First published: Thu Nov 23 2023(Updated: )
It was discovered that the OpenZFS sharenfs feature incorrectly handled IPv6 address data. This could result in IPv6 restrictions not being applied, contrary to expectations.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libuutil3linux | <2.1.9-2ubuntu1.2 | 2.1.9-2ubuntu1.2 |
Ubuntu Ubuntu | =23.04 | |
All of | ||
ubuntu/zfsutils-linux | <2.1.9-2ubuntu1.2 | 2.1.9-2ubuntu1.2 |
Ubuntu Ubuntu | =23.04 | |
All of | ||
ubuntu/libuutil3linux | <2.1.5-1ubuntu6~22.04.2 | 2.1.5-1ubuntu6~22.04.2 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/zfsutils-linux | <2.1.5-1ubuntu6~22.04.2 | 2.1.5-1ubuntu6~22.04.2 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/libuutil1linux | <0.8.3-1ubuntu12.16 | 0.8.3-1ubuntu12.16 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/zfsutils-linux | <0.8.3-1ubuntu12.16 | 0.8.3-1ubuntu12.16 |
Ubuntu Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability in USN-6511-1 is an OpenZFS vulnerability that incorrectly handles IPv6 address data.
The vulnerability in USN-6511-1 could result in IPv6 restrictions not being applied as expected.
The software versions affected by the vulnerability in USN-6511-1 are libuutil3linux 2.1.9-2ubuntu1.2 and zfsutils-linux 2.1.9-2ubuntu1.2 on Ubuntu 23.04, libuutil3linux 2.1.5-1ubuntu6~22.04.2 and zfsutils-linux 2.1.5-1ubuntu6~22.04.2 on Ubuntu 22.04, and libuutil1linux 0.8.3-1ubuntu12.16 and zfsutils-linux 0.8.3-1ubuntu12.16 on Ubuntu 20.04.
To fix the vulnerability in USN-6511-1, you need to update the affected software packages to their respective fixed versions: libuutil3linux 2.1.9-2ubuntu1.2 and zfsutils-linux 2.1.9-2ubuntu1.2 on Ubuntu 23.04, libuutil3linux 2.1.5-1ubuntu6~22.04.2 and zfsutils-linux 2.1.5-1ubuntu6~22.04.2 on Ubuntu 22.04, and libuutil1linux 0.8.3-1ubuntu12.16 and zfsutils-linux 0.8.3-1ubuntu12.16 on Ubuntu 20.04.
You can find more information about the vulnerability in USN-6511-1 on the Ubuntu Security Notices website (CVE-2013-20001) and the respective launchpad.net pages for the fixed versions of the affected software packages.