Almost 40% of Ubuntu users vulnerable to new privilege elevation flaws

https://www.bleepingcomputer.com/news/security/almost-40-percent-of-ubuntu-users-vulnerable-to-new-privilege-elevation-flaws/

204 points · 19 comments · view on lemmy.world

19 Comments

hygieia@feddit.nl · 92 pts · 3y (4 replies)

CVE-2023-2640 and CVE-2023-32629 if you don't fancy spending an age clicking Object to all the 'legitimate interest' cookie shit.

maiskanzler@feddit.de · 0 pts · 3y

Tip: "I still don't care about cookies" for desktop browsers + deleting all cookies at the end of the browser session works flawlessly for me.

dookie@kbin.cafe · -7 pts · 3y (2 replies)

bro doesnt have an adblocker?

moreeni@lemm.ee · 4 pts · 3y (1 reply)

And a script blocker like NoScript

garam@lemmy.my.id · 4 pts · 3y

All disable script all together on foreign site using uBo

Yewb@kbin.social · 27 pts · 3y (1 reply)

CVE-2023-2640

Needs a user account on the system (even unprivledged accounts) via overlayfs

Overlayfs allows one, usually read-write, directory tree to be overlaid onto another, read-only directory tree. All modifications go to the upper, writable layer. This type of mechanism is most often used for live CDs but there is a wide variety of other uses.

darkmugglet@lemm.ee · 4 pts · 3y

Or a docker container.

BadRS@lemmy.world · 25 pts · 3y (1 reply)

Is the end of this headline "because they haven't updated in 3 years"?

style99@kbin.social · 10 pts · 3y

In this case, it's more like the opposite. People testing the cutting edge versions of Ubuntu are the ones impacted.

astraeus@programming.dev · 11 pts · 3y (2 replies)

Couldn’t find whether this even impacts LTS builds. Either way, seems like patching should resolve the issue

style99@kbin.social · 5 pts · 3y (1 reply)

LTS uses the 5.15 Linux kernel (by default). This vulnerability impacts 6.2.

RoundSparrow@lemmy.ml · 4 pts · 3y

If I understand correctnly.... Ubuntu 22.04.2 LTS has 5.19 kernel by default: https://9to5linux.com/ubuntu-22-04-2-lts-released-with-linux-kernel-5-19-updated-components "the Ubuntu 22.04.2 LTS point release also comes with a newer kernel, namely Linux 5.19, from the Ubuntu 22.10 (Kinetic Kudu) release"

As you said, if it is only 6.2, still out of the window.

Yewb@kbin.social · 8 pts · 3y

Needs a user account on the system (even unprivledged accounts) via overlayfs

Overlayfs allows one, usually read-write, directory tree to be overlaid onto another, read-only directory tree. All modifications go to the upper, writable layer. This type of mechanism is most often used for live CDs but there is a wide variety of other uses.

roq@noc.social · 6 pts · 3y (1 reply)

@leo what’s the solution, is it just the normal apt update/upgrade or something more complicated? And is it possible to know if a machine has suffered such attack at all?

leo@lemmy.linuxuserspace.show · 8 pts · 3y

According to the Ubuntu bulletin, a simple update is sufficient.

The Wiz announcement didn't really go into specifics, so not sure other than normal user auditing.

djsaskdja@reddthat.com · -12 pts · 3y (2 replies)

Typical lolbuntu move

prenatal_confusion@lemmy.one · 5 pts · 3y

<°==<

GustavoM@lemmy.world · 2 pts · 3y

Ubloatu*

ftfy