|
|
Subscribe / Log in / New account

Ubuntu alert USN-7819-2 (linux-azure-fips)

From:  Rodrigo Figueiredo Zaiden <rodrigo.zaiden@canonical.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-7819-2] Linux kernel (Azure FIPS) vulnerabilities
Date:  Tue, 21 Oct 2025 19:27:31 -0300
Message-ID:  <4d8240d8-e182-43f7-8c62-8fb9918afb7b@canonical.com>

========================================================================== Ubuntu Security Notice USN-7819-2 October 21, 2025 linux-azure-fips vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-azure-fips: Linux kernel for Microsoft Azure Cloud systems with FIPS Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - Device tree and open firmware driver; - SCSI subsystem; - TTY drivers; - Ext4 file system; - Network file system (NFS) server daemon; - SMB network file system; - Bluetooth subsystem; - Packet sockets; - Network traffic control; - VMware vSockets driver; (CVE-2025-38350, CVE-2024-57996, CVE-2025-37752, CVE-2025-38617, CVE-2025-38477, CVE-2025-38083, CVE-2024-38541, CVE-2023-52757, CVE-2023-52975, CVE-2025-38618, CVE-2024-49950, CVE-2024-50073, CVE-2025-37785, CVE-2025-21796, CVE-2025-38683, CVE-2025-37797) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.4.0-1155-azure-fips 5.4.0-1155.162+fips1 Available with Ubuntu Pro linux-image-azure-fips 5.4.0.1155.92 Available with Ubuntu Pro linux-image-azure-fips-5.4 5.4.0.1155.92 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7819-2 https://ubuntu.com/security/notices/USN-7819-1 CVE-2023-52757, CVE-2023-52975, CVE-2024-38541, CVE-2024-49950, CVE-2024-50073, CVE-2024-57996, CVE-2025-21796, CVE-2025-37752, CVE-2025-37785, CVE-2025-37797, CVE-2025-38083, CVE-2025-38350, CVE-2025-38477, CVE-2025-38617, CVE-2025-38618, CVE-2025-38683 Package Information: https://launchpad.net/ubuntu/+source/linux-azure-fips/5.4...


Attachment: OpenPGP_signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmj4CNQFAwAAAAAACgkQZ0GeRcM5nt31 iQf/UO/TlDxMNVzE3H4QAbUZUufqU55SXZxREO2kzN8VF4X8t+zKBVlCw6AcWGcGwoTy8b/mFR5l 7QhBNTUqbVnD/oAWLql8V8L2snZAUQUkVRw8rkcpxLCi/3YarHUi4Ulop7M3+GypbyXRCtWDmNiR nw4B+0l8sleEMQwX07Qk80LIxZxqMyKBkpr8/f3UN+S217YicRAjh7AL6fqPlq9WDf3YzhnEOlM/ 1Htw9TLCvXo0mSYCdMWY9t9lsqFvuhYleZ75V9riCDSEOqdKAuWwd4ZX4/tFs+UMcgC+G3vlNKWu iqMXchjuh/Gq6cFYHjwVhUtXFWu3MWigfebNsbZEOA== =C+Hl -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds