---
title: 'Security Team Weekly Summary: August 31, 2017'
description: 'The Security Team weekly reports are intended to be very short summaries
  of the Security Team’s weekly activities. If you would like to reach the Security
  Team, you can find us at the #ubuntu-hardened channel on FreeNode. Alternatively,
  you can mail the Ubuntu Hardened mailing list at: ubuntu-hardened@lists.ubuntu.com
  During the last week […]'
url: https://canonical.com/blog/security-team-weekly-summary-august-31-2017?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Canonical](https://canonical.com/blog/author/canonical "More about Canonical")

30 August 2017

# Security Team Weekly Summary: August 31, 2017

---

Share the article

The [Security Team](https://wiki.ubuntu.com/SecurityTeam) weekly reports are intended to be very short summaries of the Security Team’s weekly activities.

If you would like to reach the Security Team, you can find us at the #ubuntu-hardened channel on [FreeNode](https://wiki.ubuntu.com/FreeNode). Alternatively, you can mail the Ubuntu Hardened mailing list at: [ubuntu-hardened@lists.ubuntu.com](mailto:ubuntu-hardened@lists.ubuntu.com)

During the last week, the Ubuntu Security team:

* Triaged 287 public security vulnerability reports, retaining the 61 that applied to Ubuntu.
* Published 6 Ubuntu Security Notices which fixed 13 security issues (CVEs) across 6 supported packages.

### Ubuntu Security Notices

* [[USN-3402-1] PySAML2 vulnerability](https://www.ubuntu.com/usn/usn-3402-1)
* [[USN-3401-1] TeX Live vulnerability](https://www.ubuntu.com/usn/usn-3401-1)
* [[USN-3400-1] Augeas vulnerability](https://www.ubuntu.com/usn/usn-3400-1)
* [[USN-3399-1] cvs vulnerability](https://www.ubuntu.com/usn/usn-3399-1)
* [[USN-3398-1] graphite2 vulnerabilities](https://www.ubuntu.com/usn/usn-3398-1)
* [[USN-3397-1] strongSwan vulnerability](https://www.ubuntu.com/usn/usn-3397-1)

### Bug Triage

* Backlog: <https://bugs.launchpad.net/~ubuntu-security/+subscribedbugs>

### Mainline Inclusion Requests

* websockify (LP: #[1108935](https://bugs.launchpad.net/bugs/1108935 "Bug")) underway
* MIR backlog: <https://bugs.launchpad.net/~ubuntu-security/+assignedbugs?field.searchtext=%5BMIR%5D>

### Updates to Community Supported Packages

* Simon Quigley (tsimonq2) provided a debdiff for trusty for kdepimlibs (LP: #[1630700](https://bugs.launchpad.net/bugs/1630700 "Bug"))
* Simon Quigley (tsimonq2) provided a debdiff for xenial for kcoreaddons (LP: #[1630700](https://bugs.launchpad.net/bugs/1630700 "Bug"))
* Simon Quigley (tsimonq2) provided debdiffs for trusty-zesty for varnish (LP: #[1708354](https://bugs.launchpad.net/bugs/1708354 "Bug"))

### Development

* Updated review tools to calculate uncompressed squashfs size and error out if too large. Update to unpack to SNAP\_USER\_COMMON and cleanup stale review directories.
* review-tools fix for LP: #[1712476](https://bugs.launchpad.net/bugs/1712476 "Bug")
* review-tools: implement new ‘reload-command’ yaml and new execstack checks
* Submitted apparmor pull for artful to the Kernel Team.
* Submitted seccomp logging patch set for both artful 4.12 and artful 4.13 kernels.
* Submitted PR 3804 for user and group name lookups in snap-seccomp in support of snap privilege dropping.
* Submitted PR 3805 to stop hardcoding uids and gids (for ‘root’ and ‘shadow’).
* Submitted libseccomp PR for improved logging changes (<https://github.com/seccomp/libseccomp/pull/92>).
* fixed a libseccomp test runner bug that was causing a class of tests to not run (<https://github.com/seccomp/libseccomp/pull/91>).
* Work with design on ‘Snap interfaces GUI descriptions’
* Perform various PR reviews in support of cross-distro and improved udev tagging
* Meet with snapd team (Gustavo) on final designs for new desktop interfaces (PR 3719)

### What the Security Team is Reading This Week

* [Weird Python Integers](https://kate.io/blog/2017/08/22/weird-python-integers/)
* [Rethinking the dbus message bus](https://dvdhrm.github.io/rethinking-the-dbus-message-bus/)

### Weekly Meeting

* Weekly meeting was cancelled this week (eclipse watching)
* Info: <https://wiki.ubuntu.com/SecurityTeam/Meeting>

### More Info

* [Ubuntu CVE Tracker](http://people.canonical.com/~ubuntu-security/cve/)
* [Ubuntu security notices](https://www.ubuntu.com/usn/)
* [Follow Ubuntu Security on Twitter](https://www.twitter.com/ubuntu_sec)
* [How to help improve Ubuntu security](https://wiki.ubuntu.com/SecurityTeam/GettingInvolved)

[Get in touch

Interested in running Ubuntu in your organization?](https://ubuntu.com/about/contact-us/form)

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Canonical joins the Open Secure AI Alliance](https://canonical.com/blog/open-secure-ai-alliance)

Canonical is now part of the Open Secure AI Alliance, announced by NVIDIA with partners across cloud computing, cybersecurity, enterprise software, open source foundations, and...

[Canonical](https://canonical.com/blog/author/canonical)

28 August 2026

[### Arduino® VENTUNO™ Q is available for pre-order with Ubuntu pre-installed](https://canonical.com/blog/arduino-ventuno-q-is-available-for-pre-order-with-ubuntu-pre-installed)

London, UK – August 25, 2026 – Following our initial collaboration announcement in March 2026, Canonical and Arduino (a subsidiary of Qualcomm Technologies, Inc.) are excited...

[Canonical](https://canonical.com/blog/author/canonical)

25 August 2026

[### Advantech AOM-2721 is now Ubuntu Certified](https://canonical.com/blog/advantech-aom-2721-ubuntu-certified)

Canonical announces that the Advantech AOM-2721 is officially joining the list of Ubuntu Certified Hardware.

[Mikhail Khazov](https://canonical.com/blog/author/khazov-m)

13 August 2026

[### Canonical integrates NVIDIA Nemotron 3.5 Lightning with Ubuntu for always-on AI agents](https://canonical.com/blog/nvidia-nemotron-3-5-lightning)

Canonical is pleased to announce that NVIDIA’s newly introduced NVIDIA Nemotron 3.5 Lightning, an open, customizable model built for always-on AI agents, is now available on...

[Canonical](https://canonical.com/blog/author/canonical)

11 August 2026
