{"id":59003,"date":"2024-08-20T18:30:00","date_gmt":"2024-08-20T15:30:00","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/180265\/LSN-0106-1.txt"},"modified":"2024-08-20T18:30:00","modified_gmt":"2024-08-20T15:30:00","slug":"kernel-live-patch-security-notice-lsn-0106-1","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/kernel-live-patch-security-notice-lsn-0106-1\/","title":{"rendered":"Kernel Live Patch Security Notice LSN-0106-1"},"content":{"rendered":"<p>Linux kernel vulnerabilities<\/p>\n<p>A security issue affects these releases of Ubuntu and its derivatives:<\/p>\n<p>&#8211; Ubuntu 20.04 LTS<br \/>&#8211; Ubuntu 18.04 LTS<br \/>&#8211; Ubuntu 16.04 LTS<br \/>&#8211; Ubuntu 22.04 LTS<br \/>&#8211; Ubuntu 14.04 LTS<\/p>\n<p>Summary<\/p>\n<p>Several security issues were fixed in the kernel.<\/p>\n<p>Software Description<\/p>\n<p>&#8211; linux &#8211; Linux kernel<br \/>&#8211; linux-aws &#8211; Linux kernel for Amazon Web Services (AWS) systems<br \/>&#8211; linux-azure &#8211; Linux kernel for Microsoft Azure Cloud systems<br \/>&#8211; linux-gcp &#8211; Linux kernel for Google Cloud Platform (GCP) systems<br \/>&#8211; linux-gke &#8211; Linux kernel for Google Container Engine (GKE) systems<br \/>&#8211; linux-gkeop &#8211; Linux kernel for Google Container Engine (GKE) systems<br \/>&#8211; linux-ibm &#8211; Linux kernel for IBM cloud systems<br \/>&#8211; linux-oracle &#8211; Linux kernel for Oracle Cloud systems<\/p>\n<p>Details<\/p>\n<p>In the Linux kernel, the following vulnerability has been<br \/>resolved: netfilter: nf_tables: disallow timeout for anonymous sets<br \/>Never used from userspace, disallow these parameters.(CVE-2023-52620)<\/p>\n<p>In the Linux kernel, the following vulnerability has been<br \/>resolved: tls: fix race between tx work scheduling and socket close<br \/>Similarly to previous commit, the submitting thread (recvmsg\/sendmsg)<br \/>may exit as soon as the async crypto handler calls complete(). Reorder<br \/>scheduling the work before calling complete(). This seems more logical<br \/>in the first place, as it\u2019s the inverse order of what the submitting<br \/>thread will do.(CVE-2024-26585)<\/p>\n<p>In the Linux kernel, the following vulnerability has been<br \/>resolved: tty: n_gsm: fix possible out-of-bounds in gsm0_receive()<br \/>Assuming the following: &#8211; side A configures the n_gsm in basic option<br \/>mode &#8211; side B sends the header of a basic option mode frame with data<br \/>length 1 &#8211; side A switches to advanced option mode &#8211; side B sends 2 data<br \/>bytes which exceeds gsm-&gt;len Reason: gsm-&gt;len is not used in advanced<br \/>option mode. &#8211; side A switches to basic option mode &#8211; side B keeps<br \/>sending until gsm0_receive() writes past gsm-&gt;buf Reason: Neither<br \/>gsm-&gt;state nor gsm-&gt;len have been reset after reconfiguration. Fix this<br \/>by changing gsm-&gt;count to gsm-&gt;len comparison from equal to less than.<br \/>Also add upper limit checks against the constant MAX_MRU in<br \/>gsm0_receive() and gsm1_receive() to harden against memory corruption of<br \/>gsm-&gt;len and gsm-&gt;mru. All other checks remain as we still need to limit<br \/>the data according to the user configuration and actual payload size.](CVE-2024-36016)<\/p>\n<p>Update instructions<\/p>\n<p>The problem can be corrected by updating your kernel livepatch to the<br \/>following versions:<\/p>\n<p>Ubuntu 20.04 LTS<br \/>aws &#8211; 106.1<br \/>azure &#8211; 106.1<br \/>gcp &#8211; 106.1<br \/>generic &#8211; 106.1<br \/>gkeop &#8211; 106.1<br \/>ibm &#8211; 106.1<br \/>lowlatency &#8211; 106.1<br \/>oracle &#8211; 106.1<\/p>\n<p>Ubuntu 18.04 LTS<br \/>aws &#8211; 106.1<br \/>azure &#8211; 106.1<br \/>gcp &#8211; 106.1<br \/>generic &#8211; 106.1<br \/>lowlatency &#8211; 106.1<br \/>oracle &#8211; 106.1<\/p>\n<p>Ubuntu 16.04 LTS<br \/>aws &#8211; 106.1<br \/>azure &#8211; 106.1<br \/>gcp &#8211; 106.1<br \/>generic &#8211; 106.1<br \/>lowlatency &#8211; 106.1<\/p>\n<p>Ubuntu 22.04 LTS<br \/>aws &#8211; 106.1<br \/>azure &#8211; 106.1<br \/>gcp &#8211; 106.1<br \/>generic &#8211; 106.1<br \/>gke &#8211; 106.1<br \/>ibm &#8211; 106.1<br \/>oracle &#8211; 106.1<\/p>\n<p>Ubuntu 14.04 LTS<br \/>generic &#8211; 106.1<br \/>lowlatency &#8211; 106.1<\/p>\n<p>Support Information<\/p>\n<p>Livepatches for supported LTS kernels will receive upgrades for a period<br \/>of up to 13 months after the build date of the kernel.<\/p>\n<p>Livepatches for supported HWE kernels which are not based on an LTS<br \/>kernel version will receive upgrades for a period of up to 9 months<br \/>after the build date of the kernel, or until the end of support for that<br \/>kernel\u2019s non-LTS distro release version, whichever is sooner.<\/p>\n<p>References<\/p>\n<p>&#8211; CVE-2023-52620<br \/>&#8211; CVE-2024-26585<br \/>&#8211; CVE-2024-36016<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Linux kernel vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: &#8211; Ubuntu 20.04 LTS&#8211; Ubuntu 18.04 LTS&#8211; Ubuntu 16.04 LTS&#8211; Ubuntu 22.04 LTS&#8211; Ubuntu 14.04 LTS Summary Several security issues were fixed in the kernel. Software Description &#8211; linux &#8211; Linux kernel&#8211; linux-aws &#8211; Linux kernel for Amazon Web Services (AWS) &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-59003","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59003","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=59003"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59003\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=59003"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=59003"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=59003"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}