[ubuntu-hardened] Assess vulnerabilities status of HWE kernels

Francisco jftuduri at gmail.com
Wed Feb 5 18:56:20 UTC 2025


Hi everyone!

I'm working on a vulnerability scanner and would like some confirmation on
how to handle HWE kernels.
I'm using the CVE OVALs as the source of vulnerability information, but I
will refer here to the data at https://ubuntu.com/security/cves for
simplicity.

For example, considering CVE-2024-38541
<https://ubuntu.com/security/CVE-2024-38541>, it is listed as:
Package: linux
- 24.04 LTS noble -> Fixed 6.8.0-40.40
- 22.04 LTS jammy -> Vulnerable

If I'm assessing a 22.04 system I would assume that the kernel is
vulnerable. However, if this system has HWE enabled it would have the
kernel 6.8.0-52.53~22.04.1, which is higher than the fixed version shown
for 24.04, so I would expect it to include the fix from 6.8.0-40.40.
What would be the correct assessment in this case?

And in general, when assessing the kernel vulnerability status under HWE
should we:
- Rely on what’s listed for the specific LTS release (e.g., "vulnerable"
for 22.04 in this case), or
- Check if a fix exists in a newer release (even if the fix isn’t
officially shown for the current LTS release)?

Is there some other way to check the vulnerability status of HWE kernels?

Thanks in advance!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.ubuntu.com/archives/ubuntu-hardened/attachments/20250205/ff087f17/attachment.html>


More information about the ubuntu-hardened mailing list