Release Info

Advisory: CLSA-2024:1719567415

OS: Ubuntu 16.04 ELS

Public date: 2024-06-28 05:36:57

Project: linux-hwe

Version: 4.15.0-231.242~16.04.1

Errata link: https://errata.tuxcare.com/els_os/ubuntu16.04els/CLSA-2024-1719567415.html

Changelog

[ Ubuntu: 4.15.0-231.242 ] * CVE-url: https://ubuntu.com/security/CVE-2024-2201 - x86/cpufeatures: Add new word for scattered features - x86/cpufeatures: Add CPUID_LNX_5 to track recently added Linux-defined word - x86/bugs: Change commas to semicolons in 'spectre_v2' sysfs file - x86/bhi: Add support for clearing branch history at syscall entry - x86/bhi: Define SPEC_CTRL_BHI_DIS_S - x86/bhi: Enumerate Branch History Injection (BHI) bug - x86/bhi: Add BHI mitigation knob - x86/bhi: Mitigate KVM by default - x86/bugs: Fix BHI documentation - x86/bugs: Cache the value of MSR_IA32_ARCH_CAPABILITIES - x86/bugs: Rename various 'ia32_cap' variables to 'x86_arch_cap_msr' - x86/bugs: Fix BHI handling of RRSBA - x86/bugs: Clarify that syscall hardening isn't a BHI mitigation - x86/bugs: Fix BHI retpoline check * CVE-url: https://ubuntu.com/security/CVE-2024-26922 - drm/amdgpu: validate the parameters of bo mapping operations more clearly * CVE-url: https://ubuntu.com/security/CVE-2024-26642 - netfilter: nf_tables: disallow anonymous set with timeout flag * CVE-url: https://ubuntu.com/security/CVE-2021-33631 - ext4: fix kernel BUG in 'ext4_write_inline_data_end()' * CVE-url: https://ubuntu.com/security/CVE-2024-36902 - ipv6: fib6_rules: avoid possible NULL dereference in fib6_rule_action() * CVE-url: https://ubuntu.com/security/CVE-2024-36901 - ipv6: prevent NULL dereference in ip6_output() * Miscellaneous upstream changes - media: xc4000: Fix atomicity violation in xc4000_get_frequency - [Config] updateconfigs for CONFIG_BHI_{AUTO|OFF|ON}

Update

Update command: apt-get update apt-get --only-upgrade install linux-hwe*

Packages list

linux-buildinfo-4.15.0-231-tuxcare.els29-generic_4.15.0-231.242~16.04.1_amd64.deb linux-buildinfo-4.15.0-231-tuxcare.els29-lowlatency_4.15.0-231.242~16.04.1_amd64.deb linux-cloud-tools-4.15.0-231-tuxcare.els29-generic_4.15.0-231.242~16.04.1_amd64.deb linux-cloud-tools-4.15.0-231-tuxcare.els29-lowlatency_4.15.0-231.242~16.04.1_amd64.deb linux-headers-4.15.0-231-tuxcare.els29_4.15.0-231.242~16.04.1_all.deb linux-headers-4.15.0-231-tuxcare.els29-generic_4.15.0-231.242~16.04.1_amd64.deb linux-headers-4.15.0-231-tuxcare.els29-lowlatency_4.15.0-231.242~16.04.1_amd64.deb linux-hwe-cloud-tools-4.15.0-231-tuxcare.els29_4.15.0-231.242~16.04.1_amd64.deb linux-hwe-tools-4.15.0-231-tuxcare.els29_4.15.0-231.242~16.04.1_amd64.deb linux-image-unsigned-4.15.0-231-tuxcare.els29-generic_4.15.0-231.242~16.04.1_amd64.deb linux-image-unsigned-4.15.0-231-tuxcare.els29-lowlatency_4.15.0-231.242~16.04.1_amd64.deb linux-modules-4.15.0-231-tuxcare.els29-generic_4.15.0-231.242~16.04.1_amd64.deb linux-modules-4.15.0-231-tuxcare.els29-lowlatency_4.15.0-231.242~16.04.1_amd64.deb linux-modules-extra-4.15.0-231-tuxcare.els29-generic_4.15.0-231.242~16.04.1_amd64.deb linux-source-4.15.0_4.15.0-231.242~16.04.1_all.deb linux-tools-4.15.0-231-tuxcare.els29-generic_4.15.0-231.242~16.04.1_amd64.deb linux-tools-4.15.0-231-tuxcare.els29-lowlatency_4.15.0-231.242~16.04.1_amd64.deb

CVEs

CVE-2024-26642
CVE-2021-47545
CVE-2021-33631
CVE-2024-2201