Skip to main content

Your submission was sent successfully! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates from Canonical and upcoming events where you can meet our team.Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

  1. Blog
  2. Article

Canonical
on 9 November 2017

Security Team Weekly Summary: November 9, 2017


The Security Team weekly reports are intended to be very short summaries of the Security Team’s weekly activities.

If you would like to reach the Security Team, you can find us at the #ubuntu-hardened channel on FreeNode. Alternatively, you can mail the Ubuntu Hardened mailing list at: ubuntu-hardened@lists.ubuntu.com

During the last week, the Ubuntu Security team:

  • Triaged 201 public security vulnerability reports, retaining the 45 that applied to Ubuntu.
  • Published 13 Ubuntu Security Notices which fixed 33 security issues (CVEs) across 16 supported packages.

Ubuntu Security Notices

Bug Triage

Mainline Inclusion Requests

Updates to Community Supported Packages

  • Lucas Kocia (lkocia) provided a debdiff for xenial for firewalld (LP: #1617617)

  • Jeremy Bicha (jbicha) provided a debdiff for zesty for gdm3 (LP: #1729354)

Development

  • fixed last of snappy-debug updates (handle core vs classic policy), test, push to stable
  • reviews
    • PR 4105 – i386/socket/trusty testsuite fix
    • review apparmor.d man page patch from jj
    • PR 4109 – fix parsing of mountinfo fields
    • PRs 4123 and 4124 – fix bug in ofono interface
    • PR 4136 – snap-confine apparmor policy bug
  • https://forum.snapcraft.io/t/device-cgroup-is-applied-to-devmode-snap/2663

  • documented the content interface wrt shared libraries to follow store guidelines for cross-publisher sharing.
  • documented auto-connection for a specific plugging snap to a specific slotting snap
  • documented errno for different security backends
  • 1724785
  • PR 4114 don’t udev tag with devmode/classic snaps
  • PR 4115 udev tag serial-port interface with only path attribute
  • PR 4116 udev tag hidraw interface with only path attribute
  • PR 4127 don’t udev tag but add /dev/uhid to device cgroup
  • PRs 4131-4134 for 2.29
  • Migrated AppArmor to GitLab: https://gitlab.com/apparmor

  • [Work-in-progress] AppArmor support for multiple policy cache directories: apparmor/apparmor!4

  • Simplified usage of libapparmor cleanup functions by preserving errno: apparmor/apparmor!6

  • Landed upstream libseccomp changes to support new dynamic seccomp logging: seccomp/libseccomp#92

What the Security Team is Reading This Week

Weekly Meeting

More Info

Related posts


Lech Sandecki
23 October 2024

6 facts for CentOS users who are holding on

Cloud and server Article

Considering migrating to Ubuntu from other Linux platforms, such as CentOS? Find six useful facts to get started! ...


Kris Sharma
17 October 2024

Why is Ubuntu Linux the leading choice to replace CentOS for financial services?

Financial Services Article

Financial services are powered by technology. The customer experience is increasingly driven by data, with tailoring of products and services to reflect individual behaviors and preferences. All of this rests on a foundation of secure, stable technology that can support agility and flexibility to adapt to customer needs, whilst at the sam ...


eslerm
19 November 2024

Needrestart local privilege escalation vulnerability fixes available

Ubuntu Article

Qualys discovered vulnerabilities which allow a local attacker to gain root privileges in the needrestart package (CVE-2024-48990, CVE-2024-48991, CVE-2024-48992, and CVE-2024-11003) and a related issue in libmodule-scandeps-perl (CVE-2024-10224). The vulnerabilities affect Debian, Ubuntu and other Linux distributions. Canonical’s securit ...