Kernel vulnerabilities

Releases and other announcements.
Please don't post support questions here
Forum rules
Section reserved for the team. You can reply to announcements here but not post new topics. Do not add support questions to threads here, use the appropriate support forum instead.
Husse

Kernel vulnerabilities

Post by Husse »

Kernel updates for in all 10 vulnerabilities have been released
If I count correctly seven of these are for a local attacker
Nevertheless it may be a good idea to upgrade your kernel
Read about the ups and downs of that here
This is not without some risk to your system as these are level 5 updates and could potentially break your system
You have to reboot after this update
Luckily, if they do, you can just boot into the old kernel
Edit - both the old and the new kernel will have an entry in Grub
fwc

Re: Kernel vulnerabilities

Post by fwc »

How do you boot into the old if it doesn't work?
User avatar
Boo
Level 7
Level 7
Posts: 1633
Joined: Mon Mar 26, 2007 7:48 am

Re: Kernel vulnerabilities

Post by Boo »

the old kernels will be listed in the grub boot menu.
just use the arrow keys to navigate to the desired one and hit enter.

Boo
Image
Now where was i going? Oh yes, crazy!
Husse

Re: Kernel vulnerabilities

Post by Husse »

I have now installed the final Helena Main on my laptop and all level 4 and 5 updates with good result, the Broadcom STA driver was not broken and on my desktop the ATI fglrx driver was not broken
Updates seem to go smoother now, but in the link above there are reports of failed updates
Any kernel update leaves a link to the old kernel in Grub so you can boot with it and it is possible to remove the new kernel if you cant' use it
M_aD
Level 4
Level 4
Posts: 204
Joined: Sun Apr 27, 2008 9:03 am
Location: Belgium
Contact:

Re: Kernel vulnerabilities

Post by M_aD »

Does one need to update everything from the 4 and/or 5 level updates in Mint 8 Helena or can one just only install the 2.6.31-19 kernel stuff?
Last edited by M_aD on Mon Feb 08, 2010 6:04 pm, edited 1 time in total.
red-e-made
Level 5
Level 5
Posts: 526
Joined: Sat Jul 14, 2007 11:31 am

Re: Kernel vulnerabilities

Post by red-e-made »

Running Mint 7 XFCE here, and just installed all Level 4 and 5 updates. Rebooted. No problems whatsoever. Thanks for the heads up, Husse.
mmesantos1

Re: Kernel vulnerabilities

Post by mmesantos1 »

Thanks for the heads up. I am running Mint 8 Main x32 and updated to the latest PAE kernel as well as all Level 4 & 5 updates and all is working well. :)
Husse

Re: Kernel vulnerabilities

Post by Husse »

The level 4 updates available now is for xorg so they are not necessary to secure you from this threat, it's the level 5 kernel things that are important
M_aD
Level 4
Level 4
Posts: 204
Joined: Sun Apr 27, 2008 9:03 am
Location: Belgium
Contact:

Re: Kernel vulnerabilities

Post by M_aD »

That's all i needed to know. Thank you Husse. :)
z06gal

Re: Kernel vulnerabilities

Post by z06gal »

I just updated via synaptic and all seems to be fine. Thanks for the info Husse. :D
fwc

Re: Kernel vulnerabilities

Post by fwc »

Which exact files in the updater do I need if I am running 32bit, Gnome Helena?
Husse

Re: Kernel vulnerabilities

Post by Husse »

fwc wrote:Which exact files in the updater do I need if I am running 32bit, Gnome Helena?
I don't have an unupdated system any more but as far as I remember all the level 5 ones, except possibly an update to hal which I think was there, or maybe not there could be new ones
Remember that this can break your system and that you can use the old kernel in that case
fwc

Re: Kernel vulnerabilities

Post by fwc »

Husse wrote:
fwc wrote:Which exact files in the updater do I need if I am running 32bit, Gnome Helena?
I don't have an unupdated system any more but as far as I remember all the level 5 ones, except possibly an update to hal which I think was there, or maybe not there could be new ones
Remember that this can break your system and that you can use the old kernel in that case
aha! thanks very much. It worked but I was wondering if it would be any faster or just patch security holes. Thanks for all the info.
SL_DON

Re: Kernel vulnerabilities

Post by SL_DON »

Noob user here just did the kernel update and so far so good.

just would like to know how long the old kernel will still be in grub and if its permanent how to remove it once i am satisfied that my system is stable.
User avatar
newW2
Level 5
Level 5
Posts: 821
Joined: Fri Apr 06, 2007 10:24 am
Location: USA

Re: Kernel vulnerabilities

Post by newW2 »

First use this command to see the list of the installed kernels in your Ubuntu

$ dpkg --get-selections | grep linux-image

Now for example try to delete the oldest one (change oldest kernel with your oldest one)

# $ sudo apt-get purge [oldest-kernel-from grep command above]

If the kernel you try to uninstall is not updated, you will get a message to update first before you continue. Update then the kernel and then uninstall that old kernel and the updates using the same command above.

Important : Do not uninstall the linux-image-generic as it is necessary to receive updates of the kernel.

[note if satisfied and using grub2; then run update-grub as root to cleanup grub]

Source is from one of our sponsors that has many a good how-to and/or review:
http://www.unixmen.com/linux-tutorials/ ... -in-ubuntu
dan j

Re: Kernel vulnerabilities

Post by dan j »

Use ubuntu-tweak to remove old kernels.

http://ubuntu-tweak.com/
blklime

Re: Kernel vulnerabilities

Post by blklime »

How does one update the kernel?
mmesantos1

Re: Kernel vulnerabilities

Post by mmesantos1 »

blklime wrote:How does one update the kernel?
Set Mint update for level 5 and then update. Once complete reboot your PC. After that you can remove old kernel. You can reboot again to be sure, well I do but that's it.
Kendoori
Level 5
Level 5
Posts: 748
Joined: Thu Jul 09, 2009 12:51 pm
Location: Sanibel, FL USA

Re: Kernel vulnerabilities

Post by Kendoori »

I also updated with no issues. I was motivated to do this because of issues with my MSI U100 and the Bison webcam. Updating the kernel per level 5 releases fixed this for me.
User avatar
kmb42vt
Level 5
Level 5
Posts: 974
Joined: Sun Dec 06, 2009 11:15 am
Location: Vermont
Contact:

Re: Kernel vulnerabilities

Post by kmb42vt »

Note: I'm only posting this for info purposes and not recommending anyone jump out and upgrade. Perhaps some more experienced than I can determine whether it's needed or not.

ZDNet and Ubuntu recently announced that more vulnerabilities have been found in Ubuntu's latest kernels covering versions 6.06 LTS to 9.10 (Ubuntu/Kubuntu/Xubuntu/Edubuntu) which should include Mint versions also I believe? In my case, my latest kernel is 2.6.31-20.57 in which case I would need to upgrade to 2.6.31-20.58 if I read things right.

Here's the link to the ZDNet article and another to the referenced Ubuntu announcement. The latter lists the Ubuntu versions and the various vulnerable kernel versions along with the required updates under each one:

http://blogs.zdnet.com/hardware/?p=7728

http://www.ubuntu.com/usn/USN-914-1

I found that the updates are available under "Level 5" in mintUpdate.
"Humph. Choice, it is the quintessential Linux delusion, simultaneously the source of it's greatest strength, and it's greatest weakness." (All apologies to The Architect)
Post Reply

Return to “Releases & Announcements”