Security Team Weekly Summary: November 9, 2017
Canonical
on 9 November 2017
The Security Team weekly reports are intended to be very short summaries of the Security Team’s weekly activities.
If you would like to reach the Security Team, you can find us at the #ubuntu-hardened channel on FreeNode. Alternatively, you can mail the Ubuntu Hardened mailing list at: [email protected]
During the last week, the Ubuntu Security team:
- Triaged 201 public security vulnerability reports, retaining the 45 that applied to Ubuntu.
- Published 13 Ubuntu Security Notices which fixed 33 security issues (CVEs) across 16 supported packages.
Ubuntu Security Notices
Bug Triage
Mainline Inclusion Requests
-
spice-vdagent underway (LP: #1200296)
-
pcp (pcp-3.12.2) completed (LP: #1700827)
-
MIR backlog: https://bugs.launchpad.net/~ubuntu-security/+assignedbugs?field.searchtext=%5BMIR%5D
Updates to Community Supported Packages
-
Lucas Kocia (lkocia) provided a debdiff for xenial for firewalld (LP: #1617617)
-
Jeremy Bicha (jbicha) provided a debdiff for zesty for gdm3 (LP: #1729354)
Development
- fixed last of snappy-debug updates (handle core vs classic policy), test, push to stable
- reviews
- PR 4105 – i386/socket/trusty testsuite fix
- review apparmor.d man page patch from jj
- PR 4109 – fix parsing of mountinfo fields
- PRs 4123 and 4124 – fix bug in ofono interface
- PR 4136 – snap-confine apparmor policy bug
-
https://forum.snapcraft.io/t/device-cgroup-is-applied-to-devmode-snap/2663
- documented the content interface wrt shared libraries to follow store guidelines for cross-publisher sharing.
- documented auto-connection for a specific plugging snap to a specific slotting snap
- documented errno for different security backends
- 1724785
- PR 4114 don’t udev tag with devmode/classic snaps
- PR 4115 udev tag serial-port interface with only path attribute
- PR 4116 udev tag hidraw interface with only path attribute
- PR 4127 don’t udev tag but add /dev/uhid to device cgroup
- PRs 4131-4134 for 2.29
-
Migrated AppArmor to GitLab: https://gitlab.com/apparmor
-
[Work-in-progress] AppArmor support for multiple policy cache directories: apparmor/apparmor!4
-
Simplified usage of libapparmor cleanup functions by preserving errno: apparmor/apparmor!6
-
Landed upstream libseccomp changes to support new dynamic seccomp logging: seccomp/libseccomp#92
What the Security Team is Reading This Week
Weekly Meeting
-
Log: https://wiki.sne.bianheman.eu.org/MeetingLogs/Security/20171030
-
Info: https://wiki.sne.bianheman.eu.org/SecurityTeam/Meeting
More Info
Ubuntu cloud
Ubuntu offers all the training, software infrastructure, tools, services and support you need for your public and private clouds.
Newsletter signup
Related posts
What’s new in security for Ubuntu 24.04 LTS?
We’re excited about the upcoming Ubuntu 24.04 LTS release, Noble Numbat. Like all Ubuntu releases, Ubuntu 24.04 LTS comes with 5 years of free security...
Announcing Authd: OIDC authentication for Ubuntu Desktop and Server
Today we are announcing the general availability of Authd, a new authentication daemon for Ubuntu that allows direct integration with cloud-based identity...
Meet Canonical at Open Source Summit Europe 2024
Join Canonical, the publisher of Ubuntu, as we attend the upcoming Open Source Summit Europe 2024 in Austria. Hosted by the Linux Foundation, this summit is...