[Bug 2040280] Re: CVE-2022-40982 on Ubuntu Mantic Linux Kernel still not fixed

Thadeu Lima de Souza Cascardo 2040280 at bugs.launchpad.net
Sat Nov 18 09:02:01 UTC 2023


The kernel mitigations for this vulnerability were provided back in
August, when Mantic was still the development released. So, though the
Mantic target kernel had not been in the release pocket yet, the fixes
were there, so it was marked as pending for the development release.
When Mantic got released, the status was not updated fast enough.

So thank you for bringing this up, this has been fixed in our CVE
tracker and CVE web pages now.

Cascardo.

** Also affects: linux (Ubuntu)
   Importance: Undecided
       Status: New

** Also affects: linux (Ubuntu Mantic)
   Importance: Undecided
       Status: New

** Also affects: intel-microcode (Ubuntu Mantic)
   Importance: Undecided
       Status: New

** Changed in: linux (Ubuntu)
       Status: New => Fix Released

** Changed in: linux (Ubuntu Mantic)
       Status: New => Fix Released

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to intel-microcode in Ubuntu.
https://bugs.launchpad.net/bugs/2040280

Title:
  CVE-2022-40982 on Ubuntu Mantic Linux Kernel still not fixed

Status in intel-microcode package in Ubuntu:
  Confirmed
Status in linux package in Ubuntu:
  Fix Released
Status in intel-microcode source package in Mantic:
  New
Status in linux source package in Mantic:
  Fix Released

Bug description:
  An pro fix CVE-2022-40982 gives me an ✘ CVE-2022-40982 is not
  resolved. Strangely without a specific description of the affected
  package:

  "1 package is still affected: linux"

  But, when i look up the CVW here: https://ubuntu.com/security/CVE-2022-40982
  it is mentioned that the fix is contained with the new version of intel-microcode: mantic Released (3.20230808.1) And that's the version i seem to have installed:
  apt show intel-microcode:

  "Package: intel-microcode Version: 3.20230808.1"

  Any Ideas on that?

  ProblemType: Bug
  DistroRelease: Ubuntu 23.10
  Package: intel-microcode 3.20230808.1
  ProcVersionSignature: Ubuntu 6.5.0-9.9-generic 6.5.3
  Uname: Linux 6.5.0-9-generic x86_64
  ApportVersion: 2.27.0-0ubuntu5
  Architecture: amd64
  CasperMD5CheckResult: pass
  CurrentDesktop: Unity:Unity7:ubuntu
  Date: Tue Oct 24 16:05:24 2023
  InstallationDate: Installed on 2022-08-05 (445 days ago)
  InstallationMedia: Ubuntu Unity 22.04
  SourcePackage: intel-microcode
  UpgradeStatus: Upgraded to mantic on 2023-10-12 (12 days ago)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/intel-microcode/+bug/2040280/+subscriptions




More information about the foundations-bugs mailing list