Release Info

Advisory: CLSA-2025:1763989962

OS: Ubuntu 20.04 ELS

Public date: 2025-11-24 13:12:44.130478

Project: linux

Version: 5.4.0-223.243

Errata link: https://errata.tuxcare.com/els_os/ubuntu20.04els/CLSA-2025-1763989962.html

Changelog

* CVE-url: https://ubuntu.com/security/CVE-2025-38352 - posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() * CVE-url: https://ubuntu.com/security/CVE-2022-25265 - x86/elf: Add table to document READ_IMPLIES_EXEC - x86/elf: Split READ_IMPLIES_EXEC from executable PT_GNU_STACK - x86/elf: Disable automatic READ_IMPLIES_EXEC on 64-bit * CVE-url: https://ubuntu.com/security/CVE-2022-49170 - f2fs: fix to do sanity check on curseg->alloc_type * CVE-url: https://ubuntu.com/security/CVE-2021-47479 - staging: rtl8712: fix use-after-free in rtl8712_dl_fw * CVE-url: https://ubuntu.com/security/CVE-2022-49519 - ath10k: skip ath10k_halt during suspend for driver state RESTARTING * CVE-url: https://ubuntu.com/security/CVE-2024-46713 - perf/aux: Fix AUX buffer serialization * CVE-url: https://ubuntu.com/security/CVE-2024-36914 - drm/amd/display: Skip on writeback when it's not applicable * CVE-url: https://ubuntu.com/security/CVE-2024-36880 - Bluetooth: qca: add missing firmware sanity checks * Miscellaneous upstream changes - net: openvswitch: fix nested key length validation in the set() action - isofs: Prevent the use of too small fid - ext4: ignore xattrs past end - net: ppp: Add bound checking for skb data on ppp_sync_txmung - media: venus: hfi: add check to handle incorrect queue size - media: venus: hfi_parser: add check to avoid out of bound access - sctp: detect and prevent references to a freed transport in sendmsg - ext4: improve xattr consistency checking and error reporting - ext4: introduce ITAIL helper - ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all() - ibmvnic: create send_control_ip_offload - ibmvnic: Use strscpy() instead of strncpy() - ibmvnic: Use kernel helpers for hex dumps - wifi: at76c50x: fix use after free access in at76_disconnect - wifi: cfg80211: fix use-after-free in cmp_bss()

Update

Update command: apt-get update apt-get --only-upgrade install linux*

Packages list

linux-buildinfo-5.4.0-223-tuxcare.els5-generic_5.4.0-223.243_amd64.deb linux-buildinfo-5.4.0-223-tuxcare.els5-lowlatency_5.4.0-223.243_amd64.deb linux-cloud-tools-5.4.0-223-tuxcare.els5_5.4.0-223.243_amd64.deb linux-cloud-tools-5.4.0-223-tuxcare.els5-generic_5.4.0-223.243_amd64.deb linux-cloud-tools-5.4.0-223-tuxcare.els5-lowlatency_5.4.0-223.243_amd64.deb linux-cloud-tools-common_5.4.0-223.243_all.deb linux-doc_5.4.0-223.243_all.deb linux-headers-5.4.0-223-tuxcare.els5_5.4.0-223.243_all.deb linux-headers-5.4.0-223-tuxcare.els5-generic_5.4.0-223.243_amd64.deb linux-headers-5.4.0-223-tuxcare.els5-lowlatency_5.4.0-223.243_amd64.deb linux-image-unsigned-5.4.0-223-tuxcare.els5-generic_5.4.0-223.243_amd64.deb linux-image-unsigned-5.4.0-223-tuxcare.els5-lowlatency_5.4.0-223.243_amd64.deb linux-libc-dev_5.4.0-223.243_amd64.deb linux-modules-5.4.0-223-tuxcare.els5-generic_5.4.0-223.243_amd64.deb linux-modules-5.4.0-223-tuxcare.els5-lowlatency_5.4.0-223.243_amd64.deb linux-modules-extra-5.4.0-223-tuxcare.els5-generic_5.4.0-223.243_amd64.deb linux-source-5.4.0_5.4.0-223.243_all.deb linux-tools-5.4.0-223-tuxcare.els5_5.4.0-223.243_amd64.deb linux-tools-5.4.0-223-tuxcare.els5-generic_5.4.0-223.243_amd64.deb linux-tools-5.4.0-223-tuxcare.els5-lowlatency_5.4.0-223.243_amd64.deb linux-tools-common_5.4.0-223.243_all.deb linux-tools-host_5.4.0-223.243_all.deb

CVEs

CVE-2025-38352
CVE-2024-36880
CVE-2022-25265
CVE-2022-49519
CVE-2022-49170
CVE-2024-46713
CVE-2024-36914
CVE-2021-47479