---
title: 'Security Team Weekly Summary: November 16, 2017'
description: 'The Security Team weekly reports are intended to be very short summaries
  of the Security Team’s weekly activities. If you would like to reach the Security
  Team, you can find us at the #ubuntu-hardened channel on FreeNode. Alternatively,
  you can mail the Ubuntu Hardened mailing list at: ubuntu-hardened@lists.ubuntu.com
  During the last we […]'
url: https://canonical.com/blog/security-team-weekly-summary-november-16-2017?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Canonical](https://canonical.com/blog/author/canonical "More about Canonical")

16 November 2017

# Security Team Weekly Summary: November 16, 2017

[Linux](https://canonical.com/blog/tag/linux)
[livepatch](https://canonical.com/blog/tag/livepatch)
[OpenJDK](https://canonical.com/blog/tag/openjdk)
[OpenSSL](https://canonical.com/blog/tag/openssl)
[Security](https://canonical.com/blog/tag/security)
[ssl](https://canonical.com/blog/tag/ssl)
[Vulnerabilities](https://canonical.com/blog/tag/vulnerabilities)

---

Share the article

The [Security Team](https://wiki.ubuntu.com/SecurityTeam) weekly reports are intended to be very short summaries of the Security Team’s weekly activities.

If you would like to reach the Security Team, you can find us at the #ubuntu-hardened channel on [FreeNode](https://wiki.ubuntu.com/FreeNode). Alternatively, you can mail the Ubuntu Hardened mailing list at: [ubuntu-hardened@lists.ubuntu.com](mailto:ubuntu-hardened@lists.ubuntu.com)

During the last week, the Ubuntu Security team:

* Triaged 149 public security vulnerability reports, retaining the 50 that applied to Ubuntu.
* Published 5 Ubuntu Security Notices which fixed 21 security issues (CVEs) across 5 supported packages.

### Ubuntu Security Notices

* [[USN-3476-1] postgresql-common vulnerabilities](https://www.ubuntu.com/usn/usn-3476-1)
* [[USN-3346-3] Bind vulnerabilities](https://www.ubuntu.com/usn/usn-3346-3)
* [[USN-3473-1] OpenJDK 8 vulnerabilities](https://www.ubuntu.com/usn/usn-3473-1)
* [[USN-3475-1] OpenSSL vulnerabilities](https://www.ubuntu.com/usn/usn-3475-1)
* [[USN-3474-1] Liblouis vulnerability](https://www.ubuntu.com/usn/usn-3474-1)

### Bug Triage

* Backlog: <https://bugs.launchpad.net/~ubuntu-security/+subscribedbugs>

### Mainline Inclusion Requests

* spice-vdagent underway (LP: #[1200296](https://bugs.launchpad.net/bugs/1200296 "Bug"))
* MIR backlog: <https://bugs.launchpad.net/~ubuntu-security/+assignedbugs?field.searchtext=%5BMIR%5D>

### Development

* (snapd) submitted fix for for /dev/pts slave EPERM fix – PR 4159 and 4160 (2.29)
* (snapd) submitted fix for modprobe failure causing all security backends to fail – PR 4162
* (snapd) submitted fix for raw-usb udev\_enumerate issue – PR 4164 and 4165 (2.29)
* (snapd) created policy-updates-xxxii PR for master (PR 4180) and 2.29 (PR 4181), coordinate with snapd team. Among other things, this has a workaround rule for the above electron denial
* (snapd) submitted ‘add test-policy-app spread test’ – PR 4157
* updated eCryptfs -next branch for linux-next testing and got it ready to create a 4.15 pull request
* snapd reviews
  + ‘fix udev tagging for hooks’ – PR 4144
  + ‘drop group filter from seccomp rules’ PR 4185
  + ‘support bash as base runtime’ PR 4197
* landed documentation for the new (Linux 4.14) seccomp dynamic logging support in the upstream Linux man-pages project: [1](https://git.kernel.org/pub/scm/docs/man-pages/man-pages.git/commit/?id=2577dbba2b4f0906d2941e5f38095a494537b255), [2](https://git.kernel.org/pub/scm/docs/man-pages/man-pages.git/commit/?id=6d1728dad1adcfae9248081a9c39ced2a16bd160), [3](https://git.kernel.org/pub/scm/docs/man-pages/man-pages.git/commit/?id=17c56ad055e349b690cf4eb6ff375df86c1136b7), [4](https://git.kernel.org/pub/scm/docs/man-pages/man-pages.git/commit/?id=f04207f4062e95d97a994586a4af30f6eab586e4)

### What the Security Team is Reading This Week

* [Why TLS 1.3 isn’t there yet](https://www.feistyduck.com/bulletproof-tls-newsletter/issue_33_why_tls_13_isnt_there_yet)
* [Exploiting CVE-2017-5123 with full protections. SMEP, SMAP, and the Chrome Sandbox!](https://salls.github.io/Linux-Kernel-CVE-2017-5123/)

### Weekly Meeting

* Log: <https://wiki.ubuntu.com/MeetingLogs/Security/20171106>
* Info: <https://wiki.ubuntu.com/SecurityTeam/Meeting>

### More Info

* [Ubuntu CVE Tracker](http://people.canonical.com/~ubuntu-security/cve/)
* [Ubuntu security notices](https://www.ubuntu.com/usn/)
* [Follow Ubuntu Security on Twitter](https://www.twitter.com/ubuntu_sec)
* [How to help improve Ubuntu security](https://wiki.ubuntu.com/SecurityTeam/GettingInvolved)

[Get in touch

Interested in running Ubuntu in your organization?](https://ubuntu.com/about/contact-us/form)

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Januscape vulnerability CVE-2026-53359 mitigations available](https://canonical.com/blog/januscape-linux-vulnerability-mitigations-available)

Introduction A local privilege escalation (LPE) vulnerability affecting the Linux kernel was publicly disclosed on July 6, 2026. The vulnerability was assigned CVE ID...

[seth-arnold](https://canonical.com/blog/author/seth-arnold)

11 July 2026

[### DirtyClone Linux kernel local privilege escalation vulnerability fixes available](https://canonical.com/blog/dirtyclone-linux-vulnerability-fixes-available)

On June 25, 2026, JFrog published their research into CVE-2026-43503, referring to the vulnerability as DirtyClone. The vulnerability had previously been responsibly disclosed...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026

[### pedit COW kernel local privilege escalation vulnerability mitigations](https://canonical.com/blog/pedit-cow-linux-vulnerability-fixes-available)

Mitigations are available for the Linux vulnerability with CVE ID CVE-2026-46331. The CVE ID was assigned on June 16 2026 and highlighted as a local privilege escalation (LPE)...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026

[### PinTheft Linux kernel vulnerability mitigation](https://canonical.com/blog/pintheft-linux-kernel-vulnerability-mitigation)

A local privilege escalation (LPE) security vulnerability in the Linux kernel, codename “PinTheft,” was publicly disclosed on May 19, 2026. The vulnerability was fixed in the...

[seth-arnold](https://canonical.com/blog/author/seth-arnold)

21 May 2026
