News: 1645630148

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Ubuntu applies security fixes for all versions back to 14.04

(2022/02/23)


Ubuntu has issued a batch of updates that cover the default as well as the AWS and KVM flavours for the current short-term release [1]21.10 , both the original [2]5.04 and OEM [3]5.14 builds for the current 20.04 LTS release, as well as [4]18.04 , and, surprisingly, even [5]16.04 and 14.04 .

While kernel releases trickle out all the time, the last two members of that list – [6]2016's Xenial Xerus and [7]2014's Trusty Tahr – emphasise that even very old releases in Extended Security Maintenance or [8]ESM sometimes need a bit of TLC.

It also might surprise some that multiple different Linux kernels are available for a single product release. Although Ubuntu pushes out a new Long-Term Support ( [9]LTS ) release every even-numbered year, those get five years of bugfixes.

Kernel fixes

The 21.10 update issues fixes for a number of medium-severity bugs. You can read more detail [10]here .

Fixes for OEM 5.14 build of 20.04 are [11]here , and for the original are [12]here . All are assessed as medium severity.

The 18.04 security release is [13]here – with all vulns requiring local access.

Finally, the 16.04 and 14.04 updates are [14]here , and include fixes for two medium-severity Bluetooth bugs.

If you run an LTS release but you need features from newer releases, there are two ways forward. If there's a newer LTS release, upgrade to that – but maybe play it safe and wait for the point-one release, as with any OS. For instance, for 20.04, [15]20.04.1 arrived the following August.

[16]Linux Snap package tool fixes make-me-root bugs

[17]GNOME Project retires OpenGL rendering library Clutter

[18]Google's Chrome OS Flex could revive old PCs, Macs

[19]Comparing the descendants of Mandrake and Mandriva Linux

In the meantime, though, if you need features from a newer short-term release, there's the Hardware Enablement (HWE) stack. So, for example, although 20.04 shipped with kernel 5.04, if you install the HWE update, you'll get the kernel, drivers, and some of the display stack of the current release. Right now, that's 21.10 with kernel 5.13. Ubuntu publishes [20]instructions and it's a simple job.

If even that isn't new enough, Ubuntu also maintains what it describes as the OEM kernel series. As the company's [21]page says, installing that is as simple as: apt install linux-oem-20.04b

Note, though, that the final letter changes over time, so you should search for later letters on the end. As of the time of writing, linux-oem-20.04d will get you kernel 5.14.0.1024.2.

These methods also work on Ubuntu derivatives such as Linux Mint as well.

[22]

Don't want to be caught out by updates on desktops and laptops? The Reg FOSS desk suggests doing it every day – and that applies to Windows, too. Around here, we generally turn non-server boxes right off at night, so first thing in the morning, turn it on and immediately do a full update, complete with a reboot if necessary. If you share our cavalier attitude towards outdated dependencies, here's how to do it from the command line:

[23]

[24]

sudo -s ← this gets you a root shell.

apt update ← refresh the database of available updates.

[25]

apt full-upgrade -y ← the modern way to update everything.

apt autoremove -y ← removes any now-superfluous packages, without asking. (Take the -y off the end if you are more cautious.)

apt purge ← deletes any system-provided config files from removed packages.

[26]

apt clean ← empties APT's package cache, which can clear a lot of disk space.

snap refresh ← does the same for those newfangled Snap packages, such as Firefox.

For convenience, you can concatenate them all together: sudo -s

apt update ; apt full-upgrade -y ; apt autoremove -y ; apt purge ; apt clean ; snap refresh

(Yes, we know, using && instead of ; might be more prudent, but it means extra typing.)

If you use Flatpaks as well, stick flatpak update on the end too.

Usually, Ubuntu keeps the shell history for the root account, so each day, you can just press the up-arrow until the last invocation reappears, then press Enter. ®

Get our [27]Tech Resources



[1] https://ubuntu.com/security/notices/USN-5295-2

[2] https://ubuntu.com/security/notices/USN-5297-1

[3] https://ubuntu.com/security/notices/USN-5302-1

[4] https://ubuntu.com/security/notices/USN-5294-2

[5] https://ubuntu.com/security/notices/USN-5299-1

[6] https://www.theregister.com/2016/03/29/ubuntu_16_04_first_beta_review/

[7] https://www.theregister.com/2014/04/22/ubuntu_14_04_review/

[8] https://ubuntu.com/security/esm

[9] https://ubuntu.com/blog/what-is-an-ubuntu-lts-release

[10] https://ubuntu.com/security/notices/USN-5295-2

[11] https://ubuntu.com/security/notices/USN-5302-1

[12] https://ubuntu.com/security/notices/USN-5297-1

[13] https://ubuntu.com/security/notices/USN-5294-2

[14] https://ubuntu.com/security/notices/USN-5294-2

[15] https://lists.ubuntu.com/archives/ubuntu-announce/2020-August/000259.html

[16] https://www.theregister.com/2022/02/19/linux_snap_ubuntu/

[17] https://www.theregister.com/2022/02/18/clutter_gnome_retired/

[18] https://www.theregister.com/2022/02/16/google_chrome_os/

[19] https://www.theregister.com/2022/02/15/comparing_the_descendants_of_mandrake/

[20] https://wiki.ubuntu.com/Kernel/LTSEnablementStack

[21] https://wiki.ubuntu.com/Kernel/OEMKernel

[22] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YhZoOlJNovb-EEVRzDPEfwAAANc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[23] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YhZoOlJNovb-EEVRzDPEfwAAANc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[24] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YhZoOlJNovb-EEVRzDPEfwAAANc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[25] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YhZoOlJNovb-EEVRzDPEfwAAANc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[26] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YhZoOlJNovb-EEVRzDPEfwAAANc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[27] https://whitepapers.theregister.com/



Tom7

Soooooo.... are the fixes important?

DoContra

From the box to the right of the article, all fixes seem to be medium severity local privilege escalations and some backported bluetooth fixes for exploitable bugs (which I assume require bluetooth hardware)

RE: are they important

Snake

Following the links in the story:

- both 21.10 release, and 20.04 / 5.14 LTS builds contains Medium-level CVE's

- however, 20.04 LTS / 5.04 build contains a High-level CVE, CVE-2022-0492

etc.

So yes, I would say that they should be applied as soon as possible.

Don't use &&

Chris Gray 1

Since "&&" allows the processes to all run at the same time, methinks you *must* use ";" to separate them - you want them to run sequentially, not all at once. Even if there is some magic locking that is done, there is no guarantee which command starts first.

Re: Don't use &&

Wempy

no, `&` allows them to run concurrently (in the background) `&&` will run the next one only when the preceeding one finishes with an exit code of zero.

original_rwg

If it ain't broke - upgrade anyway :)

Your scheduled bit pedantry whenever shell commands are mentioned

DoContra

When using sudo (and not using relative paths), it's a good idea to pass -H (set $HOME to the target user's home directory -- root's home in this case) as this can potentially apply small to moderate borking to the non-root user's config files (the one I've had and seen was permission problems on vim's per-user files); for this use (calling apt/aptitude) it shouldn't be a problem but...

From the fine article's commands:

sudo -s

would become

sudo -Hs

PD: The advice to wait for the LTS.1 release is so good, Ubuntu forces it on you: when configured to upgrade only to the next LTS, Ubuntu's updater will not show the update until sometime after the .1 version releases (or you call the distro upgrader manually with the -d option).

PPD: Most internet guides will either have multiple sudo invocations (one for each command), or will do something like sudo bash -c "list; of; commands". I'm not educated enough to discuss the relative merits of either of these three options, but personally I find this article's approach the most convenient by far, so that's what I use.

"...if the church put in half the time on covetousness that it does on lust,
this would be a better world." - Garrison Keillor, "Lake Wobegon Days"