what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Kernel Live Patch Security Notice LSN-0064-1

Kernel Live Patch Security Notice LSN-0064-1
Posted Mar 19, 2020
Authored by Benjamin M. Romer

Paulo Bonzini discovered that the KVM hypervisor implementation in the Linux kernel could improperly let a nested (level 2) guest access the resources of a parent (level 1) guest in certain situations. An attacker could use this to expose sensitive information.

tags | advisory, kernel
systems | linux
advisories | CVE-2020-2732
SHA-256 | 013a0dfba70302c800eab63aa571da076d3bc4a87d14b9f7b138548d27333d78

Kernel Live Patch Security Notice LSN-0064-1

Change Mirror Download
==========================================================================
Kernel Live Patch Security Notice 0064-1
March 19, 2020

linux vulnerability
==========================================================================

A security issue affects these releases of Ubuntu:

| Series | Base kernel | Arch | flavors |
|------------------+--------------+----------+------------------|
| Ubuntu 18.04 LTS | 4.15.0 | amd64 | aws |
| Ubuntu 18.04 LTS | 4.15.0 | amd64 | generic |
| Ubuntu 18.04 LTS | 4.15.0 | amd64 | lowlatency |
| Ubuntu 18.04 LTS | 4.15.0 | amd64 | oem |
| Ubuntu 18.04 LTS | 5.0.0 | amd64 | azure |
| Ubuntu 18.04 LTS | 5.0.0 | amd64 | gcp |
| Ubuntu 14.04 LTS | 4.4.0 | amd64 | generic |
| Ubuntu 14.04 LTS | 4.4.0 | amd64 | lowlatency |
| Ubuntu 16.04 LTS | 4.4.0 | amd64 | aws |
| Ubuntu 16.04 LTS | 4.4.0 | amd64 | generic |
| Ubuntu 16.04 LTS | 4.4.0 | amd64 | lowlatency |
| Ubuntu 16.04 LTS | 4.15.0 | amd64 | azure |
| Ubuntu 16.04 LTS | 4.15.0 | amd64 | generic |
| Ubuntu 16.04 LTS | 4.15.0 | amd64 | lowlatency |

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

Paulo Bonzini discovered that the KVM hypervisor implementation in the
Linux kernel could improperly let a nested (level 2) guest access the
resources of a parent (level 1) guest in certain situations. An attacker
could use this to expose sensitive information. (CVE-2020-2732)

Update instructions:

The problem can be corrected by updating your livepatches to the following
versions:

| Kernel | Version | flavors |
|--------------------------+----------+--------------------------|
| 4.4.0-168.197 | 64.2 | generic, lowlatency |
| 4.4.0-168.197~14.04.1 | 64.2 | lowlatency, generic |
| 4.4.0-169.198 | 64.2 | generic, lowlatency |
| 4.4.0-169.198~14.04.1 | 64.2 | lowlatency, generic |
| 4.4.0-170.199 | 64.2 | lowlatency, generic |
| 4.4.0-170.199~14.04.1 | 64.2 | lowlatency, generic |
| 4.4.0-171.200 | 64.2 | lowlatency, generic |
| 4.4.0-171.200~14.04.1 | 64.2 | generic, lowlatency |
| 4.4.0-173.203 | 64.2 | generic, lowlatency |
| 4.4.0-173.203~14.04.1 | 64.2 | generic, lowlatency |
| 4.4.0-174.204 | 64.2 | lowlatency, generic |
| 4.4.0-1098.109 | 64.2 | aws |
| 4.4.0-1099.110 | 64.2 | aws |
| 4.4.0-1100.111 | 64.2 | aws |
| 4.4.0-1101.112 | 64.2 | aws |
| 4.4.0-1102.113 | 64.2 | aws |
| 4.15.0-69.78 | 64.2 | generic, lowlatency |
| 4.15.0-69.78~16.04.1 | 64.2 | lowlatency, generic |
| 4.15.0-70.79 | 64.2 | lowlatency, generic |
| 4.15.0-70.79~16.04.1 | 64.2 | generic, lowlatency |
| 4.15.0-72.81 | 64.2 | generic, lowlatency |
| 4.15.0-72.81~16.04.1 | 64.2 | generic, lowlatency |
| 4.15.0-74.83~16.04.1 | 64.2 | lowlatency, generic |
| 4.15.0-74.84 | 64.2 | generic, lowlatency |
| 4.15.0-76.86 | 64.2 | generic, lowlatency |
| 4.15.0-76.86~16.04.1 | 64.2 | lowlatency, generic |
| 4.15.0-88.88 | 64.2 | generic, lowlatency |
| 4.15.0-88.88~16.04.1 | 64.2 | lowlatency, generic |
| 4.15.0-1054.56 | 64.2 | aws |
| 4.15.0-1056.58 | 64.2 | aws |
| 4.15.0-1057.59 | 64.2 | aws |
| 4.15.0-1058.60 | 64.2 | aws |
| 4.15.0-1060.62 | 64.2 | aws |
| 4.15.0-1063.68 | 64.2 | azure |
| 4.15.0-1063.72 | 64.2 | oem |
| 4.15.0-1064.69 | 64.2 | azure |
| 4.15.0-1064.73 | 64.2 | oem |
| 4.15.0-1065.75 | 64.2 | oem |
| 4.15.0-1066.71 | 64.2 | azure |
| 4.15.0-1066.76 | 64.2 | oem |
| 4.15.0-1067.72 | 64.2 | azure |
| 4.15.0-1067.77 | 64.2 | oem |
| 4.15.0-1069.74 | 64.2 | azure |
| 4.15.0-1069.79 | 64.2 | oem |
| 4.15.0-1071.76 | 64.2 | azure |
| 4.15.0-1073.83 | 64.2 | oem |
| 5.0.0-1025.26~18.04.1 | 64.5 | gcp |
| 5.0.0-1025.27~18.04.1 | 64.4 | azure |
| 5.0.0-1027.29~18.04.1 | 64.4 | azure |
| 5.0.0-1028.29~18.04.1 | 64.5 | gcp |
| 5.0.0-1028.30~18.04.1 | 64.4 | azure |
| 5.0.0-1029.30~18.04.1 | 64.5 | gcp |
| 5.0.0-1029.31~18.04.1 | 64.4 | azure |

Support Information:

Kernels older than the levels listed below do not receive livepatch
updates. Please upgrade your kernel as soon as possible.

| Series | Version | Flavors |
|------------------+------------------+--------------------------|
| Ubuntu 18.04 LTS | 4.15.0-1054 | aws |
| Ubuntu 16.04 LTS | 4.4.0-1098 | aws |
| Ubuntu 18.04 LTS | 5.0.0-1025 | azure |
| Ubuntu 16.04 LTS | 4.15.0-1063 | azure |
| Ubuntu 18.04 LTS | 4.15.0-69 | generic lowlatency |
| Ubuntu 18.04 LTS | 5.0.0-1025 | gcp |
| Ubuntu 16.04 LTS | 4.15.0-69 | generic lowlatency |
| Ubuntu 14.04 LTS | 4.4.0-168 | generic lowlatency |
| Ubuntu 18.04 LTS | 4.15.0-1063 | oem |
| Ubuntu 16.04 LTS | 4.4.0-168 | generic lowlatency |

References:
CVE-2020-2732


--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close