Ubuntu security updates

4 views
Skip to first unread message

Irina Semenova

unread,
Sep 17, 2018, 12:15:13 PM9/17/18
to kernelca...@googlegroups.com
To apply patches do the following: 

Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.

You can manually update the server by running:
# /usr/bin/kcarectl --update


CHANGELOG:
ubuntu-bionic: {latest-version: 4.15.0-34.37}
ubuntu-trusty-lts-xenial:
  CVE-2018-13094: An issue was discovered in the XFS filesystem in fs/xfs/libxfs/xfs_attr_leaf.c
    in the Linux kernel. A NULL pointer dereference may occur for a corrupted xfs
    image after xfs_da_shrink_inode() is called with a NULL bp. This can lead to a
    system crash and a denial of service.
  CVE-2018-13405: A vulnerability was found in the fs/inode.c:inode_init_owner() function
    logic of the LInux kernel that allows local users to create files with an unintended
    group ownership and with group execution and SGID permission bits set, in a scenario
    where a directory is SGID and belongs to a certain group and is writable by a
    user who is not a member of this group. This can lead to excessive permissions
    granted in case when they should not.
  cvelist: [CVE-2018-13405, CVE-2018-13094]
  latest-version: 4.4.0-135.161~14.04.1
ubuntu-xenial:
  CVE-2018-13094: An issue was discovered in the XFS filesystem in fs/xfs/libxfs/xfs_attr_leaf.c
    in the Linux kernel. A NULL pointer dereference may occur for a corrupted xfs
    image after xfs_da_shrink_inode() is called with a NULL bp. This can lead to a
    system crash and a denial of service.
  CVE-2018-13405: A vulnerability was found in the fs/inode.c:inode_init_owner() function
    logic of the LInux kernel that allows local users to create files with an unintended
    group ownership and with group execution and SGID permission bits set, in a scenario
    where a directory is SGID and belongs to a certain group and is writable by a
    user who is not a member of this group. This can lead to excessive permissions
    granted in case when they should not.
  cvelist: [CVE-2018-13405, CVE-2018-13094]
  latest-version: 4.4.0-135.161
ubuntu-xenial-aws:
  CVE-2018-13094: An issue was discovered in the XFS filesystem in fs/xfs/libxfs/xfs_attr_leaf.c
    in the Linux kernel. A NULL pointer dereference may occur for a corrupted xfs
    image after xfs_da_shrink_inode() is called with a NULL bp. This can lead to a
    system crash and a denial of service.
  CVE-2018-13405: A vulnerability was found in the fs/inode.c:inode_init_owner() function
    logic of the LInux kernel that allows local users to create files with an unintended
    group ownership and with group execution and SGID permission bits set, in a scenario
    where a directory is SGID and belongs to a certain group and is writable by a
    user who is not a member of this group. This can lead to excessive permissions
    granted in case when they should not.
  cvelist: [CVE-2018-13405, CVE-2018-13094]
  latest-version: 4.4.0-1067.77
ubuntu-xenial-lts-bionic: {latest-version: 4.15.0-24.26~16.04.1}

==== deploy-prep ====
kernels='ubuntu-xenial-lts-bionic ubuntu-bionic ubuntu-xenial-aws ubuntu-trusty-lts-xenial ubuntu-xenial'
lkernel['ubuntu-xenial-lts-bionic']=4.15.0-24.26~16.04.1
lkernel['ubuntu-bionic']=4.15.0-34.37
lkernel['ubuntu-xenial-aws']=4.4.0-1067.77
lkernel['ubuntu-trusty-lts-xenial']=4.4.0-135.161~14.04.1
lkernel['ubuntu-xenial']=4.4.0-135.161

--
-- 
Regards, 
Irina Semenova | Project Coordinator of KernelCare 
Skype: iras535

CloudLinux.com  |  KernelCare.com  |  Imunify360 

helpdesk.cloudlinux.com: 24/7 Free, exceptionally good support
Follow twitter.com/CloudLinuxOS for technical updates
Reply all
Reply to author
Forward
0 new messages