Ubuntu是一個(gè)以桌面應(yīng)用為主的Linux操作系統(tǒng)。它是一個(gè)開放源代碼的自由軟件,提供了一個(gè)健壯、功能豐富的計(jì)算環(huán)境,既適合家庭使用又適用于商業(yè)環(huán)境。Ubuntu為全球數(shù)百個(gè)公司提供商業(yè)支持。
3月31日,Ubuntu發(fā)布了安全更新,修復(fù)了Linux內(nèi)核發(fā)現(xiàn)的執(zhí)行任意代碼漏洞。以下是漏洞詳情:
漏洞詳情
來源:https://ubuntu.com/security/notices/LSN-0085-1
1.CVE-2022-1055 嚴(yán)重程度:高
Linux內(nèi)核中的網(wǎng)絡(luò)流量控制實(shí)現(xiàn)包含一個(gè)use-after-free漏洞。本地攻擊者可以使用它來導(dǎo)致拒絕服務(wù)(系統(tǒng)崩潰)或可能執(zhí)行任意代碼
2.CVE-2022-27666 嚴(yán)重程度:中
Linux 內(nèi)核中的 IPsec 實(shí)現(xiàn)在執(zhí)行 ESP 轉(zhuǎn)換時(shí)沒有正確分配足夠的內(nèi)存,導(dǎo)致基于堆的緩沖區(qū)溢出。本地攻擊者可以使用它來導(dǎo)致拒絕服務(wù)(系統(tǒng)崩潰)或可能執(zhí)行任意代碼。
受影響產(chǎn)品和版本
上述漏洞影響Ubuntu 21.10, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS
解決方案
可以通過將系統(tǒng)更新到以下軟件包版本來糾正該問題:
Ubuntu 21.10
linux-image-5.13.0-1021-aws - 5.13.0-1021.23
linux-image-5.13.0-1023-gcp - 5.13.0-1023.28
linux-image-virtual - 5.13.0.39.48
linux-image-generic-64k - 5.13.0.39.48
linux-image-generic - 5.13.0.39.48
linux-image-aws - 5.13.0.1021.22
linux-image-5.13.0-39-generic-lpae - 5.13.0-39.44
linux-image-5.13.0-39-generic - 5.13.0-39.44
linux-image-5.13.0-1020-kvm - 5.13.0-1020.21
linux-image-5.13.0-39-generic-64k - 5.13.0-39.44
linux-image-5.13.0-39-lowlatency - 5.13.0-39.44
linux-image-oem-20.04 - 5.13.0.39.48
linux-image-gke - 5.13.0.1023.21
linux-image-gcp - 5.13.0.1023.21
linux-image-oracle - 5.13.0.1025.25
linux-image-5.13.0-1025-oracle - 5.13.0-1025.30
linux-image-kvm - 5.13.0.1020.20
linux-image-generic-lpae - 5.13.0.39.48
linux-image-lowlatency - 5.13.0.39.48
Ubuntu 20.04
linux-image-virtual - 5.4.0.107.111
linux-image-virtual-hwe-20.04 - 5.13.0.39.44~20.04.24
linux-image-generic - 5.4.0.107.111
linux-image-oem - 5.4.0.107.111
linux-image-lowlatency-hwe-20.04 - 5.13.0.39.44~20.04.24
linux-image-5.4.0-107-generic-lpae - 5.4.0-107.121
linux-image-5.13.0-39-generic-lpae - 5.13.0-39.44~20.04.1
linux-image-5.4.0-107-lowlatency - 5.4.0-107.121
linux-image-5.13.0-39-generic - 5.13.0-39.44~20.04.1
linux-image-5.4.0-1061-kvm - 5.4.0-1061.64
linux-image-azure-lts-20.04 - 5.4.0.1074.72
linux-image-5.13.0-39-generic-64k - 5.13.0-39.44~20.04.1
linux-image-5.13.0-39-lowlatency - 5.13.0-39.44~20.04.1
linux-image-generic-hwe-20.04 - 5.13.0.39.44~20.04.24
linux-image-5.4.0-1069-oracle - 5.4.0-1069.75
linux-image-aws-lts-20.04 - 5.4.0.1071.73
linux-image-5.4.0-1074-azure - 5.4.0-1074.77
linux-image-5.4.0-107-generic - 5.4.0-107.121
linux-image-oem-osp1 - 5.4.0.107.111
linux-image-generic-64k-hwe-20.04 - 5.13.0.39.44~20.04.24
linux-image-oracle-lts-20.04 - 5.4.0.1069.69
linux-image-generic-lpae-hwe-20.04 - 5.13.0.39.44~20.04.24
linux-image-5.4.0-1071-aws - 5.4.0-1071.76
linux-image-kvm - 5.4.0.1061.60
linux-image-generic-lpae - 5.4.0.107.111
linux-image-lowlatency - 5.4.0.107.111
Ubuntu 18.04
linux-image-generic-hwe-18.04 - 5.4.0.107.121~18.04.92
linux-image-snapdragon-hwe-18.04 - 5.4.0.107.121~18.04.92
linux-image-oem - 5.4.0.107.121~18.04.92
linux-image-5.4.0-107-generic-lpae - 5.4.0-107.121~18.04.1
linux-image-generic-lpae-hwe-18.04 - 5.4.0.107.121~18.04.92
linux-image-5.4.0-107-lowlatency - 5.4.0-107.121~18.04.1
linux-image-5.4.0-1069-oracle - 5.4.0-1069.75~18.04.1
linux-image-virtual-hwe-18.04 - 5.4.0.107.121~18.04.92
linux-image-5.4.0-107-generic - 5.4.0-107.121~18.04.1
linux-image-oem-osp1 - 5.4.0.107.121~18.04.92
linux-image-oracle - 5.4.0.1069.75~18.04.48
linux-image-lowlatency-hwe-18.04 - 5.4.0.107.121~18.04.92
查看更多漏洞信息 以及升級請?jiān)L問官網(wǎng):
https://ubuntu.com/security/cve
本文鏈接:http://www.www897cc.com/showinfo-119-2250-0.html云安全日報(bào)220331:Ubuntu Linux內(nèi)核發(fā)現(xiàn)執(zhí)行任意代碼漏洞,需要盡快升級
聲明:本網(wǎng)頁內(nèi)容旨在傳播知識,若有侵權(quán)等問題請及時(shí)與本網(wǎng)聯(lián)系,我們將在第一時(shí)間刪除處理。郵件:2376512515@qq.com