Release Info

Advisory: CLSA-2023:1688072342

OS: Ubuntu 16.04 ELS

Public date: 2023-06-29 16:59:04

Project: linux

Version: 4.4.0-241.275

Errata link: https://errata.tuxcare.com/els_os/ubuntu16.04els/CLSA-2023-1688072342.html

Changelog

* CVE-2023-32233 // CVE-url: https://ubuntu.com/security/CVE-2023-32233 - netfilter: nf_tables: add nft_set_is_anonymous() helper - netfilter: nf_tables: split set destruction in deactivate and destroy phase - netfilter: nf_tables: unbind set in rule from commit path - netfilter: nf_tables: fix set double-free in abort path - netfilter: nf_tables: bogus EBUSY when deleting set after flush - netfilter: nf_tables: use-after-free in failing rule with bound set - netfilter: nf_tables: deactivate anonymous set from preparation phase * Bionic update: upstream stable patchset 2018-12-12 (LP: #1808185) // CVE- url: https://ubuntu.com/security/CVE-2023-32233 - netfilter: nf_tables: bogus EBUSY in chain deletions * CVE-url: https://ubuntu.com/security/CVE-2023-32233 - netfilter: nf_tables: release objects on netns destruction - netfilter: nf_tables: destroy basechain and rules on netdevice removal - netfilter: nft_hash: support deletion of inactive elements - netfilter: nf_tables: remove check against removal of inactive objects - netfilter: nfnetlink: pass down netns pointer to call() and call_rcu() - netfilter: nf_tables: introduce nft_setelem_parse_flags() helper - netfilter: nft_rbtree: introduce nft_rbtree_interval_end() helper - netfilter: nft_rbtree: allow adjacent intervals with dynamic updates - netfilter: nf_tables: parse element flags from nft_del_setelem() - netfilter: nf_tables: reject loops from set element jump to chain - netfilter: nf_tables: fix wrong destroy anonymous sets if binding fails - netfilter: nf_tables: add generic macros to check for generation mask - netfilter: nf_tables: add generation mask to tables - netfilter: nf_tables: add generation mask to chains - netfilter: nf_tables: add generation mask to sets - netfilter: nf_tables: get rid of NFT_BASECHAIN_DISABLED - netlink: add NLM_F_NONREC flag for deletion requests - netfilter: nf_tables: add support for inverted logic in nft_lookup - netfilter: nf_tables: get rid of possible_net_t from set and basechain - netfilter: nf_tables: simplify the basic expressions' init routine - netfilter: nf_tables: fix *leak* when expr clone fail - netfilter: nf_tables: missing sanitization in data from userspace - netfilter: nf_tables: revisit chain/object refcounting from elements * CVE-2023-1380 // CVE-url: https://ubuntu.com/security/CVE-2023-1380 - wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() * CVE-url: https://ubuntu.com/security/CVE-2023-2124 - xfs: verify buffer contents when we skip log replay * Bionic update: upstream stable patchset 2023-04-05 (LP: #2015399) // CVE- url: https://ubuntu.com/security/CVE-2023-32269 - netrom: Fix use-after-free caused by accept on already connected socket * Bionic update: upstream stable patchset 2023-04-05 (LP: #2015399) // CVE- url: https://ubuntu.com/security/CVE-2023-2162 - scsi: iscsi_tcp: Fix UAF during login when accessing the shost ipaddress

Update

Update command: apt-get update apt-get --only-upgrade install linux*

Packages list

linux-buildinfo-4.4.0-241-tuxcare.els12-generic_4.4.0-241.275_amd64.deb linux-buildinfo-4.4.0-241-tuxcare.els12-lowlatency_4.4.0-241.275_amd64.deb linux-cloud-tools-4.4.0-241-tuxcare.els12_4.4.0-241.275_amd64.deb linux-cloud-tools-4.4.0-241-tuxcare.els12-generic_4.4.0-241.275_amd64.deb linux-cloud-tools-4.4.0-241-tuxcare.els12-lowlatency_4.4.0-241.275_amd64.deb linux-cloud-tools-common_4.4.0-241.275_all.deb linux-doc_4.4.0-241.275_all.deb linux-headers-4.4.0-241-tuxcare.els12_4.4.0-241.275_all.deb linux-headers-4.4.0-241-tuxcare.els12-generic_4.4.0-241.275_amd64.deb linux-headers-4.4.0-241-tuxcare.els12-lowlatency_4.4.0-241.275_amd64.deb linux-image-unsigned-4.4.0-241-tuxcare.els12-generic_4.4.0-241.275_amd64.deb linux-image-unsigned-4.4.0-241-tuxcare.els12-lowlatency_4.4.0-241.275_amd64.deb linux-libc-dev_4.4.0-241.275_amd64.deb linux-modules-4.4.0-241-tuxcare.els12-generic_4.4.0-241.275_amd64.deb linux-modules-4.4.0-241-tuxcare.els12-lowlatency_4.4.0-241.275_amd64.deb linux-modules-extra-4.4.0-241-tuxcare.els12-generic_4.4.0-241.275_amd64.deb linux-source-4.4.0_4.4.0-241.275_all.deb linux-tools-4.4.0-241-tuxcare.els12_4.4.0-241.275_amd64.deb linux-tools-4.4.0-241-tuxcare.els12-generic_4.4.0-241.275_amd64.deb linux-tools-4.4.0-241-tuxcare.els12-lowlatency_4.4.0-241.275_amd64.deb linux-tools-common_4.4.0-241.275_all.deb linux-tools-host_4.4.0-241.275_all.deb

CVEs

CVE-2023-1380
CVE-2023-2124
CVE-2023-32269
CVE-2023-2162
CVE-2023-32233