Ubuntu alert USN-7697-1 (aide)
From: | noreply+usn-bot@canonical.com | |
To: | ubuntu-security-announce@lists.ubuntu.com | |
Subject: | [USN-7697-1] AIDE vulnerabilities | |
Date: | Thu, 14 Aug 2025 20:34:45 +0000 | |
Message-ID: | <E1umeer-0006UO-4n@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-7697-1 August 14, 2025 aide vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in AIDE. Software Description: - aide: Advanced Intrusion Detection Environment Details: Rajesh Pangare discovered that AIDE incorrectly handled filenames. A local attacker could possibly use this issue to bypass the detection of malicious files. (CVE-2025-54389) Rajesh Pangare discovered that AIDE incorrectly handled extended file attributes. A local attacker could possibly use this issue to cause a denial of service. (CVE-2025-54409) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 aide 0.18.8-2ubuntu0.1 Ubuntu 24.04 LTS aide 0.18.6-2ubuntu0.1 Ubuntu 22.04 LTS aide 0.17.4-1ubuntu0.2 Ubuntu 20.04 LTS aide 0.16.1-1ubuntu0.1+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS aide 0.16-3ubuntu0.1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS aide 0.16~a2.git20130520-3ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 14.04 LTS aide 0.16~a2.git20130520-2ubuntu0.1+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7697-1 CVE-2025-54389, CVE-2025-54409 Package Information: https://launchpad.net/ubuntu/+source/aide/0.18.8-2ubuntu0.1 https://launchpad.net/ubuntu/+source/aide/0.18.6-2ubuntu0.1 https://launchpad.net/ubuntu/+source/aide/0.17.4-1ubuntu0.2
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmieSE8ACgkQcpJm3tlz hgEblg//fcusZxdGZIJD0DysBKIFQMcyhjzbDvRy4kA2PbyaaulBgPfOI8ZNkC31 RM9Vcc9PhdQVGUFzMG+3gNYLwBd6n23cLC89MjI4/SQlxUfZXvNPcJ88mQ4XfCLj cSuHG3MrKJCi+g+oliJX/uUdCILu0ARTwL3+sG8f42b+UBZapt4UNcc1SvOOVDmj JizU1+dwg6ZBJ71/lMOSFSberl8qOkugA1ktFCPCyjL+LKKhQWf+X8ZO+p3tpDRm VGA6Yzk8i7+qB2FD/o6N195uX+KZc14hxCx14sdButcUXCrRDs65EGlOV/1ugQwv hM/84vP9fZMiGLbtBVvSRrUs8hnB/aB6/E44nv18y4hXKWbXRO6BFqCSlQRVvu1/ DTXPZ37Ze21xL35dVHj6b8ZDp1jjfh60Qtf6E4PSCCrZRYhJItnYDqCLbkfrMrBH WbirLHnwzu4lctKS3p7cN957jbFc4tL7tunhuGoo2XD78D+ZIAjny5xHCj2pW4NT uhwSfue8uN3tmCtBLGcMDNzDIaNgzV6RaMs9KVfbZkk7/C/XYXBLDREz32RPgpbr YenyWqBOto4vLUhOnT3Q/325hT8zH7eWUJEhBRAgiXfbv7P1T+282/J2REie1YJd hMq1Qcl8yDCCFXMTz/Po7zKJmqWwxb2zCH0F6Xtp93UwLrlJ52Q= =7pBe -----END PGP SIGNATURE-----