in-development 24.04 release - not in any other Ubuntu versions - and was removed as soon as we became aware, so unless you are running the devel release AND you had manually opted to install this version from the -proposed pocket, you would not be affected - very lucky https://discourse.ubuntu.com/t/xz-liblzma-security-update/43714 What do we know about this? A lot - there has been significant investigation (and speculation) since it was announced, both at the social side of things and the technical aspects of the backdoor itself For the purpose of the podcast, we won’t go too deep into either but will try and cover the salient details Regarding the inclusion of the backdoor itself - looks to have been a very long and patient campaign by the attacker, who slowly gained the trust of the upstream project over the last 2 years and likely pressured the maintainer via sock-puppet accounts to then get themselves added as an additional maintainer Since then they seemed to be quite a good maintainer themselves - diligently adding new features and bug fixes etc over the past 2 years, but then suddenly introduced the backdoor into the most recent 2 releases The method of introducing the backdoor was also interesting, in that it required 2 parts - the binary containing the backdoor and the code to get this compiled into the liblzma library at build time The binary was committed into the upstream git repo disguised as an xz archive itself used as part of the test suite The code to inject this into the build was NOT part of the git repo, but instead was just in the tarball prepared by the maintainer for the official release And it used many levels of obfuscation to hide this backdoor within that fake test xz archive So the attacker was not just patient but also very technically skilled - and not just multiple levels of obfuscation in the build process but the backdoor code itself contained many elements to try and make it harder to recognise and reverse engineer, presumably to allow it to hide in plain sight although as we will see, this runtime obfuscation within the backdoor binary was what gave it away eventually It’s often said that one of the advantages of Open Source is the huge community, which is summarised as Linus’ Law - with enough eyeballs all bugs are shallow - but sadly this wasn’t proven out in this case Backdoor was not found by anyone doing review of the changes upstream or by the various distros like Debian / Fedora / OpenSUSE / Arch or even Ubuntu when incorporating this new version into their repos - but instead was found by Andres Freund, one of the maintainers of PostgreSQL, when they were looking to benchmark some new changes scheduled for the next PostgreSQL release Luckily decided to use Debian unstable for this, and Debian had incorporated this new version into unstable a few weeks ago, and wanted to get the performance noise floor of the system as low as possible before doing benchmarking of PostgreSQL - noticed large transient CPU spikes in sshd and then eventually weird memory errors in sshd due to bugs in the initial version of the backdoor After a lot of painstaking work was able to determine that liblzma was the culprit and appeared to contain some very strange code to hook into the authentication process of sshd when it was launched via systemd Was able to trace that back to the aforementioned manually prepared tarballs of xz-utils on Github The CPU spikes Andres observed were due to the use of things like a trie to lookup symbol names at runtime, rather than directly encoding them in the exploit binary, presumably to try and make reverse engineering of the binary harder (since you can’t just run strings on it and get any real sensible output) Some excellent writeups have been done regarding both the technical aspects of the backdoor itself, as well as the process taken by the attacker to incorporate this into the xz-utils project - both from a community point of view and a technical point of view From a technical point of view, the impact of this backdoor was to allow an attacker to get pre-authentication remote-code execution in sshd via a specific private key when connecting to the server - NOBUS Hooked into the RSA certificate validation process in sshd, looking for a particular matching private key from the client - and if found would then proceed to execute arbitrary commands specified by the client without requiring usual authentication By using this mechanism, nobody but the attacker can use the backdoor since they don’t have the matching private key - so the impact of the backdoor is somewhat limited BUT the fact they targeted such a widely used and deployed package across a huge number of distros, means they essentially wanted a backdoor into any Linux machine in the future that only they could use Interesting to try and speculate who the attacker could be (nation state?) and what their intended purpose was especially given this wide reaching goal of getting this into all the major Linux distros - but it would be just speculation So rather than speculate, for the purpose of this podcast episode, interesting to look at the timeline as it concerned Ubuntu The publishing history of the package is all visible in Launchpad Packages in Ubuntu get inherited from Debian who also publish history Upstream published the first backdoored version 5.6.0 via GitHub tarball on 24th Feb 2024 Debian incorporated this into unstable on 26th Feb On 27th Feb, the Ubuntu Archive Auto-Sync bot copied this version into noble-proposed Due to the ongoing time_t transition, sat it noble-proposed for the next month Security team heard whispers of the possible backdoor just hours before it was publicly disclosed, and as soon as we heard of the possible backdoor, and realised that it only affected the version in-development noble-proposed we quickly notified the Archive Admin team who then deleted it from noble-proposed on 29th March, neutralising the main threat Most important thing to know for Ubuntu, we have taken a very conservative approach - not only have we removed this version from noble-proposed as soon as we became aware, we are then rebuilding every binary package that got built since that compromised version was in noble-proposed originally - out of an abundance of caution - we don’t have any information that says this backdoor was doing anything other than what the various writeups have found so far, BUT we also can’t be certain that it didn’t have other functionality either - so being very cautious and rebuilding everything that was itself built since 27th Feb As such, delayed the development of 24.04 so beta release is slipping by one week One of the most interesting parts is the sheer luck that this was found - not by security researchers or maintainers but by a developer from Microsoft who happened to be looking for the right things at the right time and decided to be curious Also for Ubuntu, luck that the time_t transition in Debian/Ubuntu caused many packages to be stuck in noble-proposed and not in the release pocket, else many Ubuntu users and developers would have been impacted if this had migrated to the noble release pocket Also interesting that the attacker appears to have had quite a good grasp on OSS development practices and was quite persistent in trying to get this incorporated into distros - even urging for this new version to be synced to Ubuntu so that it would land in the upcoming noble release as recently as Thursday last week, just hours before the public disclosure Not only could they do all the original social engineering work upstream, and technical work to develop and hide the backdoor, but could then interface with distros via their established practices to try and get them to incorporate their new backdoored version faster than they may have otherwise Huge amount of work has been done to detail both the timeline of the attack as well as the technical details of both the code used to incorporate the backdoored code into the final liblzma binary during the build process, as well as the details of the backdoor itself and how it operates at runtime In the end highlights both the challenges and strengths of OSS - lots of OSS projects have long dependency chains - in this case openssh when integrated with libsystemd which in turn used liblzma - and it is unclear who the maintainers and authors are or what procedures are in place for vetting and transferring ownership of OSS projects - all present significant challenges for OSS However, significant strength of OSS is the visibility and ability for anyone to get involved, which is what we saw in the aftermath - despite all the advanced obfuscation techniques employed was able to be analysed in a matter of days by the community working together - and to analyse it in a huge amount of depth and in such an open way that it leaves little room for questioning the validity of the assessment - anyone can double check the work and come to the same conclusions This isn’t the first software supply chain attack and likely isn’t even the first against an OSS project but it is a wake-up call to the OSS and Linux ecosystem Get in contact security@ubuntu.com #ubuntu-security on the Libera.Chat IRC network ubuntu-hardened mailing list Security section on discourse.ubuntu.com @ubuntusecurity@fosstodon.org, @ubuntu_sec on twitter

    Full show notes at the publisher

    Previous 1 2 3 4 25 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights