OverviewAfter the announcement of Ubuntu Pro GA last week, we take the time to dispelsome myths around all things Ubuntu Pro, esm-apps and apt etc, plus Camila sitsdown with Mark and David to discuss the backstory of Editorconfig CVE-2023-0341and we also have a brief summary of the security updates from the past week.
Ubuntu Pro, esm-apps and apt confusions [00:40]* https://www.theregister.com/2022/10/13/canonical_ubuntu_ad/
+ talks in general about Ubuntu Pro notices in apt but doesn’t cover anydetails
https://www.omgubuntu.co.uk/2022/10/ubuntu-pro-terminal-ad
https://news.ycombinator.com/item?id=33260896
almost no engagement on hacker news
The following security updates require Ubuntu Pro with 'esm-apps' enabled: python2.7-minimal python2.7 libpython2.7-minimal libpython2.7-stdlibLearn more about Ubuntu Pro at https://ubuntu.com/pro
* There appears to be a few main issues:
1. Users don’t like what appears to be an advertisement in the apt output
2. Some updates now appear to be behind a “paywall”
3. Whilst they are free for personal use, to get access to them you need toregister an account on Ubuntu One etc and this requires providing varioushigh-level personal details (Name, Email etc)
So let’s take some time to look into these issues:
pro config set apt_news Falseso there is nothing to pay here - likely most folks that find thisobjectionable are personal users and so are entitled to the freesubscription
esm-apps part of this message indicates thatthese updates are for packages in the Universe component of the Ubuntuarchive - previously this has only ever been community supported - andso the Ubuntu Security team would only ever provide security updates onrare occasions OR if a member of the community came along and providedan update in the form of a debdiff which could be sponsored by someonefrom the Ubuntu Security teamThe inside story of Editorconfig CVE-2023-0341 [09:05]* Interview by Camila Camargo de Matos with David Fernandez Gonzalez and MarkEsler about the discovery and investigation of CVE-2023-0341 in Editorconfig([USN-5842-1] EditorConfig Core C vulnerability from Episode 186) * Keynote: Improving FOSS Security - Mark Esler | UbuCon Asia 2022 * https://litios.github.io/2023/01/14/CVE-2023-0341.html
This week in Ubuntu Security Updates [25:19]64 unique CVEs addressed
[USN-5849-1] Heimdal vulnerabilities* 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS) + CVE-2022-45142
[USN-5835-4] Cinder vulnerability* 1 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS) + CVE-2022-47951
[USN-5835-5] Nova vulnerability* 1 CVEs addressed in Bionic (18.04 LTS) + CVE-2022-47951
[USN-5852-1] OpenStack Swift vulnerability* 1 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Kinetic (22.10) + CVE-2022-47950
[USN-5850-1] Linux kernel vulnerabilities* 5 CVEs addressed in Kinetic (22.10) + CVE-2023-0590 + CVE-2022-42895 + CVE-2022-3640 + CVE-2022-3628 + CVE-2022-3619
[USN-5854-1] Linux kernel vulnerabilities* 11 CVEs addressed in Bionic (18.04 LTS) + CVE-2022-43750 + CVE-2022-41850 + CVE-2022-41849 + CVE-2022-39842 + CVE-2022-3649 + CVE-2022-3646 + CVE-2022-29901 + CVE-2022-29900 + CVE-2022-2663 + CVE-2022-26373 + CVE-2022-20369
[USN-5855-1] ImageMagick vulnerabilities* 2 CVEs addressed in Bionic (18.04 LTS) + CVE-2022-44268 + CVE-2022-44267
[USN-5856-1] Linux kernel (OEM) vulnerabilities* 3 CVEs addressed in Jammy (22.04 LTS) + CVE-2022-3424 + CVE-2022-1048 + CVE-2023-0179
[USN-5857-1] Linux kernel (OEM) vulnerability* 1 CVEs addressed in Jammy (22.04 LTS) + CVE-2023-0179
[USN-5858-1] Linux kernel (OEM) vulnerabilities* 4 CVEs addressed in Jammy (22.04 LTS) + CVE-2022-45934 + CVE-2022-42895 + CVE-2022-3545 + CVE-2023-0179
[USN-5859-1] Linux kernel (OEM) vulnerabilities* 4 CVEs addressed in Focal (20.04 LTS) + CVE-2022-42895 + CVE-2022-4139 + CVE-2022-3545 + CVE-2023-0179
[USN-5848-1] less vulnerability* 1 CVEs addressed in Jammy (22.04 LTS), Kinetic (22.10) + CVE-2022-46663
[USN-5860-1] Linux kernel (GKE) vulnerabilities* 14 CVEs addressed in Jammy (22.04 LTS) + CVE-2023-0590 + CVE-2022-47940 + CVE-2022-45934 + CVE-2022-42895 + CVE-2022-41850 + CVE-2022-41849 + CVE-2022-3643 + CVE-2022-3640 + CVE-2022-3628 + CVE-2022-3623 + CVE-2022-3619 + CVE-2022-3543 + CVE-2022-42896 + CVE-2022-4378
[USN-5861-1] Linux kernel (Dell300x) vulnerabilities* 15 CVEs addressed in Bionic (18.04 LTS) + CVE-2022-45934 + CVE-2022-43750 + CVE-2022-41850 + CVE-2022-41849 + CVE-2022-39842 + CVE-2022-3649 + CVE-2022-3646 + CVE-2022-3643 + CVE-2022-29901 + CVE-2022-29900 + CVE-2022-2663 + CVE-2022-26373 + CVE-2022-20369 + CVE-2022-42896 + CVE-2022-43945
[USN-5862-1] Linux kernel (Qualcomm Snapdragon) vulnerabilities* 11 CVEs addressed in Bionic (18.04 LTS) + CVE-2022-43750 + CVE-2022-41850 + CVE-2022-41849 + CVE-2022-39842 + CVE-2022-3649 + CVE-2022-3646 + CVE-2022-29901 + CVE-2022-29900 + CVE-2022-2663 + CVE-2022-26373 + CVE-2022-20369
[USN-5863-1] Linux kernel (Azure) vulnerabilities* 4 CVEs addressed in Xenial ESM (16.04 ESM) + CVE-2022-45934 + CVE-2022-3643 + CVE-2022-42896 + CVE-2022-43945
[USN-5865-1] Linux kernel (Azure) vulnerabilities* 11 CVEs addressed in Bionic (18.04 LTS) + CVE-2022-43750 + CVE-2022-41850 + CVE-2022-41849 + CVE-2022-39842 + CVE-2022-3649 + CVE-2022-3646 + CVE-2022-29901 + CVE-2022-29900 + CVE-2022-2663 + CVE-2022-26373 + CVE-2022-20369
[USN-5866-1] Nova vulnerabilities* 5 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS) + CVE-2022-37394 + CVE-2021-3654 + CVE-2020-17376 + CVE-2017-18191 + CVE-2015-9543
[USN-5867-1] WebKitGTK vulnerabilities* 3 CVEs addressed in Focal (20.04 LTS), Jammy (22.04 LTS), Kinetic (22.10) + CVE-2023-23518 + CVE-2023-23517 + CVE-2022-42826
[USN-5864-1] Fig2dev vulnerabilities* 14 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS) + CVE-2021-32280 + CVE-2021-3561 + CVE-2020-21676 + CVE-2020-21675 + CVE-2020-21535 + CVE-2020-21534 + CVE-2020-21533 + CVE-2020-21532 + CVE-2020-21531 + CVE-2020-21530 + CVE-2020-21529 + CVE-2019-19797 + CVE-2019-19555 + CVE-2019-14275
[LSN-0091-1] Linux kernel vulnerability* 2 CVEs addressed in + CVE-2022-42719 + CVE-2022-41222
[USN-5869-1] HAProxy vulnerability* 2 CVEs addressed in Bionic (18.04 LTS), Focal (20.04 LTS), Jammy (22.04 LTS), Kinetic (22.10) + CVE-2023-25725 + CVE-2023-24580
[USN-5871-1] Git vulnerabilities* 2 CVEs addressed in Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Jammy (22.04 LTS), Kinetic (22.10) + CVE-2023-23946 + CVE-2023-22490
[USN-5870-1] apr-util vulnerability* 1 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic (18.04 LTS), Focal (20.04 LTS), Jammy (22.04 LTS), Kinetic (22.10) + CVE-2022-25147
Get in contact* security@ubuntu.com * #ubuntu-security on the Libera.Chat IRC network * ubuntu-hardened mailing list * Security section on discourse.ubuntu.com * @ubuntusecurity@fosstodon.org, @ubuntu_sec on twitter