lemmy.net.au
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002@lemy.lol to Linux@programming.dev · 4 days ago

Canonical Says Ubuntu Infrastructure Is Facing Cross-Border DDoS Attack

linuxiac.com

external-link
message-square
15
fedilink
95
external-link

Canonical Says Ubuntu Infrastructure Is Facing Cross-Border DDoS Attack

linuxiac.com

cm0002@lemy.lol to Linux@programming.dev · 4 days ago
message-square
15
fedilink
Access Restricted
linuxiac.com
external-link
  • kamstrup@programming.dev
    link
    fedilink
    arrow-up
    11
    ·
    4 days ago

    Normally patches roll out before the vulnerability is disclosed. But I honestly don’t know the status on CopyFail

    • Jesus_666@lemmy.world
      link
      fedilink
      arrow-up
      8
      arrow-down
      1
      ·
      4 days ago

      Most distros delivered patched kernels well before the vulnerability was publicly disclosed. Not sure if Ubuntu did but they had ample time to do so.

      • lengau@midwest.social
        link
        fedilink
        arrow-up
        5
        ·
        4 days ago

        Not true. None of the major distros were alerted and Ubuntu, Debian, RHEL, etc. were all struggling at the last minute. See: https://infosec.exchange/@wdormann/116489443704631952

        However, none of those DDoS’s took out the archive servers, so Ubuntu users could still get new kernels.

        • Jesus_666@lemmy.world
          link
          fedilink
          arrow-up
          3
          ·
          4 days ago

          Interesting. So only the fast distros were done patching by time of disclosure. The ones you wouldn’t run a server on. Because only the kernel devs better informed. That’s… pretty amateurish from the guys who discovered CopyFail.

          • lengau@midwest.social
            link
            fedilink
            arrow-up
            5
            ·
            4 days ago

            Even then, some of the upstream LTS kernels didn’t get the patch until the 30th.

      • Successful_Try543@feddit.org
        link
        fedilink
        arrow-up
        4
        ·
        edit-2
        4 days ago

        Ubuntu 26.04 has already been patched, but not the older (LTS) releases.

        https://ubuntu.com/security/CVE-2026-31431

    • lengau@midwest.social
      link
      fedilink
      arrow-up
      3
      ·
      4 days ago

      The people who found the vulnerability didn’t do proper coordinated disclosure. See: https://infosec.exchange/@wdormann/116489443704631952

    • Miaou@jlai.lu
      link
      fedilink
      arrow-up
      2
      ·
      3 days ago

      The Debian Bookworm fix was only rolled out last night. Bookworm was not directly affected though, so maybe that’s why it took a bit more time

Linux@programming.dev

linux@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linux@programming.dev

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

  • !linux_memes@programming.dev
  • !linuxphones@lemmy.ca
  • our Matrix group chat
  • !reactos@programming.dev

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 442 users / day
  • 2.13K users / week
  • 2.87K users / month
  • 2.91K users / 6 months
  • 1 local subscriber
  • 13.5K subscribers
  • 251 Posts
  • 1.21K Comments
  • Modlog
  • mods:
  • Ategon@programming.dev
  • adr1an@programming.dev
  • dwraf_of_ignorance@programming.dev
  • BE: 0.19.9
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org