ABOUT THIS EPISODE
Overview
John and Maximé have been talking about Ubuntu’s AppArmor user namespace restrictions at the the Linux Security Summit in Europe this past week, plus we cover some more details from the official announcement of permission prompting in Ubuntu 24.10, a new release of Intel TDX for Ubuntu 24.04 LTS and more.
This week in Ubuntu Security Updates (01:11)613 unique CVEs addressed in the past fortnight
[USN-6989-1] OpenStack vulnerability- 1 CVEs addressed in Jammy (22.04 LTS), Noble (24.04 LTS)
- 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS)
- 8 CVEs addressed in Focal (20.04 LTS)
- 2 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS)
- 1 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS)
- 10 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
- 6 CVEs addressed in Jammy (22.04 LTS), Noble (24.04 LTS)
- 1 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM)
- 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS)
- 2 CVEs addressed in Jammy (22.04 LTS)
- HTTP/2 DoS, seen exploited in the wild and listen on the CISA KEV
- 2 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS)
- 220 CVEs addressed in Noble (24.04 LTS)
- Full CVE list elided - see USN for details
- 85 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS)
- Full CVE list elided - see USN for details
- 221 CVEs addressed in Noble (24.04 LTS)
- Full CVE list elided - see USN for details
- 219 CVEs addressed in Jammy (22.04 LTS), Noble (24.04 LTS)
- Full CVE list elided - see USN for details
- 94 CVEs addressed in Focal (20.04 LTS)
- Full CVE list elided - see USN for details
- 219 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
- Full CVE list elided - see USN for details
- 222 CVEs addressed in Jammy (22.04 LTS)
- Full CVE list elided - see USN for details
- 219 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
- Full CVE list elided - see USN for details
- 429 CVEs addressed in Jammy (22.04 LTS)
- Full CVE list elided - see USN for details
- 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS)
- 3 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS)
- 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS)
- 1 CVEs addressed in Xenial ESM (16.04 ESM)
- 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS)
- 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS)
- 2 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS)
- 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS)
- 5 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS)
- 9 CVEs addressed in Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Noble (24.04 LTS)
- 1 CVEs addressed in Jammy (22.04 LTS), Noble (24.04 LTS)
- 1 CVEs addressed in Focal (20.04 LTS)
- 6 CVEs addressed in Trusty ESM (14.04 ESM)
- https://events.linuxfoundation.org/linux-security-summit-europe/program/schedule/
- Sep 16-17 - Vienna, Austria
- John Johansen and Maxime Bélair from AppArmor team presented “Restricting Unprivileged User Namespaces in Ubuntu”
- Other talks
- Deep-dive into xz-utils supply chain attack
- Internals of the SLUB memory allocator for exploit developers
- Landlock update - including details of new IOCTL restrictions etc
- systemd and TPM2 update
- https://discourse.ubuntu.com/t/ubuntu-desktop-s-24-10-dev-cycle-part-5-introducing-permissions-prompting/47963
- Ubuntu Security Center with snapd-based AppArmor home file access prompting preview in episode 236
- Even works for command-line applications etc - not just graphical
- Covers future developments as well:
- Better default response suggestions based on user feedback.
- Shell integration of the prompting pop-ups (eg full screen takeovers)
- Improved rule management summaries and better messaging of overlapping or redundant prompts.
- Expansion of the prompting system to cover additional snap interfaces such as camera and microphone access.
- Smarter client side analysis of prompts, recommending additional options if multiple similar prompts are detected.
- https://discourse.ubuntu.com/t/version-2-1-of-intel-tdx-on-ubuntu-24-04-lts-released/47918/1
- Confidential computing - using TDX to run VMs in confidential mode - runs workloads (VMs) in hardware-backed isolated execution environments (Trust Domains). VM memory isolation via encryption in hardware so can’t be accessed by the hypervisor, remote attestation etc (Confidential Computing with Ijlal Loutfi and Karen Horovitz from Episode 230)
- https://discourse.ubuntu.com/t/intel-tdx-1-0-technology-preview-available-on-ubuntu-23-10/40698
- Scripting to setup the required elements to use TDX on Ubuntu 24.04 host and
then setup guest VMs to run in confidential mode
- Install server image, run scripts, enable TDX in BIOS, create VM images etc
- Can also configure remote attestation of VM too
- See full changes at https://github.com/canonical/tdx/releases/tag/2.1
- https://discourse.ubuntu.com/t/jammy-jellyfish-point-release-changes/29835/8
- Only covers changes in main and restricted, doesn’t list security updates either
- https://discourse.ubuntu.com/t/jammy-jellyfish-release-notes/24668
- Upcoming AppArmor Security update for CVE-2016-1585 from Episode 226
- https://discourse.ubuntu.com/t/upcoming-apparmor-security-update-for-cve-2016-1585/44268/3
- Now published to -updates pocket for 20.04 LTS and 22.04 LTS
- Will be published to -security pocket next week
English
United States
IN THIS EPISODE
TRANSCRIPT 🔗
Are you the producer of this podcast?
Add a podcast transcript
Need Audio-to-Text?
Transcribe with Listen411 in Just 60 Seconds
SEARCH PAST EPISODES
Search past episodes of Ubuntu Security Podcast.
OTHER EPISODES IN THIS PODCAST
Overview
A recent Microsoft Windows update breaks Linux dual-boot - or does it? This week
we look into reports of the recent Windows patch-Tuesday update breaking
dual-boot, including a deep-dive into the technical details of Secure Boot,
SBAT, grub, shim and more, plus we look at a vulnerability …
Overview
This week we take a deep dive behind-the-scenes look into how the team handled a
recent report from Snyk’s Security Lab of a local privilege escalation
vulnerability in wpa_supplicant plus we cover security updates in Prometheus
Alertmanager, OpenSSL, Exim, snapd, Gross, curl and mo…
Overview
This week we take a look at the recent Crowdstrike outage and what we can learn
from it compared to the testing and release process for security updates in
Ubuntu, plus we cover details of vulnerabilities in poppler, phpCAS, EDK II,
Python, OpenJDK and one package with over 300 CVE fixes …
Overview
A look into CISA’s Known Exploited Vulnerability Catalogue is on our minds this
week, plus we look at vulnerability updates for gdb, Ansible, CUPS, libheif,
Roundcube, the Linux kernel and more.
This week in Ubuntu Security Updates
175 unique CVEs addressed
[USN-6842-1] gdb vulne…
Overview
This week we deep-dive into one of the best vulnerabilities we’ve seen in a long
time regreSSHion - an unauthenticated, remote, root code-execution vulnerability
in OpenSSH. Plus we cover updates for Plasma Workspace, Ruby, Netplan,
FontForge, OpenVPN and a whole lot more.
This wee…
Disclaimer: The podcast and artwork embedded on this page are from Ubuntu Security Team, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
EDIT
Thank you for helping to keep the podcast database up to date.