[ubuntu-hardened] Assess vulnerabilities status of HWE kernels
Diogo Sousa
diogo.sousa at canonical.com
Fri Feb 7 14:06:51 UTC 2025
Hello, Francisco.
In the CVE page we also have entries for the HWE variants. Those will be in
the form linux-hwe-<version>
Further down you'll see there is an entry for linux-hwe-6.8 indicating that
it has been fixed for Jammy (Fixed 6.8.0-40.40~22.04.3).
You should look for those specific entries when making a determination.
Thank you for your time,
---
Diogo Sousa
Engineering Manager - Security Engineering
UTC+0 🇵🇹
On Wed, Feb 5, 2025 at 6:58 PM Francisco <jftuduri at gmail.com> wrote:
> Hi everyone!
>
> I'm working on a vulnerability scanner and would like some confirmation on
> how to handle HWE kernels.
> I'm using the CVE OVALs as the source of vulnerability information, but I
> will refer here to the data at https://ubuntu.com/security/cves for
> simplicity.
>
> For example, considering CVE-2024-38541
> <https://ubuntu.com/security/CVE-2024-38541>, it is listed as:
> Package: linux
> - 24.04 LTS noble -> Fixed 6.8.0-40.40
> - 22.04 LTS jammy -> Vulnerable
>
> If I'm assessing a 22.04 system I would assume that the kernel is
> vulnerable. However, if this system has HWE enabled it would have the
> kernel 6.8.0-52.53~22.04.1, which is higher than the fixed version shown
> for 24.04, so I would expect it to include the fix from 6.8.0-40.40.
> What would be the correct assessment in this case?
>
> And in general, when assessing the kernel vulnerability status under HWE
> should we:
> - Rely on what’s listed for the specific LTS release (e.g., "vulnerable"
> for 22.04 in this case), or
> - Check if a fix exists in a newer release (even if the fix isn’t
> officially shown for the current LTS release)?
>
> Is there some other way to check the vulnerability status of HWE kernels?
>
> Thanks in advance!
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.ubuntu.com/archives/ubuntu-hardened/attachments/20250207/3cb2999c/attachment.html>
More information about the ubuntu-hardened
mailing list