Ubuntu alert USN-6864-1 (linux-gcp, linux-intel)
| From: | Rodrigo Figueiredo Zaiden <rodrigo.zaiden@canonical.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-6864-1] Linux kernel vulnerabilities | |
| Date: | Wed, 03 Jul 2024 23:38:05 -0300 | |
| Message-ID: | <3389a00f-0678-4dbb-9a41-6279c4867f8e@canonical.com> |
========================================================================== Ubuntu Security Notice USN-6864-1 July 04, 2024 linux-gcp, linux-intel vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-intel: Linux kernel for Intel IoT platforms Details: It was discovered that the Intel Data Streaming and Intel Analytics Accelerator drivers in the Linux kernel allowed direct access to the devices for unprivileged users and virtual machines. A local attacker could use this to cause a denial of service. (CVE-2024-21823) A security issue was discovered in the Linux kernel. An attacker could possibly use it to compromise the system. This update corrects flaws in the following subsystem: - Netfilter; (CVE-2024-26924) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS linux-image-6.8.0-1006-intel 6.8.0-1006.13 linux-image-6.8.0-1009-gcp 6.8.0-1009.10 linux-image-gcp 6.8.0-1009.10 linux-image-intel 6.8.0-1006.13 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-6864-1 CVE-2024-21823, CVE-2024-26924 Package Information: https://launchpad.net/ubuntu/+source/linux-gcp/6.8.0-1009.10 https://launchpad.net/ubuntu/+source/linux-intel/6.8.0-10...
Attachment: OpenPGP_signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmaGCw0FAwAAAAAACgkQZ0GeRcM5nt01 UggArz0Fz/GbQ2K5O8Pvy9KrqC7TDO7k5dcoKJL5wAskPckdXidZm3u6imSaMmuIdcxP0m6x4r0a AoB35C1Nlt5uUD04Ql+9R2/eykUo9cli90gI5mYm2CQAOmulmV/WTg8hacAHAgxIFbnlclHyRZyp 58S/JRxm5vuC4IqkYzYrF/wCfkIAedP54Y0dWDqfxz4Od7BumCRbul2iN+2EY1w1b31RzgNvqeep htaq1HQBaTHGtqyWrEd9c1Nr1Xyt0EPOr7xCY/TdbqNo758EyHYEfClGTmHnMpFv33WLl+Opl/gU Q0zvQh536IFa4xDsh/XWWgsbDZVF2IzBoGyBaXDSwg== =QfOz -----END PGP SIGNATURE-----
Attachment: None (type=text/plain)
