Description

Canonical has recently released security updates to address several vulnerabilities in the Linux kernel for Microsoft Azure Cloud systems in Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. These vulnerabilities, if exploited, could allow an attacker to cause a denial of service, expose sensitive information, or execute arbitrary code. Key vulnerabilities include CVE-2021-33631, an issue with the ext4 file system; CVE-2023-6270, a race condition in the ATA over Ethernet driver; CVE-2024-2201, insufficient mitigations for Branch History Injection; and CVE-2024-23307, a race condition in the software RAID driver. Additional fixes were applied to various Linux kernel subsystems, addressing CVE-2024-26642, CVE-2024-26922, CVE-2024-26720, CVE-2024-26736, CVE-2024-26898, CVE-2021-47063, and CVE-2023-52615. These vulnerabilities affected components such as the block layer subsystem, hardware random number generator core, GPU drivers, AFS file system, memory management, and Netfilter. As Ubuntu 16.04 and 18.04 have reached their end of life, security updates are now provided through Extended Security Maintenance (ESM) via Ubuntu Pro. Alternatively, TuxCare offers Extended Lifecycle Support (ELS) for continued security patching. TuxCare has already patched the aforementioned vulnerabilities for Ubuntu 16.04 and 18.04 ELS and offers KernelCare Enterprise, a live kernel patching solution that applies updates without system reboots, ensuring continuous protection for Microsoft Azure Cloud users.