Time to roll security updates

Kees Cook kees at ubuntu.com
Tue Aug 5 20:34:02 UTC 2008


It's that time again (and with some urgency, due to CVE-2008-3275).
Please pull, build, and boot test.  I have some PoCs I can test with
once the .debs are somewhere I can snag them from.

                dapper     feisty         gutsy         hardy
CVE-2008-2812  pending    pending       pending       pending  medium
CVE-2008-2931  pending    pending  not-affected  not-affected  low
CVE-2008-3272  pending    pending       pending       pending  low
CVE-2008-3275  pending    pending       pending       pending  medium

These have been commited to the ubuntu-security git trees.  (Note that
hardy is expecting -19.39 as a version to avoid ABI bumping the existing
-security/-updates version; -20 in proposed will need to be respun with
the CVE fixes from -19.39)

Thanks!

-Kees

-- 
Kees Cook
Ubuntu Security Team




More information about the kernel-team mailing list