Ubuntu alert USN-7259-1 (glibc)
From: | Hlib Korzhynskyy <hlib.korzhynskyy@canonical.com> | |
To: | ubuntu-security-announce@lists.ubuntu.com | |
Subject: | [USN-7259-1] GNU C Library vulnerability | |
Date: | Thu, 06 Feb 2025 14:07:43 -0330 | |
Message-ID: | <d54e15a7-083c-453e-a49a-fc4331be8b7c@canonical.com> |
========================================================================== Ubuntu Security Notice USN-7259-1 February 06, 2025 glibc vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: GNU C Library could be made to crash or run programs if it received specially crafted input. Software Description: - glibc: GNU C Library Details: It was discovered that GNU C Library incorrectly handled memory when using the assert function. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 libc6 2.40-1ubuntu3.1 Ubuntu 24.04 LTS libc6 2.39-0ubuntu8.4 Ubuntu 22.04 LTS libc6 2.35-0ubuntu3.9 Ubuntu 20.04 LTS libc6 2.31-0ubuntu9.17 Ubuntu 18.04 LTS libc6 2.27-3ubuntu1.6+esm4 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7259-1 CVE-2025-0395 Package Information: https://launchpad.net/ubuntu/+source/glibc/2.40-1ubuntu3.1 https://launchpad.net/ubuntu/+source/glibc/2.39-0ubuntu8.4 https://launchpad.net/ubuntu/+source/glibc/2.35-0ubuntu3.9 https://launchpad.net/ubuntu/+source/glibc/2.31-0ubuntu9.17
Attachment: OpenPGP_signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- wsF5BAABCAAjFiEELOLXZEFYQHcSWEHiyfW2m9Ldu6sFAmek82cFAwAAAAAACgkQyfW2m9Ldu6tD KQ//X+fG8IAbwVrrIbno1do04R0dENQ2XKmTNqRaACnhU/8Jn29OINPd+VCXqxcWdjhlpoQ7VxN2 iiDOCOuLLQER94OZiU5DAiilTfMRIzI4vq+dc78Tc1l34mGBOng7sv2VqsrsTY2e/EzUt2hiJMeQ mZgyaFwSq14cYRkWjskg0m/1vkAUCditM3HpeJ1ESZQElNqQ1z8+X48C8ot4QEKat11S9TwCZwCc jANchjObnilj19DQX4bgEz6IvmdElXMJ/Dvv7UuYM36JLfeVc8V+StUNtLQxMLpSVK56KrNIeurC 1prkeVLYqsaWP9L2SOyMXmvtuFI4GctVWV9br92rTgwjYRFLxT9gjDzR4wnzFtwDATiHu9P83m2h pz1JOq4OKb5uEb9NBIKYOcEBDhkmqjeROSDnB1XUBBdsa60hSmiXuBdpyiQ8kfQeAVKFYNjY+wWO KStopatflim/hES9iC0q0mJLWy4UrOz1KqxOzh7YOuxV01R17YsdCQyxduaX6J6kVwFZgxVJGRb2 gKpJbesspaVyxn3IC3FTe/7SZGgobBfQGT7Mh1aaLhLrr5Chy9I5jMVXYds5Gu7qqWlRNFpAgx7M GPILLI4C2m9B0aPjMfpPf+N7H3Vkqd8VNYPlpw/Alo3IpzngnKorgl95BCQDeLm5rtfSXs/JWHwO RHM= =zQiU -----END PGP SIGNATURE-----
Attachment: None (type=text/plain)