{"id":60431,"date":"2024-11-21T06:45:45","date_gmt":"2024-11-21T03:45:45","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/182703\/USN-7089-7.txt"},"modified":"2024-11-21T06:45:45","modified_gmt":"2024-11-21T03:45:45","slug":"ubuntu-security-notice-usn-7089-7","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/ubuntu-security-notice-usn-7089-7\/","title":{"rendered":"Ubuntu Security Notice USN-7089-7"},"content":{"rendered":"<p>==========================================================================<br \/>Ubuntu Security Notice USN-7089-7<br \/>November 19, 2024<\/p>\n<p>linux-lowlatency, linux-lowlatency-hwe-6.8 vulnerabilities<br \/>==========================================================================<\/p>\n<p>A security issue affects these releases of Ubuntu and its derivatives:<\/p>\n<p>&#8211; Ubuntu 24.04 LTS<br \/>&#8211; Ubuntu 22.04 LTS<\/p>\n<p>Summary:<\/p>\n<p>Several security issues were fixed in the Linux kernel.<\/p>\n<p>Software Description:<br \/>&#8211; linux-lowlatency: Linux low latency kernel<br \/>&#8211; linux-lowlatency-hwe-6.8: Linux low latency kernel<\/p>\n<p>Details:<\/p>\n<p>Chenyuan Yang discovered that the USB Gadget subsystem in the Linux<br \/>kernel did not properly check for the device to be enabled before<br \/>writing. A local attacker could possibly use this to cause a denial of<br \/>service. (CVE-2024-25741)<\/p>\n<p>Several security issues were discovered in the Linux kernel.<br \/>An attacker could possibly use these to compromise the system.<br \/>This update corrects flaws in the following subsystems:<br \/>&#8211; ARM32 architecture;<br \/>&#8211; MIPS architecture;<br \/>&#8211; PA-RISC architecture;<br \/>&#8211; PowerPC architecture;<br \/>&#8211; RISC-V architecture;<br \/>&#8211; S390 architecture;<br \/>&#8211; x86 architecture;<br \/>&#8211; Cryptographic API;<br \/>&#8211; Serial ATA and Parallel ATA drivers;<br \/>&#8211; Null block device driver;<br \/>&#8211; Bluetooth drivers;<br \/>&#8211; Cdrom driver;<br \/>&#8211; Clock framework and drivers;<br \/>&#8211; Hardware crypto device drivers;<br \/>&#8211; CXL (Compute Express Link) drivers;<br \/>&#8211; Cirrus firmware drivers;<br \/>&#8211; GPIO subsystem;<br \/>&#8211; GPU drivers;<br \/>&#8211; I2C subsystem;<br \/>&#8211; IIO subsystem;<br \/>&#8211; InfiniBand drivers;<br \/>&#8211; ISDN\/mISDN subsystem;<br \/>&#8211; LED subsystem;<br \/>&#8211; Multiple devices driver;<br \/>&#8211; Media drivers;<br \/>&#8211; Fastrpc Driver;<br \/>&#8211; Network drivers;<br \/>&#8211; Microsoft Azure Network Adapter (MANA) driver;<br \/>&#8211; Near Field Communication (NFC) drivers;<br \/>&#8211; NVME drivers;<br \/>&#8211; NVMEM (Non Volatile Memory) drivers;<br \/>&#8211; PCI subsystem;<br \/>&#8211; Pin controllers subsystem;<br \/>&#8211; x86 platform drivers;<br \/>&#8211; S\/390 