Security Team Weekly Summary: September 7, 2017

Canonical

Canonical

on 7 September 2017

The Security Team weekly reports are intended to be very short summaries of the Security Team’s weekly activities.

If you would like to reach the Security Team, you can find us at the #ubuntu-hardened channel on FreeNode. Alternatively, you can mail the Ubuntu Hardened mailing list at: ubuntu-hardened@lists.ubuntu.com

During the last week, the Ubuntu Security team:

  • Triaged 201 public security vulnerability reports, retaining the 59 that applied to Ubuntu.
  • Published 9 Ubuntu Security Notices which fixed 18 security issues (CVEs) across 11 supported packages.

Ubuntu Security Notices

Bug Triage

Mainline Inclusion Requests

Updates to Community Supported Packages

  • Gianfranco Costamagna provided a debdiff for xenial for check-all-the-things (LP: #1597245)

Development

  • Lots of snapd reviews: PR 3720 (solus), PR 3398 (XDG_ATA_DIRS for wayland), PR 3617 (big udev update), PR 3814 (opengl updates), PR 3812 (bluez interface on classic)
  • snapd PR 3826 for iio
  • follow-ups on PR 3805 (username/group instead of uid/gid)
  • lots of review/discussion surrounding PR 3621 (snap-confine calling snap-update-ns)
  • triage/fix snap-seccop testsuite failures on armhf and arm64
  • begin investigation of snapd device cgroup regression

What the Security Team is Reading This Week

Weekly Meeting

More Info

Ubuntu cloud

Ubuntu offers all the training, software infrastructure, tools, services and support you need for your public and private clouds.

Newsletter signup

Select topics you’re interested in

In submitting this form, I confirm that I have read and agree to Canonical’s Privacy Notice and Privacy Policy.

Related posts

A first look at desktop metrics

We first announced our intention to ask users to provide basic, not-personally-identifiable system data back in February. Since then we have built the Ubuntu Report tool and integrated it in to the Ubuntu 18.04 LTS initial setup tool. You…

Ubuntu 16.04 LTS certified for Intel NUC for IoT device development

Canonical and Intel® are pleased to announce that Ubuntu 16.04 LTS is now certified on selected Intel® NUC Mini PCs and boards. This partnership will aid device manufacturer’s and their developers to a smoother path to the development and…

Report from the GNOME Software design sprint

  A couple of weeks ago representatives from across Canonical met in London to talk about ideas to improve the user experience of GNOME Software. We had people from the store team, snap advocacy, snapd, design and from the desktop…