|
|
Subscribe / Log in / New account

Ubuntu alert USN-7259-1 (glibc)

From:  Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-7259-1] GNU C Library vulnerability
Date:  Thu, 06 Feb 2025 14:07:43 -0330
Message-ID:  <d54e15a7-083c-453e-a49a-fc4331be8b7c@canonical.com>

========================================================================== Ubuntu Security Notice USN-7259-1 February 06, 2025 glibc vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: GNU C Library could be made to crash or run programs if it received specially crafted input. Software Description: - glibc: GNU C Library Details: It was discovered that GNU C Library incorrectly handled memory when using the assert function. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10   libc6                           2.40-1ubuntu3.1 Ubuntu 24.04 LTS   libc6                           2.39-0ubuntu8.4 Ubuntu 22.04 LTS   libc6                           2.35-0ubuntu3.9 Ubuntu 20.04 LTS   libc6                           2.31-0ubuntu9.17 Ubuntu 18.04 LTS   libc6                           2.27-3ubuntu1.6+esm4                                   Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References:   https://ubuntu.com/security/notices/USN-7259-1   CVE-2025-0395 Package Information:   https://launchpad.net/ubuntu/+source/glibc/2.40-1ubuntu3.1   https://launchpad.net/ubuntu/+source/glibc/2.39-0ubuntu8.4   https://launchpad.net/ubuntu/+source/glibc/2.35-0ubuntu3.9   https://launchpad.net/ubuntu/+source/glibc/2.31-0ubuntu9.17


Attachment: OpenPGP_signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- wsF5BAABCAAjFiEELOLXZEFYQHcSWEHiyfW2m9Ldu6sFAmek82cFAwAAAAAACgkQyfW2m9Ldu6tD KQ//X+fG8IAbwVrrIbno1do04R0dENQ2XKmTNqRaACnhU/8Jn29OINPd+VCXqxcWdjhlpoQ7VxN2 iiDOCOuLLQER94OZiU5DAiilTfMRIzI4vq+dc78Tc1l34mGBOng7sv2VqsrsTY2e/EzUt2hiJMeQ mZgyaFwSq14cYRkWjskg0m/1vkAUCditM3HpeJ1ESZQElNqQ1z8+X48C8ot4QEKat11S9TwCZwCc jANchjObnilj19DQX4bgEz6IvmdElXMJ/Dvv7UuYM36JLfeVc8V+StUNtLQxMLpSVK56KrNIeurC 1prkeVLYqsaWP9L2SOyMXmvtuFI4GctVWV9br92rTgwjYRFLxT9gjDzR4wnzFtwDATiHu9P83m2h pz1JOq4OKb5uEb9NBIKYOcEBDhkmqjeROSDnB1XUBBdsa60hSmiXuBdpyiQ8kfQeAVKFYNjY+wWO KStopatflim/hES9iC0q0mJLWy4UrOz1KqxOzh7YOuxV01R17YsdCQyxduaX6J6kVwFZgxVJGRb2 gKpJbesspaVyxn3IC3FTe/7SZGgobBfQGT7Mh1aaLhLrr5Chy9I5jMVXYds5Gu7qqWlRNFpAgx7M GPILLI4C2m9B0aPjMfpPf+N7H3Vkqd8VNYPlpw/Alo3IpzngnKorgl95BCQDeLm5rtfSXs/JWHwO RHM= =zQiU -----END PGP SIGNATURE-----


Attachment: None (type=text/plain)


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds