Issue726


header.png

Welcome to the Ubuntu Weekly Newsletter, Issue 726 for the week of March 6 - 12, 2022.

In this Issue

  • USN-5317-1: Linux kernel vulnerabilities
  • Welcome New Members and Developers
  • Ubuntu Stats
  • Hot in Support
  • LoCo Events

  • Unprivileged eBPF disabled by default for Ubuntu 20.04 LTS, 18.04 LTS, 16.04 ESM
  • Plasma 5.24.3 available on Kubuntu 21.10
  • Other Community News
  • Ubuntu Cloud News
  • Canonical News
  • In the Press
  • In the Blogosphere
  • Featured Audio and Video
  • Meeting Reports
  • Upcoming Meetings and Events
  • Updates and Security for 18.04, 20.04, and 21.10
  • And much more!

General Community News

USN-5317-1: Linux kernel vulnerabilities

This Ubuntu Security Notice provides us with details of fixed security vulnerabilities in the Linux kernel. Specifics of this vulnerability: the CVEs fixed, who discovered the flaws, and how it could be exploited if left unpatched are given. The releases impacted and package versions are noted, providing the fixes.

https://ubuntu.com/security/notices/USN-5317-1

Vulnerability documentation in the medias:

Welcome New Members and Developers

Congratulations to this contributor!

Ubuntu Stats

Bug Stats

  • Open: 138373 (-150)
  • Critical: 325 (0)
  • Unconfirmed: 69079 (-102)

As always, the Bug Squad needs more help. If you want to get started, please see: https://wiki.ubuntu.com/BugSquad

Translations

  • Ukrainian: 88.05% (38666/1104)
  • German: 87.08% (41798/49)
  • French: 81.51% (59825/6990)
  • Spanish: 80.91% (61755/4199)
  • Swedish: 77.57% (72584/878)

Hot in Support

Ask Ubuntu Top 5 Questions

Ask (and answer!) questions at: https://askubuntu.com/

Ubuntu Forums Top 5 Threads

Find more support at: https://ubuntuforums.org/

LoCo Events

The following LoCo team events are currently scheduled in the next two weeks:

Looking beyond the next two weeks? Visit the LoCo Team Portal to browse upcoming events around the world: http://loco.ubuntu.com/events/

The Hub

Unprivileged eBPF disabled by default for Ubuntu 20.04 LTS, 18.04 LTS, 16.04 ESM

Alex Murray writes that eBPF code can cause the kernel to "leak privileged information" which is prevented via eBPF being disabled by default. This is a normal setting for Ubuntu 21.10 & the in-development Ubuntu 22.04 LTS, but is a new default for Ubuntu 16.04 ESM, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS as a "hardening measure". If your system requires it, a command is provided which will reverse the change, or to check your existing system configuration.

https://discourse.ubuntu.com/t/unprivileged-ebpf-disabled-by-default-for-ubuntu-20-04-lts-18-04-lts-16-04-esm/27047

Addressing the flaws:

The Planet

Plasma 5.24.3 available on Kubuntu 21.10

The Kubuntu team is pleased to announce Plasma 5.24.3 is now available in the team backports PPA for Kubuntu 21.10 (Impish Indri). A link to the Plasma 5.24.3 release notes, and the commands required to add the backports PPA are provided. As well a caveat for some risks involved with using it, plus where to file any bug reports should bugs be found are provided.

https://kubuntu.org/news/plasma-5-24-3-available-on-kubuntu-21-10/

Other Community News

奇安信正式加入优麒麟社区,携手共建开源生态

“近日,奇安信已完成 CLA(Contributor License Agreement 贡献者许可协议)签署 ,正式加入优麒麟社区。同时奇安信也在优麒麟社区建立了浏览器 SIG 组,主要负责优麒麟社区浏览器的兼容 …”

https://www.ubuntukylin.com/news/1746-cn.html

Ubuntu Cloud News

Canonical News

In the Press

The Dirty Pipe Vulnerability

Max Kellermann provides the story of CVE-2022-0847. We are given the history from the first support ticket about data corruption, through to the eventual discovery of the flaw. Included is a discussion of the code that was used to prove the 'unlikely' flaw, then how the actual commit was located that introduced this flaw. A timeline showing the first support ticket, through to patching and public disclosure is provided.

https://dirtypipe.cm4all.com/

In the Blogosphere

Budgie 10.6 Desktop Environment Improves Theme and Panel, Revamps Notification System

Marius Nestor writes that "Joshua Strobl of the Budgie Desktop team" has announced the release of Budgie 10.6. We are given a brief tour of some of the improvements found in this release, and advised to visit the project's GitHub if more details are required.

