[Ksplice][Ubuntu-24.04-Updates] New Ksplice updates for Ubuntu 24.04 Noble (USN-7703-1)
Oracle Ksplice
gregory.herrero at oracle.com
Wed Sep 10 20:17:48 UTC 2025
Synopsis: USN-7703-1 can now be patched using Ksplice
CVEs: CVE-2025-21759 CVE-2025-21787 CVE-2025-21790 CVE-2025-21791 CVE-2025-21795 CVE-2025-21836 CVE-2025-21844
Systems running Ubuntu 24.04 Noble can now use Ksplice to patch
against the latest Ubuntu Security Notice, USN-7703-1.
INSTALLING THE UPDATES
We recommend that all users of Ksplice Uptrack running Ubuntu 24.04
Noble install these updates.
On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.
Alternatively, you can install these updates by running:
# /usr/sbin/uptrack-upgrade -y
DESCRIPTION
* CVE-2025-21759: Use-after-free in ipv6 networking driver.
* CVE-2025-21787: Denial-of-service in Ethernet team driver.
* CVE-2025-21790: Null pointer dereference in Virtual eXtensible Local Area Network (VXLAN) driver.
* CVE-2025-21791: Privilege escalation in layer 3 master device support.
* CVE-2025-21795: Remote denial-of-service in NFS server driver.
* CVE-2025-21836: Use-after-free in IO-uring subsystem.
* CVE-2025-21844: Denial-of-service in Common Internet File System (CIFS).
A missing check when using the SMB3 client could lead to a NULL
pointer dereference. A local attacker could use this flaw to cause a
denial-of-service.
* Information leak in USB Modem (CDC ACM) driver.
* Note: Oracle has determined some CVEs are not applicable.
The kernel is not affected by the following CVEs
since the code under consideration is not compiled.
CVE-2025-21785
SUPPORT
Ksplice support is available at ksplice-support_ww at oracle.com.
More information about the Ksplice-Ubuntu-24.04-updates
mailing list