drivers;<br \/>&#8211; SCSI drivers;<br \/>&#8211; Thermal drivers;<br \/>&#8211; TTY drivers;<br \/>&#8211; UFS subsystem;<br \/>&#8211; USB DSL drivers;<br \/>&#8211; USB core drivers;<br \/>&#8211; DesignWare USB3 driver;<br \/>&#8211; USB Gadget drivers;<br \/>&#8211; USB Serial drivers;<br \/>&#8211; VFIO drivers;<br \/>&#8211; VHOST drivers;<br \/>&#8211; File systems infrastructure;<br \/>&#8211; BTRFS file system;<br \/>&#8211; GFS2 file system;<br \/>&#8211; JFFS2 file system;<br \/>&#8211; JFS file system;<br \/>&#8211; Network file systems library;<br \/>&#8211; Network file system client;<br \/>&#8211; NILFS2 file system;<br \/>&#8211; NTFS3 file system;<br \/>&#8211; SMB network file system;<br \/>&#8211; Memory management;<br \/>&#8211; Netfilter;<br \/>&#8211; Tracing infrastructure;<br \/>&#8211; io_uring subsystem;<br \/>&#8211; BPF subsystem;<br \/>&#8211; Core kernel;<br \/>&#8211; Bluetooth subsystem;<br \/>&#8211; CAN network layer;<br \/>&#8211; Ceph Core library;<br \/>&#8211; Networking core;<br \/>&#8211; IPv4 networking;<br \/>&#8211; IPv6 networking;<br \/>&#8211; IUCV driver;<br \/>&#8211; MAC80211 subsystem;<br \/>&#8211; Network traffic control;<br \/>&#8211; Sun RPC protocol;<br \/>&#8211; Wireless networking;<br \/>&#8211; AMD SoC Alsa drivers;<br \/>&#8211; SoC Audio for Freescale CPUs drivers;<br \/>&#8211; MediaTek ASoC drivers;<br \/>&#8211; SoC audio core drivers;<br \/>&#8211; SOF drivers;<br \/>&#8211; Sound sequencer drivers;<br \/>(CVE-2024-42104, CVE-2024-42084, CVE-2024-42252, CVE-2024-41096,<br \/>CVE-2024-42237, CVE-2024-42140, CVE-2024-42150, CVE-2024-41031,<br \/>CVE-2024-41059, CVE-2024-41062, CVE-2024-41051, CVE-2024-41028,<br \/>CVE-2024-41090, CVE-2024-41092, CVE-2024-43855, CVE-2024-41021,<br \/>CVE-2024-42229, CVE-2024-41056, CVE-2024-41048, CVE-2024-41036,<br \/>CVE-2024-42094, CVE-2024-41089, CVE-2024-41068, CVE-2024-41039,<br \/>CVE-2024-41095, CVE-2024-41069, CVE-2024-42234, CVE-2024-42136,<br \/>CVE-2024-41025, CVE-2024-42157, CVE-2024-42248, CVE-2024-42087,<br \/>CVE-2024-41041, CVE-2024-42230, CVE-2024-42151, CVE-2024-42130,<br \/>CVE-2024-42244, CVE-2024-41079, CVE-2024-42253, CVE-2024-42092,<br \/>CVE-2024-41022, CVE-2024-42137, CVE-2024-42132, CVE-2024-42108,<br \/>CVE-2024-42155, CVE-2024-42127, CVE-2024-41060, CVE-2024-42074,<br \/>CVE-2024-41081, CVE-2024-42066, CVE-2024-42098, CVE-2024-42082,<br \/>CVE-2024-42093, CVE-2024-42245, CVE-2024-41072, CVE-2024-41052,<br \/>CVE-2024-42161, CVE-2024-42096, CVE-2024-42115, CVE-2024-41074,<br \/>CVE-2024-42120, CVE-2024-41046, CVE-2024-42239, CVE-2024-41063,<br \/>CVE-2024-42090, CVE-2024-41023, CVE-2024-42069, CVE-2024-41087,<br \/>CVE-2024-42158, CVE-2024-41067, CVE-2024-41084, CVE-2024-41077,<br \/>CVE-2024-42240, CVE-2024-42145, CVE-2024-42102, CVE-2024-41020,<br \/>CVE-2024-42231, CVE-2024-41053, CVE-2024-42131, CVE-2024-42089,<br \/>CVE-2024-41083, CVE-2024-42247, CVE-2024-42105, CVE-2024-41044,<br \/>CVE-2024-42128, CVE-2024-42271, CVE-2024-41037, CVE-2024-42114,<br \/>CVE-2024-42106, CVE-2024-41076, CVE-2024-42088, CVE-2024-41057,<br \/>CVE-2024-41091, CVE-2024-42152, CVE-2024-41070, CVE-2024-41035,<br \/>CVE-2024-41050, CVE-2024-39487, CVE-2024-42113, CVE-2024-42250,<br \/>CVE-2024-41047, CVE-2024-42149, CVE-2024-42079, CVE-2024-42091,<br \/>CVE-2024-42227, CVE-2024-42095, CVE-2024-42109, CVE-2024-41033,<br \/>CVE-2023-52888, CVE-2024-41061, CVE-2024-42223, CVE-2024-42235,<br \/>CVE-2024-41086, CVE-2024-42133, CVE-2024-41082, CVE-2024-41071,<br \/>CVE-2024-41007, CVE-2023-52887, CVE-2024-39486, CVE-2024-41075,<br \/>CVE-2024-42101, CVE-2024-42077, CVE-2024-41042, CVE-2024-42225,<br \/>CVE-2024-42126, CVE-2024-41094, CVE-2024-41085, CVE-2024-41019,<br \/>CVE-2024-41058, CVE-2024-41066, CVE-2024-42156, CVE-2024-42119,<br \/>CVE-2024-41032, CVE-2024-41088, CVE-2024-42100, CVE-2024-42142,<br \/>CVE-2024-41054, CVE-2024-42103, CVE-2024-42124, CVE-2024-41034,<br \/>CVE-2024-42251, CVE-2024-42153, CVE-2024-41045, CVE-2024-42086,<br \/>CVE-2024-42243, CVE-2024-41055, CVE-2024-41078, CVE-2024-42117,<br \/>CVE-2024-41030, CVE-2024-42068, CVE-2024-42110, CVE-2024-42147,<br \/>CVE-2024-42121, CVE-2024-41080, CVE-2024-41027, CVE-2024-43858,<br \/>CVE-2024-42085, CVE-2024-42111, CVE-2024-42238, CVE-2024-41018,<br \/>CVE-2024-42138, CVE-2024-41038, CVE-2024-42070, CVE-2024-42141,<br \/>CVE-2024-41098, CVE-2024-42118, CVE-2024-41073, CVE-2024-42144,<br \/>CVE-2024-42280, CVE-2024-41049, CVE-2024-42076, CVE-2024-41065,<br \/>CVE-2024-42063, CVE-2024-41064, CVE-2024-41017, CVE-2024-42112,<br \/>CVE-2024-42064, CVE-2024-42135, CVE-2024-42146, CVE-2024-41010,<br \/>CVE-2024-41097, CVE-2024-41012, CVE-2024-42097, CVE-2024-42067,<br \/>CVE-2024-42236, CVE-2024-42080, CVE-2024-42241, CVE-2024-42065,<br \/>CVE-2024-42232, CVE-2024-42246, CVE-2024-41093, CVE-2024-41015,<br \/>CVE-2024-42129, CVE-2024-42073, CVE-2024-41029)<\/p>\n<p>Update instructions:<\/p>\n<p>The problem can be corrected by updating your system to the following<br \/>package versions:<\/p>\n<p>Ubuntu 24.04 LTS<br \/>linux-image-6.8.0-48-lowlatency 6.8.0-48.48.3<br \/>linux-image-6.8.0-48-lowlatency-64k 6.8.0-48.48.3<br \/>linux-image-lowlatency 6.8.0-48.48.3<br \/>linux-image-lowlatency-64k 6.8.0-48.48.3<br \/>linux-image-lowlatency-64k-hwe-24.04 6.8.0-48.48.3<br \/>linux-image-lowlatency-hwe-24.04 6.8.0-48.48.3<\/p>\n<p>Ubuntu 22.04 LTS<br \/>linux-image-6.8.0-48-lowlatency 6.8.0-48.48.3~22.04.1<br \/>linux-image-6.8.0-48-lowlatency-64k 6.8.0-48.48.3~22.04.1<br \/>linux-image-lowlatency-64k-hwe-22.04 6.8.0-48.48.3~22.04.1<br \/>linux-image-lowlatency-hwe-22.04 6.8.0-48.48.3~22.04.1<\/p>\n<p>After a standard system update you need to reboot your computer to make<br \/>all the necessary changes.