From gregory.herrero at oracle.com Sat Feb 8 05:15:47 2025 From: gregory.herrero at oracle.com (Oracle Ksplice) Date: Sat, 08 Feb 2025 05:15:47 +0000 Subject: [Ksplice][Ubuntu-22.04-Updates] New Ksplice updates for Ubuntu 22.04 Jammy (USN-7235-1) Message-ID: <56e493255187bea63b692a683961b6fd.apache@ksplice.com> Synopsis: USN-7235-1 can now be patched using Ksplice CVEs: CVE-2024-53103 CVE-2024-53141 Systems running Ubuntu 22.04 Jammy can now use Ksplice to patch against the latest Ubuntu Security Notice, USN-7235-1. INSTALLING THE UPDATES We recommend that all users of Ksplice Uptrack running Ubuntu 22.04 Jammy install these updates. On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf, these updates will be installed automatically and you do not need to take any action. Alternatively, you can install these updates by running: # /usr/sbin/uptrack-upgrade -y DESCRIPTION * CVE-2024-53103: Privilege escalation in Virtual Socket protocol driver. A missing variable initialization when destroying socket in the Virtual Socket protocol driver could lead to a use-after-free. A local attacker could use this flaw to escalate privileges. * CVE-2024-53141: Privilege escalation in netfilter (IP set) subsystem. A missing check when updating the bitmap for IP addresses in the netfilter (IP set) subsystem could lead to an out-of-bounds memory access. A local attacker could use this flaw to escalate privileges. SUPPORT Ksplice support is available at ksplice-support_ww at oracle.com.