|
|
Log in / Subscribe / Register

Ubuntu alert USN-8325-1 (tgt)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8325-1] tgt vulnerability
Date:  Wed, 27 May 2026 16:54:49 +0000
Message-ID:  <E1wSHWr-0001xe-U1@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-8325-1 May 27, 2026 tgt vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: tgt could be made to generate an identical sequence of challenges. Software Description: - tgt: Linux SCSI target user-space daemon Details: It was discovered that tgt incorrectly tried to achieve entropy by calling rand without srand. An attacker could possibly use this issue to make tgt generate an identical sequence of challenges, resulting in authentication bypass. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS tgt 1:1.0.85-1.1ubuntu6+esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS tgt 1:1.0.80-1ubuntu2+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS tgt 1:1.0.72-1ubuntu1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS tgt 1:1.0.63-1ubuntu1.1+esm1 Available with Ubuntu Pro Ubuntu 14.04 LTS tgt 1:1.0.43-0ubuntu4.1~14.04.3+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8325-1 CVE-2024-45751


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIyBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmoXIPEACgkQcpJm3tlz hgGhNQ/2JvbSESPeytUy4r9fyl+pehA+7GkdODUbDOeVqtdckeAVSe9kXC/fROhW e0Z+5a1A4Xd9N1fHR5fLQeGSiNeBA0M+B5M2E0fv5Ct5vm8FFbWNh37JV5NWdwL2 3Rlrl4g06V0kYW9Jag2lEq+viWBCj+uS2h5beYi2awzP302+rwfVAQLxT6ThbsZ+ b+/MUgb6LM4aeddrGnIQIv/wgFbYsMJ1UwjL+dO29A9xLcsk87DJ+/7RkTbm67uV jDdPbe5TwO984/8+/UlBfPlxdKG/i/CWbM/NpfjjzuTr2LZQW/qXQOM1DPE2Rnxr OzSOvNG1+FCW1PJWLv/v1zeZd9wx4usFzu1Rfo+tkGDwiwGu/dv5o9E2Smdkh3O5 hfXLhOo1IUb7vtJdLP1gGkbGkxXrUdgZ7JYHDQyn46xnpNvm9Tnj0CaWVGxKUpGd dtKLcvl8bHOIbk1XDWfDFMmHmheDY0BpIj3lHJ5WSRg729pzxNd2KuSwSEy1fWFC 7ze70lNpewP2Mit639eTkq7VBqUM5NACgRwvgYMFK4K5nwWVnkBTh2mXVF7jhfb0 KGepFqE5nlpBnQKGmh+HVROO+F4Ilv6AOHFIJ/eGZLLMq8jus8qBXqr9HxUQlEOL AMW7s4Rg2GoPppZbFGvCshJyQMrEN/AV7qeMvtPoTPhxgf5k9Q== =u0PB -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds