The team is back from Madrid and this week we bring you some of our plans for the upcoming Ubuntu 24.10 release, plus we talk about Google’s kernelCTF project and Mozilla’s PDF.js sandbox when covering security updates for the Linux kernel, Firefox, Spreadsheet::ParseExcel, idna and more.
121 unique CVEs addressed
io_uring
or
nftables
since they were disabled in their target kernel configuration due to
high number of historical vulns in both subsystems
eval()
on untrusted user input - high profile,
disclosed by Mandiant - high profile since it affected Barracuda email gateway
devices and was publicly reported as being exploited against these by a
Chinese APT group