← Retour
USN-7769-3
Vulnérabilité dans linux-aws-6.14 (USN-7769-3)
Résumé
vulnérabilité dans linux-aws-6.14 (USN-7769-3). Risque d'opérations non autorisées ou de divulgation. Atténuation : mise à jour vers `6.14.0-1013.13~24.04.1` ou plus.
Résumé IA snake-internal / snake-material-v2
Une vulnérabilité référencée **USN-7769-3** a été découverte dans linux-aws-6.14.
Risque d'opérations non autorisées ou de divulgation. Score CVSS : ?/10.
Action : mettez à jour linux-aws-6.14 vers **6.14.0-1013.13~24.04.1** ou supérieur.
En cas de doute, contactez votre service informatique ou cherchez « linux-aws-6.14 USN-7769-3 » sur le site de l'éditeur.
USN-7769-3 (linux-aws-6.14) —
Correctif : `6.14.0-1013.13~24.04.1` — appliquer immédiatement
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
Une **vulnérabilité** (non classée) affecte linux-aws-6.14.
📍 Périmètre concerné
linux-aws-6.14 — .
🔥 Gravité
Gravité : ?. Risque d'opérations non autorisées ou de divulgation
🔧 Comment corriger
Mettre à jour vers **6.14.0-1013.13~24.04.1**.
🛡️ Contournement
En attendant le correctif : désactivez la fonctionnalité concernée, appliquez des règles WAF, ou restreignez l'accès par ACL réseau.
🔍 Détection
Recherchez dans les logs des requêtes correspondant aux IOC connus de cette CVE. Auditez les SBOM/dépendances.
Actions de réponse (7 étapes)
Étapes concrètes et exemples de commandes que les équipes SOC/SRE doivent exécuter dans l'ordre
-
1Identify exposure identify
grep -r 'linux-aws-6.14' . | grep -v node_modulesリポジトリと本番環境の依存ファイル (package-lock.json / requirements.txt / go.sum / Gemfile.lock 等) で `linux-aws-6.14` を grep し、稼働しているサービス・バージョンを把握する。
-
6Apply patch patch
Upgrade linux-aws-6.14 to 6.14.0-1013.13~24.04.1ステージング環境で 6.14.0-1013.13~24.04.1 に上げて回帰テスト → 本番反映。回帰テストはアプリの主要ハッピーパスと、Step 3 で見つけた異常検知の続報チェックを含めること。
-
7Post-deployment verification verify
Confirm patched version is live in productionパッチ適用後、ステージングで PoC または同等の悪用パターンを再現して脆弱性が閉じたことを確認。本番では Step 3 と同じログクエリでアラート再発が無いか継続監視。
Paquets affectés
Ubuntu:24.04:LTS
linux-aws-6.14
[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.14.0-1013.13~24.04.1"}]}]
Ubuntu:24.04:LTS
linux-hwe-6.14
[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.14.0-32.32~24.04.1"}]}]
Références
- advisory https://ubuntu.com/security/notices/USN-7769-3
- report https://ubuntu.com/security/CVE-2025-38073
- report https://ubuntu.com/security/CVE-2025-38003
- report https://ubuntu.com/security/CVE-2025-38004
- report https://ubuntu.com/security/CVE-2025-38029
- report https://ubuntu.com/security/CVE-2025-38031
- report https://ubuntu.com/security/CVE-2025-38032
- report https://ubuntu.com/security/CVE-2025-38033
- report https://ubuntu.com/security/CVE-2025-38034
- report https://ubuntu.com/security/CVE-2025-38035
- report https://ubuntu.com/security/CVE-2025-38036
- report https://ubuntu.com/security/CVE-2025-38037
- report https://ubuntu.com/security/CVE-2025-38038
- report https://ubuntu.com/security/CVE-2025-38039
- report https://ubuntu.com/security/CVE-2025-38040
- report https://ubuntu.com/security/CVE-2025-38041
- report https://ubuntu.com/security/CVE-2025-38042
- report https://ubuntu.com/security/CVE-2025-38043
- report https://ubuntu.com/security/CVE-2025-38044
- report https://ubuntu.com/security/CVE-2025-38045
- report https://ubuntu.com/security/CVE-2025-38047
- report https://ubuntu.com/security/CVE-2025-38048
- report https://ubuntu.com/security/CVE-2025-38050
- report https://ubuntu.com/security/CVE-2025-38051
- report https://ubuntu.com/security/CVE-2025-38052
- report https://ubuntu.com/security/CVE-2025-38053
- report https://ubuntu.com/security/CVE-2025-38054
- report https://ubuntu.com/security/CVE-2025-38055
- report https://ubuntu.com/security/CVE-2025-38057
- report https://ubuntu.com/security/CVE-2025-38058
- report https://ubuntu.com/security/CVE-2025-38059
- report https://ubuntu.com/security/CVE-2025-38060
- report https://ubuntu.com/security/CVE-2025-38061
