========================================================================== Ubuntu Security Notice USN-5395-2 May 04, 2022 networkd-dispatcher regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 21.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: USN-5395-1 introduced a regression in networkd-dispatcher. Software Description: - networkd-dispatcher: Dispatcher service for systemd-networkd connection status changes Details: USN-5395-1 fixed vulnerabilities in networkd-dispatcher. Unfortunately that update was incomplete and could introduce a regression. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that networkd-dispatcher incorrectly handled internal scripts. A local attacker could possibly use this issue to cause a race condition, escalate privileges and execute arbitrary code. (CVE-2022-29799, CVE-2022-29800) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: networkd-dispatcher 2.1-2ubuntu0.22.04.2 Ubuntu 21.10: networkd-dispatcher 2.1-2ubuntu0.21.10.2 Ubuntu 20.04 LTS: networkd-dispatcher 2.1-2~ubuntu20.04.3 Ubuntu 18.04 LTS: networkd-dispatcher 1.7-0ubuntu3.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5395-2 https://ubuntu.com/security/notices/USN-5395-1 https://launchpad.net/bugs/1971550 Package Information: https://launchpad.net/ubuntu/+source/networkd-dispatcher/2.1-2ubuntu0.22.04.2 https://launchpad.net/ubuntu/+source/networkd-dispatcher/2.1-2ubuntu0.21.10.2 https://launchpad.net/ubuntu/+source/networkd-dispatcher/2.1-2~ubuntu20.04.3 https://launchpad.net/ubuntu/+source/networkd-dispatcher/1.7-0ubuntu3.5