Headlines |
2023-07-27 |
Ubuntu patches custom kernel bug |
 |
An unusual set of circumstances has given rise to a rare occurrence: a situation where one Linux distribution contains a kernel vulnerability while others do not. The problem arose after Ubuntu introduced custom changes to its OverlayFS kernel module. This change was fine and didn't introduce any problems, until the mainline kernel made related changes which were also fine when used with the vanilla kernel. However, mixing the two sets of changes (those from Ubuntu and those from the vanilla kernel) resulted into two security vulnerabilities. "Ubuntu, as one of the distributions using OverlayFS, had implemented custom changes to its OverlayFS module in 2018, which were generally safe. However, in 2019 and 2022, the Linux kernel project made its own modifications to the module, which conflicted with Ubuntu's changes. The widespread distribution adopted the code containing these changes recently, and the conflicts caused the introduction of the two flaws. Unfortunately, the risk of exploitation is imminent, as PoCs for the two flaws have been publicly available for a long time." People running the Ubuntu distribution (or related, downstream distributions and spins) are advised to update their kernel. Bleeping Computer has the details. |
More headlines from this project
Back to News
|
|
TUXEDO |

TUXEDO Computers - Linux Hardware in a tailor made suite Choose from a wide range of laptops and PCs in various sizes and shapes at TUXEDOComputers.com. Every machine comes pre-installed and ready-to-run with Linux. Full 24 months of warranty and lifetime support included!
Learn more about our full service package and all benefits from buying at TUXEDO.
|
Star Labs |

Star Labs - Laptops built for Linux.
View our range including the highly anticipated StarFighter. Available with coreboot open-source firmware and a choice of Ubuntu, elementary, Manjaro and more. Visit Star Labs for information, to buy and get support.
|
Shells.com |

Your own personal Linux computer in the cloud, available on any device. Supported operating systems include Android, Debian, Fedora, KDE neon, Kubuntu, Linux Mint, Manjaro and Ubuntu, ready in minutes.
Starting at US$4.95 per month, 7-day money-back guarantee
|
|