Canonical Says Ubuntu Infrastructure Is Facing Cross-Border DDoS Attack
https://linuxiac.com/canonical-says-ubuntu-infrastructure-is-facing-cross-border-ddos-attack/
https://linuxiac.com/canonical-says-ubuntu-infrastructure-is-facing-cross-border-ddos-attack/
17 Comments
ZombieCyborgFromOuterSpace@piefed.ca · 25 pts · 103d
This hatred for Snaps is getting out of hand.
Skyline969@piefed.ca · 23 pts · 103d
Ubuntu is one of the most used distros in both desktop and server environments. Take down the update servers, can’t patch CopyFail. Can’t patch CopyFail, more time to access affected systems.
That’s my paranoid take anyway.
kamstrup@programming.dev · 11 pts · 103d
Normally patches roll out before the vulnerability is disclosed. But I honestly don't know the status on CopyFail
Jesus_666@lemmy.world · 7 pts · 103d
Most distros delivered patched kernels well before the vulnerability was publicly disclosed. Not sure if Ubuntu did but they had ample time to do so.
lengau@midwest.social · 5 pts · 103d
Not true. None of the major distros were alerted and Ubuntu, Debian, RHEL, etc. were all struggling at the last minute. See: https://infosec.exchange/@wdormann/116489443704631952
However, none of those DDoS's took out the archive servers, so Ubuntu users could still get new kernels.
Jesus_666@lemmy.world · 3 pts · 103d
Interesting. So only the fast distros were done patching by time of disclosure. The ones you wouldn't run a server on. Because only the kernel devs better informed. That's... pretty amateurish from the guys who discovered CopyFail.
lengau@midwest.social · 5 pts · 103d
Even then, some of the upstream LTS kernels didn't get the patch until the 30th.
Successful_Try543@feddit.org · 4 pts · 103d
Ubuntu 26.04 has already been patched, but not the older (LTS) releases.
https://ubuntu.com/security/CVE-2026-31431
neighborhoodnerd21@mastodon.social · 3 pts · 103d
@Jesus_666 @kamstrup its my understanding that this actually hasn’t been patched in most distributions. The ubuntu statement says they released mitigations and disabled the kernel module affected but that patches will be released. according to a post on linkedin made yesterday and a video attached to it demonstrating the exploit on a current kali release it hasnt been fixed
Jesus_666@lemmy.world · 2 pts · 103d
Yeah, I turned out to be slightly misinformed. The kernel sources had a fix for a while now and fast moving distros like Arch immediately picked them up. But nobody except the kernel devs was told about the vuln and so nobody expedited deployment of a fixed kernel. Ouch.
lengau@midwest.social · 3 pts · 103d
The people who found the vulnerability didn't do proper coordinated disclosure. See: https://infosec.exchange/@wdormann/116489443704631952
Miaou@jlai.lu · 2 pts · 103d
The Debian Bookworm fix was only rolled out last night. Bookworm was not directly affected though, so maybe that's why it took a bit more time
poinck@lemmy.world · 3 pts · 103d
Successful_Try543@feddit.org · 1 pts · 103d
Does Ubuntu, like Debian, make you choose a repository mirror during the installation?
lengau@midwest.social · 2 pts · 103d
Typically they use archive.ubuntu.com, which was not affected.
neighborhoodnerd21@mastodon.social · 1 pts · 103d
@Successful_Try543 @poinck no
unexposedhazard@discuss.tchncs.de · 3 pts · 103d
Add to that the recent announcement about adding AI poop to the OS.
Greg@discuss.tchncs.de · 6 pts · 103d
Which border?