https://9to5linux.com/budgie-10-6-desktop-improves-theme-and-panel-revamps-notification-system

Ubuntu 22.04 LTS To Carry GNOME Triple Buffering Support

Michael Larabel tells us Ubuntu 22.04 LTS will carry the patches so the GNOME desktop makes use of "on-demand triple buffering support" to "boost the GPU rendering performance". Michael highlights the work performed by Canonical's Daniel Van Vugt, giving details on why it's "on-demand", and said it has "doubled the performance for Intel graphics and Raspberry Pi" and improved other graphics too. We are told it missed the latest GNOME 42 beta release, however a patched version of Mutter is currently available in the Ubuntu jammy archive.

https://www.phoronix.com/scan.php?page=news_item&px=Ubuntu-22.04-GNOME-TB

Ubuntu Security Podcast: Episode 152

"It’s a big week for kernel security vulnerabilities - we cover Dirty Pipe and fixes for the latest microarchitectural side channel issues, plus we bring you the first in a 3 part series on hardening your Ubuntu systems against malicious attackers."

https://ubuntusecuritypodcast.org/episode-152/

Ubuntu Portugal Podcast: 185 - Foco, mais foco!

"Na semana em que afinal ainda não são conhecidos os vencedores do concurso de wallpapers Jammi Jellifish o Diogo andou a melhorar a sua mestria em react, o Xubuntu anunciou o seu concurso de wallpapers e paralelamente mudou-se para para github e transifex enquanto alguns utilizadores de UBPorts podem ouvir spotify ou a sua estação de rádio preferida…"

https://podcastubuntuportugal.org/e185/

Destination Linux: 268: Free As In Freedom Not Free As In Beer

"This week’s episode of Destination Linux, we’re going to be discussing the phrase of "Free As In Freedom, Not Free As In Beer". Is it okay for developers to charge for their work? Then we’re going to take a look at a new partnership Canonical has with Vodafone."

https://destinationlinux.org/episode-268/

Meeting Reports

Upcoming Meetings and Events

  • Ubuntu 22.04 UI Freeze: Thursday, Mar 17, 2022
  • Community Office Hours: Thu, March 17, 6pm – 7pm

Times shown are UTC. For more details and farther dates please visit: https://fridge.ubuntu.com/calendars/

Updates and Security for 18.04, 20.04, and 21.10

Security Updates

Ubuntu 18.04 Updates

End of Standard Support: April 2023

Ubuntu 20.04 Updates

End of Standard Support: April 2025

Ubuntu 21.10 Updates

End of life: July 2022

Subscribe

Get your copy of the Ubuntu Weekly Newsletter delivered each week to you via email at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-news

Or follow us via our various social media presences:

Archive

You can always find older Ubuntu Weekly Newsletter issues at: https://wiki.ubuntu.com/UbuntuWeeklyNewsletter/Archive

Further News

As always you can find more Ubuntu news and announcements at:

Conclusion

Thank you for reading the Ubuntu Weekly Newsletter.

See you next week!

Credits

The Ubuntu Weekly Newsletter is brought to you by:

  • Krytarik Raido
  • Bashing-om
  • Chris Guiver
  • Wild Man
  • 1fallen
  • And many others

Glossary of Terms

Other acronyms can be found at: https://wiki.ubuntu.com/UbuntuWeeklyNewsletter/glossary

Get Involved

The Ubuntu community consists of individuals and teams, working on different aspects of the distribution, giving advice and technical support, and helping to promote Ubuntu to a wider audience. No contribution is too small, and anyone can help. It's your chance to get in on all the community fun associated with developing and promoting Ubuntu. More on this at: https://community.ubuntu.com/contribute/

Or get involved with the Ubuntu Weekly Newsletter team! We always need summary writers and editors, if you're interested, learn more at: https://wiki.ubuntu.com/UbuntuWeeklyNewsletter/Join

Feedback

This document is maintained by the Ubuntu Weekly News Team. If you have a story idea or suggestions for the Weekly Newsletter, join the Ubuntu News Team mailing list at https://lists.ubuntu.com/mailman/listinfo/Ubuntu-news-team and submit it. Ideas can also be added to the wiki at https://wiki.ubuntu.com/UbuntuWeeklyNewsletter/Ideas. If you'd like to contribute to a future issue of the Ubuntu Weekly Newsletter, please feel free to edit the appropriate wiki page. If you have any technical support questions, please check https://community.ubuntu.com/help-information/ for more information on where to get help.

Except where otherwise noted, this issue of the Ubuntu Weekly Newsletter is licensed under a Creative Commons Attribution ShareAlike 3.0 License CCL.png

UbuntuWeeklyNewsletter/Issue726 (last edited 2022-03-14 22:48:40 by bashing-om)