<\/p>\n<p>ATTENTION: Due to an unavoidable ABI change the kernel updates have<br \/>been given a new version number, which requires you to recompile and<br \/>reinstall all third party kernel modules you might have installed.<br \/>Unless you manually uninstalled the standard kernel metapackages<br \/>(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,<br \/>linux-powerpc), a standard system upgrade will automatically perform<br \/>this as well.<\/p>\n<p>References:<br \/>https:\/\/ubuntu.com\/security\/notices\/USN-7089-7<br \/>https:\/\/ubuntu.com\/security\/notices\/USN-7089-6<br \/>https:\/\/ubuntu.com\/security\/notices\/USN-7089-5<br \/>https:\/\/ubuntu.com\/security\/notices\/USN-7089-4<br \/>https:\/\/ubuntu.com\/security\/notices\/USN-7089-3<br \/>https:\/\/ubuntu.com\/security\/notices\/USN-7089-2<br \/>https:\/\/ubuntu.com\/security\/notices\/USN-7089-1<br \/>CVE-2023-52887, CVE-2023-52888, CVE-2024-25741, CVE-2024-39486,<br \/>CVE-2024-39487, CVE-2024-41007, CVE-2024-41010, CVE-2024-41012,<br \/>CVE-2024-41015, CVE-2024-41017, CVE-2024-41018, CVE-2024-41019,<br \/>CVE-2024-41020, CVE-2024-41021, CVE-2024-41022, CVE-2024-41023,<br \/>CVE-2024-41025, CVE-2024-41027, CVE-2024-41028, CVE-2024-41029,<br \/>CVE-2024-41030, CVE-2024-41031, CVE-2024-41032, CVE-2024-41033,<br \/>CVE-2024-41034, CVE-2024-41035, CVE-2024-41036, CVE-2024-41037,<br \/>CVE-2024-41038, CVE-2024-41039, CVE-2024-41041, CVE-2024-41042,<br \/>CVE-2024-41044, CVE-2024-41045, CVE-2024-41046, CVE-2024-41047,<br \/>CVE-2024-41048, CVE-2024-41049, CVE-2024-41050, CVE-2024-41051,<br \/>CVE-2024-41052, CVE-2024-41053, CVE-2024-41054, CVE-2024-41055,<br \/>CVE-2024-41056, CVE-2024-41057, CVE-2024-41058, CVE-2024-41059,<br \/>CVE-2024-41060, CVE-2024-41061, CVE-2024-41062, CVE-2024-41063,<br \/>CVE-2024-41064, CVE-2024-41065, CVE-2024-41066, CVE-2024-41067,<br \/>CVE-2024-41068, CVE-2024-41069, CVE-2024-41070, CVE-2024-41071,<br \/>CVE-2024-41072, CVE-2024-41073, CVE-2024-41074, CVE-2024-41075,<br \/>CVE-2024-41076, CVE-2024-41077, CVE-2024-41078, CVE-2024-41079,<br \/>CVE-2024-41080, CVE-2024-41081, CVE-2024-41082, CVE-2024-41083,<br \/>CVE-2024-41084, CVE-2024-41085, CVE-2024-41086, CVE-2024-41087,<br \/>CVE-2024-41088, CVE-2024-41089, CVE-2024-41090, CVE-2024-41091,<br \/>CVE-2024-41092, CVE-2024-41093, CVE-2024-41094, CVE-2024-41095,<br \/>CVE-2024-41096, CVE-2024-41097, CVE-2024-41098, CVE-2024-42063,<br \/>CVE-2024-42064, CVE-2024-42065, CVE-2024-42066, CVE-2024-42067,<br \/>CVE-2024-42068, CVE-2024-42069, CVE-2024-42070, CVE-2024-42073,<br \/>CVE-2024-42074, CVE-2024-42076, CVE-2024-42077, CVE-2024-42079,<br \/>CVE-2024-42080, CVE-2024-42082, CVE-2024-42084, CVE-2024-42085,<br \/>CVE-2024-42086, CVE-2024-42087, CVE-2024-42088, CVE-2024-42089,<br \/>CVE-2024-42090, CVE-2024-42091, CVE-2024-42092, CVE-2024-42093,<br \/>CVE-2024-42094, CVE-2024-42095, CVE-2024-42096, CVE-2024-42097,<br \/>CVE-2024-42098, CVE-2024-42100, CVE-2024-42101, CVE-2024-42102,<br \/>CVE-2024-42103, CVE-2024-42104, CVE-2024-42105, CVE-2024-42106,<br \/>CVE-2024-42108, CVE-2024-42109, CVE-2024-42110, CVE-2024-42111,<br \/>CVE-2024-42112, CVE-2024-42113, CVE-2024-42114, CVE-2024-42115,<br \/>CVE-2024-42117, CVE-2024-42118, CVE-2024-42119, CVE-2024-42120,<br \/>CVE-2024-42121, CVE-2024-42124, CVE-2024-42126, CVE-2024-42127,<br \/>CVE-2024-42128, CVE-2024-42129, CVE-2024-42130, CVE-2024-42131,<br \/>CVE-2024-42132, CVE-2024-42133, CVE-2024-42135, CVE-2024-42136,<br \/>CVE-2024-42137, CVE-2024-42138, CVE-2024-42140, CVE-2024-42141,<br \/>CVE-2024-42142, CVE-2024-42144, CVE-2024-42145, CVE-2024-42146,<br \/>CVE-2024-42147, CVE-2024-42149, CVE-2024-42150, CVE-2024-42151,<br \/>CVE-2024-42152, CVE-2024-42153, CVE-2024-42155, CVE-2024-42156,<br \/>CVE-2024-42157, CVE-2024-42158, CVE-2024-42161, CVE-2024-42223,<br \/>CVE-2024-42225, CVE-2024-42227, CVE-2024-42229, CVE-2024-42230,<br \/>CVE-2024-42231, CVE-2024-42232, CVE-2024-42234, CVE-2024-42235,<br \/>CVE-2024-42236, CVE-2024-42237, CVE-2024-42238, CVE-2024-42239,<br \/>CVE-2024-42240, CVE-2024-42241, CVE-2024-42243, CVE-2024-42244,<br \/>CVE-2024-42245, CVE-2024-42246, CVE-2024-42247, CVE-2024-42248,<br \/>CVE-2024-42250, CVE-2024-42251, CVE-2024-42252, CVE-2024-42253,<br \/>CVE-2024-42271, CVE-2024-42280, CVE-2024-43855, CVE-2024-43858<\/p>\n<p>Package Information:<br \/>https:\/\/launchpad.net\/ubuntu\/+source\/linux-lowlatency\/6.8.0-48.48.3<\/p>\n<p>https:\/\/launchpad.net\/ubuntu\/+source\/linux-lowlatency-hwe-6.8\/6.8.0-48.48.3~22.04.1<\/p>\n","protected":false},"excerpt":{"rendered":"<p>==========================================================================Ubuntu Security Notice USN-7089-7November 19, 2024 linux-lowlatency, linux-lowlatency-hwe-6.8 vulnerabilities========================================================================== A security issue affects these releases of Ubuntu and its derivatives: &#8211; Ubuntu 24.04 LTS&#8211; Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description:&#8211; linux-lowlatency: Linux low latency kernel&#8211; linux-lowlatency-hwe-6.8: Linux low latency kernel Details: Chenyuan Yang discovered that the &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-60431","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/60431","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=60431"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/60431\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=60431"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=60431"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=60431"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}