← Retour
USN-7833-4
Vulnérabilité dans linux-gcp-6.14 (USN-7833-4)
Résumé
vulnérabilité dans linux-gcp-6.14 (USN-7833-4). Risque d'opérations non autorisées ou de divulgation. Atténuation : mise à jour vers `6.14.0-1018.19~24.04.1` ou plus.
Résumé IA snake-internal / snake-material-v2
Une vulnérabilité référencée **USN-7833-4** a été découverte dans linux-gcp-6.14.
Risque d'opérations non autorisées ou de divulgation. Score CVSS : ?/10.
Action : mettez à jour linux-gcp-6.14 vers **6.14.0-1018.19~24.04.1** ou supérieur.
En cas de doute, contactez votre service informatique ou cherchez « linux-gcp-6.14 USN-7833-4 » sur le site de l'éditeur.
USN-7833-4 (linux-gcp-6.14) —
Correctif : `6.14.0-1018.19~24.04.1` — appliquer immédiatement
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
Une **vulnérabilité** (non classée) affecte linux-gcp-6.14.
📍 Périmètre concerné
linux-gcp-6.14 — .
🔥 Gravité
Gravité : ?. Risque d'opérations non autorisées ou de divulgation
🔧 Comment corriger
Mettre à jour vers **6.14.0-1018.19~24.04.1**.
🛡️ Contournement
En attendant le correctif : désactivez la fonctionnalité concernée, appliquez des règles WAF, ou restreignez l'accès par ACL réseau.
🔍 Détection
Recherchez dans les logs des requêtes correspondant aux IOC connus de cette CVE. Auditez les SBOM/dépendances.
Actions de réponse (7 étapes)
Étapes concrètes et exemples de commandes que les équipes SOC/SRE doivent exécuter dans l'ordre
-
1Identify exposure identify
grep -r 'linux-gcp-6.14' . | grep -v node_modulesリポジトリと本番環境の依存ファイル (package-lock.json / requirements.txt / go.sum / Gemfile.lock 等) で `linux-gcp-6.14` を grep し、稼働しているサービス・バージョンを把握する。
-
6Apply patch patch
Upgrade linux-gcp-6.14 to 6.14.0-1018.19~24.04.1ステージング環境で 6.14.0-1018.19~24.04.1 に上げて回帰テスト → 本番反映。回帰テストはアプリの主要ハッピーパスと、Step 3 で見つけた異常検知の続報チェックを含めること。
-
7Post-deployment verification verify
Confirm patched version is live in productionパッチ適用後、ステージングで PoC または同等の悪用パターンを再現して脆弱性が閉じたことを確認。本番では Step 3 と同じログクエリでアラート再発が無いか継続監視。
Paquets affectés
Ubuntu:24.04:LTS
linux-gcp-6.14
[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.14.0-1018.19~24.04.1"}]}]
Références
- advisory https://ubuntu.com/security/notices/USN-7833-4
- report https://ubuntu.com/security/CVE-2025-38224
- report https://ubuntu.com/security/CVE-2025-38411
- report https://ubuntu.com/security/CVE-2024-36350
- report https://ubuntu.com/security/CVE-2024-36357
- report https://ubuntu.com/security/CVE-2025-38084
- report https://ubuntu.com/security/CVE-2025-38085
- report https://ubuntu.com/security/CVE-2025-38086
- report https://ubuntu.com/security/CVE-2025-38087
- report https://ubuntu.com/security/CVE-2025-38089
- report https://ubuntu.com/security/CVE-2025-38090
- report https://ubuntu.com/security/CVE-2025-38179
- report https://ubuntu.com/security/CVE-2025-38181
- report https://ubuntu.com/security/CVE-2025-38182
- report https://ubuntu.com/security/CVE-2025-38183
- report https://ubuntu.com/security/CVE-2025-38184
- report https://ubuntu.com/security/CVE-2025-38186
- report https://ubuntu.com/security/CVE-2025-38188
- report https://ubuntu.com/security/CVE-2025-38189
- report https://ubuntu.com/security/CVE-2025-38191
- report https://ubuntu.com/security/CVE-2025-38192
- report https://ubuntu.com/security/CVE-2025-38194
- report https://ubuntu.com/security/CVE-2025-38196
- report https://ubuntu.com/security/CVE-2025-38197
- report https://ubuntu.com/security/CVE-2025-38198
- report https://ubuntu.com/security/CVE-2025-38199
- report https://ubuntu.com/security/CVE-2025-38200
- report https://ubuntu.com/security/CVE-2025-38201
- report https://ubuntu.com/security/CVE-2025-38202
- report https://ubuntu.com/security/CVE-2025-38203
- report https://ubuntu.com/security/CVE-2025-38204
- report https://ubuntu.com/security/CVE-2025-38205
- report https://ubuntu.com/security/CVE-2025-38206
- report https://ubuntu.com/security/CVE-2025-38208
- report https://ubuntu.com/security/CVE-2025-38210
- report https://ubuntu.com/security/CVE-2025-38211
- report https://ubuntu.com/security/CVE-2025-38212
- report https://ubuntu.com/security/CVE-2025-38217
- report https://ubuntu.com/security/CVE-2025-38218
- report https://ubuntu.com/security/CVE-2025-38219
- report https://ubuntu.com/security/CVE-2025-38220
- report https://ubuntu.com/security/CVE-2025-38222
- report https://ubuntu.com/security/CVE-2025-38223
- report https://ubuntu.com/security/CVE-2025-38225
- report https://ubuntu.com/security/CVE-2025-38226
- report https://ubuntu.com/security/CVE-2025-38227
- report https://ubuntu.com/security/CVE-2025-38228
- report https://ubuntu.com/security/CVE-2025-38229
- report https://ubuntu.com/security/CVE-2025-38231
- report https://ubuntu.com/security/CVE-2025-38232
- report https://ubuntu.com/security/CVE-2025-38233
- report https://ubuntu.com/security/CVE-2025-38234
- report https://ubuntu.com/security/CVE-2025-38236
- report https://ubuntu.com/security/CVE-2025-38237
- report https://ubuntu.com/security/CVE-2025-38238
- report https://ubuntu.com/security/CVE-2025-38239
- report https://ubuntu.com/security/CVE-2025-38241
- report https://ubuntu.com/security/CVE-2025-38242
- report https://ubuntu.com/security/CVE-2025-38244
- report https://ubuntu.com/security/CVE-2025-38245
- report https://ubuntu.com/security/CVE-2025-38246
- report https://ubuntu.com/security/CVE-2025-38248
- report https://ubuntu.com/security/CVE-2025-38249
- report https://ubuntu.com/security/CVE-2025-38250
- report https://ubuntu.com/security/CVE-2025-38251
- report https://ubuntu.com/security/CVE-2025-38253
- report https://ubuntu.com/security/CVE-2025-38254
- report https://ubuntu.com/security/CVE-2025-38255
- report https://ubuntu.com/security/CVE-2025-38256
- report https://ubuntu.com/security/CVE-2025-38257
- report https://ubuntu.com/security/CVE-2025-38258
- report https://ubuntu.com/security/CVE-2025-38259
- report https://ubuntu.com/security/CVE-2025-38260
- report https://ubuntu.com/security/CVE-2025-38261
- report https://ubuntu.com/security/CVE-2025-38262
- report https://ubuntu.com/security/CVE-2025-38263
- report https://ubuntu.com/security/CVE-2025-38264
- report https://ubuntu.com/security/CVE-2025-38320
- report https://ubuntu.com/security/CVE-2025-38321
- report https://ubuntu.com/security/CVE-2025-38322
- report https://ubuntu.com/security/CVE-2025-38324
- report https://ubuntu.com/security/CVE-2025-38325
- report https://ubuntu.com/security/CVE-2025-38326
- report https://ubuntu.com/security/CVE-2025-38328
- report https://ubuntu.com/security/CVE-2025-38329
- report https://ubuntu.com/security/CVE-2025-38330
- report https://ubuntu.com/security/CVE-2025-38331
- report https://ubuntu.com/security/CVE-2025-38332
- report https://ubuntu.com/security/CVE-2025-38333
- report https://ubuntu.com/security/CVE-2025-38334
- report https://ubuntu.com/security/CVE-2025-38336
- report https://ubuntu.com/security/CVE-2025-38337
- report https://ubuntu.com/security/CVE-2025-38338
- report https://ubuntu.com/security/CVE-2025-38339
- report https://ubuntu.com/security/CVE-2025-38340
- report https://ubuntu.com/security/CVE-2025-38341
- report https://ubuntu.com/security/CVE-2025-38342
- report https://ubuntu.com/security/CVE-2025-38343
- report https://ubuntu.com/security/CVE-2025-38344
- report https://ubuntu.com/security/CVE-2025-38345
- report https://ubuntu.com/security/CVE-2025-38346
- report https://ubuntu.com/security/CVE-2025-38347
