The release of Ubuntu 23.04 Lunar Lobster is nigh so we take a look at some of the things the security team has been doing along the way, plus it’s our 6000th USN so we look back at the last 19 years of USNs whilst covering security updates for the Linux kernel, Emacs, Irssi, Sudo, Firefox and more.
109 unique CVEs addressed
malloc()
/ free()
- would then trigger the memory checking of libc
which detected thissudoreplay
(can
be used to list or play back the commands executed in a sudo session) - and so
could allow an attacker to get code execution as the user running sudoreplay
by injecting terminal control characters.desktop
files - could allow an attacker to get code execution as
the user running firefox - interesting to note that as a snap, firefox is
confined by default and cannot execute arbitrary commands from the host
system - can only use binaries from within the firefox
snap itself or the
user’s $HOME
which makes exploitation of such an issue harder since less
LOLBins to make use ofio_uring
mediation support in AppArmordm-verity
within snapd for
improved integrity of snaps