- report https://ubuntu.com/security/CVE-2025-38062
- report https://ubuntu.com/security/CVE-2025-38063
- report https://ubuntu.com/security/CVE-2025-38064
- report https://ubuntu.com/security/CVE-2025-38065
- report https://ubuntu.com/security/CVE-2025-38066
- report https://ubuntu.com/security/CVE-2025-38067
- report https://ubuntu.com/security/CVE-2025-38068
- report https://ubuntu.com/security/CVE-2025-38069
- report https://ubuntu.com/security/CVE-2025-38070
- report https://ubuntu.com/security/CVE-2025-38071
- report https://ubuntu.com/security/CVE-2025-38072
- report https://ubuntu.com/security/CVE-2025-38074
- report https://ubuntu.com/security/CVE-2025-38075
- report https://ubuntu.com/security/CVE-2025-38076
- report https://ubuntu.com/security/CVE-2025-38077
- report https://ubuntu.com/security/CVE-2025-38078
- report https://ubuntu.com/security/CVE-2025-38079
- report https://ubuntu.com/security/CVE-2025-38080
- report https://ubuntu.com/security/CVE-2025-38081
- report https://ubuntu.com/security/CVE-2025-38082
- report https://ubuntu.com/security/CVE-2025-38088
- report https://ubuntu.com/security/CVE-2025-38091
- report https://ubuntu.com/security/CVE-2025-38092
- report https://ubuntu.com/security/CVE-2025-38096
- report https://ubuntu.com/security/CVE-2025-38097
- report https://ubuntu.com/security/CVE-2025-38098
- report https://ubuntu.com/security/CVE-2025-38099
- report https://ubuntu.com/security/CVE-2025-38100
- report https://ubuntu.com/security/CVE-2025-38101
- report https://ubuntu.com/security/CVE-2025-38102
- report https://ubuntu.com/security/CVE-2025-38103
- report https://ubuntu.com/security/CVE-2025-38105
- report https://ubuntu.com/security/CVE-2025-38106
- report https://ubuntu.com/security/CVE-2025-38107
- report https://ubuntu.com/security/CVE-2025-38108
- report https://ubuntu.com/security/CVE-2025-38109
- report https://ubuntu.com/security/CVE-2025-38110
- report https://ubuntu.com/security/CVE-2025-38111
- report https://ubuntu.com/security/CVE-2025-38112
- report https://ubuntu.com/security/CVE-2025-38113
- report https://ubuntu.com/security/CVE-2025-38114
- report https://ubuntu.com/security/CVE-2025-38115
- report https://ubuntu.com/security/CVE-2025-38116
- report https://ubuntu.com/security/CVE-2025-38117
- report https://ubuntu.com/security/CVE-2025-38118
- report https://ubuntu.com/security/CVE-2025-38119
- report https://ubuntu.com/security/CVE-2025-38120
- report https://ubuntu.com/security/CVE-2025-38122
- report https://ubuntu.com/security/CVE-2025-38123
- report https://ubuntu.com/security/CVE-2025-38124
- report https://ubuntu.com/security/CVE-2025-38125
- report https://ubuntu.com/security/CVE-2025-38126
- report https://ubuntu.com/security/CVE-2025-38127
- report https://ubuntu.com/security/CVE-2025-38128
- report https://ubuntu.com/security/CVE-2025-38129
- report https://ubuntu.com/security/CVE-2025-38130
- report https://ubuntu.com/security/CVE-2025-38131
- report https://ubuntu.com/security/CVE-2025-38132
- report https://ubuntu.com/security/CVE-2025-38134
- report https://ubuntu.com/security/CVE-2025-38135
- report https://ubuntu.com/security/CVE-2025-38136
- report https://ubuntu.com/security/CVE-2025-38137
- report https://ubuntu.com/security/CVE-2025-38138
- report https://ubuntu.com/security/CVE-2025-38139
- report https://ubuntu.com/security/CVE-2025-38140
- report https://ubuntu.com/security/CVE-2025-38141
- report https://ubuntu.com/security/CVE-2025-38142
- report https://ubuntu.com/security/CVE-2025-38143
- report https://ubuntu.com/security/CVE-2025-38145
- report https://ubuntu.com/security/CVE-2025-38146
- report https://ubuntu.com/security/CVE-2025-38147
- report https://ubuntu.com/security/CVE-2025-38148
- report https://ubuntu.com/security/CVE-2025-38149
- report https://ubuntu.com/security/CVE-2025-38151
- report https://ubuntu.com/security/CVE-2025-38153
- report https://ubuntu.com/security/CVE-2025-38154