- report https://ubuntu.com/security/CVE-2025-38348
- report https://ubuntu.com/security/CVE-2025-38353
- report https://ubuntu.com/security/CVE-2025-38354
- report https://ubuntu.com/security/CVE-2025-38355
- report https://ubuntu.com/security/CVE-2025-38356
- report https://ubuntu.com/security/CVE-2025-38359
- report https://ubuntu.com/security/CVE-2025-38360
- report https://ubuntu.com/security/CVE-2025-38361
- report https://ubuntu.com/security/CVE-2025-38362
- report https://ubuntu.com/security/CVE-2025-38363
- report https://ubuntu.com/security/CVE-2025-38364
- report https://ubuntu.com/security/CVE-2025-38365
- report https://ubuntu.com/security/CVE-2025-38368
- report https://ubuntu.com/security/CVE-2025-38369
- report https://ubuntu.com/security/CVE-2025-38370
- report https://ubuntu.com/security/CVE-2025-38371
- report https://ubuntu.com/security/CVE-2025-38372
- report https://ubuntu.com/security/CVE-2025-38373
- report https://ubuntu.com/security/CVE-2025-38374
- report https://ubuntu.com/security/CVE-2025-38375
- report https://ubuntu.com/security/CVE-2025-38376
- report https://ubuntu.com/security/CVE-2025-38377
- report https://ubuntu.com/security/CVE-2025-38381
- report https://ubuntu.com/security/CVE-2025-38382
- report https://ubuntu.com/security/CVE-2025-38383
- report https://ubuntu.com/security/CVE-2025-38384
- report https://ubuntu.com/security/CVE-2025-38385
- report https://ubuntu.com/security/CVE-2025-38386
- report https://ubuntu.com/security/CVE-2025-38387
- report https://ubuntu.com/security/CVE-2025-38388
- report https://ubuntu.com/security/CVE-2025-38389
- report https://ubuntu.com/security/CVE-2025-38390
- report https://ubuntu.com/security/CVE-2025-38391
- report https://ubuntu.com/security/CVE-2025-38392
- report https://ubuntu.com/security/CVE-2025-38393
- report https://ubuntu.com/security/CVE-2025-38395
- report https://ubuntu.com/security/CVE-2025-38396
- report https://ubuntu.com/security/CVE-2025-38399
- report https://ubuntu.com/security/CVE-2025-38400
- report https://ubuntu.com/security/CVE-2025-38401
- report https://ubuntu.com/security/CVE-2025-38402
- report https://ubuntu.com/security/CVE-2025-38403
- report https://ubuntu.com/security/CVE-2025-38405
- report https://ubuntu.com/security/CVE-2025-38406
- report https://ubuntu.com/security/CVE-2025-38407
- report https://ubuntu.com/security/CVE-2025-38408
- report https://ubuntu.com/security/CVE-2025-38409
- report https://ubuntu.com/security/CVE-2025-38410
- report https://ubuntu.com/security/CVE-2025-38412
- report https://ubuntu.com/security/CVE-2025-38413
- report https://ubuntu.com/security/CVE-2025-38416
- report https://ubuntu.com/security/CVE-2025-38417
- report https://ubuntu.com/security/CVE-2025-38418
- report https://ubuntu.com/security/CVE-2025-38419
- report https://ubuntu.com/security/CVE-2025-38420
- report https://ubuntu.com/security/CVE-2025-38421
- report https://ubuntu.com/security/CVE-2025-38422
- report https://ubuntu.com/security/CVE-2025-38423
- report https://ubuntu.com/security/CVE-2025-38424
- report https://ubuntu.com/security/CVE-2025-38425
- report https://ubuntu.com/security/CVE-2025-38426
- report https://ubuntu.com/security/CVE-2025-38427
- report https://ubuntu.com/security/CVE-2025-38428
- report https://ubuntu.com/security/CVE-2025-38429
- report https://ubuntu.com/security/CVE-2025-38430
- report https://ubuntu.com/security/CVE-2025-38431
- report https://ubuntu.com/security/CVE-2025-38434
- report https://ubuntu.com/security/CVE-2025-38435
- report https://ubuntu.com/security/CVE-2025-38436
- report https://ubuntu.com/security/CVE-2025-38523
- report https://ubuntu.com/security/CVE-2025-38541
- report https://ubuntu.com/security/CVE-2025-39682