disco livecd still has insecure version 15 days after 10.4 bugfix hit proposed

Bug #1806088 reported by Charles Evans
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
systemd (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

This applies to disco only.
Ref: symlink exploit fixed in 10.4 release

Systemd restart is masked.
Debian lists this update as high priority.
Any easy get-root bug should be critical,
not medium priority as listed in the usn.
Updating while running the livecd is not securing anything.
Please prioritize release of proposed security updates to disco,
and all future current livecd versions.
At least push out those updates that require substantial knowledge to activate
(libc6, dbus, systemd, and their dependencies, etc )
and packages needed to do updates (apt, networkmanager, their dependencies, etc)

Is there a way to override the mask and restart systemd?
Can I use apparmor to prevent the symlink exploit? How?

Should I file this elsewhere?

Revision history for this message
Dan Streetman (ddstreet) wrote :

please reopen if this is still an issue

Changed in systemd (Ubuntu):
status: New → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.