- report https://ubuntu.com/security/CVE-2025-38155
- report https://ubuntu.com/security/CVE-2025-38156
- report https://ubuntu.com/security/CVE-2025-38157
- report https://ubuntu.com/security/CVE-2025-38158
- report https://ubuntu.com/security/CVE-2025-38159
- report https://ubuntu.com/security/CVE-2025-38160
- report https://ubuntu.com/security/CVE-2025-38161
- report https://ubuntu.com/security/CVE-2025-38162
- report https://ubuntu.com/security/CVE-2025-38163
- report https://ubuntu.com/security/CVE-2025-38164
- report https://ubuntu.com/security/CVE-2025-38165
- report https://ubuntu.com/security/CVE-2025-38166
- report https://ubuntu.com/security/CVE-2025-38167
- report https://ubuntu.com/security/CVE-2025-38168
- report https://ubuntu.com/security/CVE-2025-38169
- report https://ubuntu.com/security/CVE-2025-38170
- report https://ubuntu.com/security/CVE-2025-38172
- report https://ubuntu.com/security/CVE-2025-38173
- report https://ubuntu.com/security/CVE-2025-38174
- report https://ubuntu.com/security/CVE-2025-38175
- report https://ubuntu.com/security/CVE-2025-38176
- report https://ubuntu.com/security/CVE-2025-38265
- report https://ubuntu.com/security/CVE-2025-38267
- report https://ubuntu.com/security/CVE-2025-38268
- report https://ubuntu.com/security/CVE-2025-38269
- report https://ubuntu.com/security/CVE-2025-38270
- report https://ubuntu.com/security/CVE-2025-38272
- report https://ubuntu.com/security/CVE-2025-38274
- report https://ubuntu.com/security/CVE-2025-38275
- report https://ubuntu.com/security/CVE-2025-38277
- report https://ubuntu.com/security/CVE-2025-38278
- report https://ubuntu.com/security/CVE-2025-38279
- report https://ubuntu.com/security/CVE-2025-38280
- report https://ubuntu.com/security/CVE-2025-38281
- report https://ubuntu.com/security/CVE-2025-38282
- report https://ubuntu.com/security/CVE-2025-38283
- report https://ubuntu.com/security/CVE-2025-38284
- report https://ubuntu.com/security/CVE-2025-38285
- report https://ubuntu.com/security/CVE-2025-38286
- report https://ubuntu.com/security/CVE-2025-38287
- report https://ubuntu.com/security/CVE-2025-38288
- report https://ubuntu.com/security/CVE-2025-38289
- report https://ubuntu.com/security/CVE-2025-38290
- report https://ubuntu.com/security/CVE-2025-38291
- report https://ubuntu.com/security/CVE-2025-38292
- report https://ubuntu.com/security/CVE-2025-38293
- report https://ubuntu.com/security/CVE-2025-38294
- report https://ubuntu.com/security/CVE-2025-38295
- report https://ubuntu.com/security/CVE-2025-38296
- report https://ubuntu.com/security/CVE-2025-38297
- report https://ubuntu.com/security/CVE-2025-38298
- report https://ubuntu.com/security/CVE-2025-38299
- report https://ubuntu.com/security/CVE-2025-38300
- report https://ubuntu.com/security/CVE-2025-38301
- report https://ubuntu.com/security/CVE-2025-38302
- report https://ubuntu.com/security/CVE-2025-38303
- report https://ubuntu.com/security/CVE-2025-38304
- report https://ubuntu.com/security/CVE-2025-38305
- report https://ubuntu.com/security/CVE-2025-38306
- report https://ubuntu.com/security/CVE-2025-38307
- report https://ubuntu.com/security/CVE-2025-38310
- report https://ubuntu.com/security/CVE-2025-38311
- report https://ubuntu.com/security/CVE-2025-38312
- report https://ubuntu.com/security/CVE-2025-38313
- report https://ubuntu.com/security/CVE-2025-38314
- report https://ubuntu.com/security/CVE-2025-38315
- report https://ubuntu.com/security/CVE-2025-38316
- report https://ubuntu.com/security/CVE-2025-38317
- report https://ubuntu.com/security/CVE-2025-38318
- report https://ubuntu.com/security/CVE-2025-38319
- report https://ubuntu.com/security/CVE-2025-38352
- report https://ubuntu.com/security/CVE-2025-38414
- report https://ubuntu.com/security/CVE-2025-38415
- report https://ubuntu.com/security/CVE-2025-38498
- report https://ubuntu.com/security/CVE-2025-38499
- report https://ubuntu.com/security/CVE-2025-39890