← Retour
USN-8094-4
Vulnérabilité dans linux-azure-6.17 (USN-8094-4)
Résumé
vulnérabilité dans linux-azure-6.17 (USN-8094-4). Risque d'opérations non autorisées ou de divulgation. Atténuation : mise à jour vers `6.17.0-1010.10~24.04.1` ou plus.
Résumé IA snake-internal / snake-material-v2
Une vulnérabilité référencée **USN-8094-4** a été découverte dans linux-azure-6.17.
Risque d'opérations non autorisées ou de divulgation. Score CVSS : ?/10.
Action : mettez à jour linux-azure-6.17 vers **6.17.0-1010.10~24.04.1** ou supérieur.
En cas de doute, contactez votre service informatique ou cherchez « linux-azure-6.17 USN-8094-4 » sur le site de l'éditeur.
USN-8094-4 (linux-azure-6.17) —
Correctif : `6.17.0-1010.10~24.04.1` — appliquer immédiatement
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
Une **vulnérabilité** (non classée) affecte linux-azure-6.17.
📍 Périmètre concerné
linux-azure-6.17 — .
🔥 Gravité
Gravité : ?. Risque d'opérations non autorisées ou de divulgation
🔧 Comment corriger
Mettre à jour vers **6.17.0-1010.10~24.04.1**.
🛡️ Contournement
En attendant le correctif : désactivez la fonctionnalité concernée, appliquez des règles WAF, ou restreignez l'accès par ACL réseau.
🔍 Détection
Recherchez dans les logs des requêtes correspondant aux IOC connus de cette CVE. Auditez les SBOM/dépendances.
Actions de réponse (7 étapes)
Étapes concrètes et exemples de commandes que les équipes SOC/SRE doivent exécuter dans l'ordre
-
1Identify exposure identify
grep -r 'linux-azure-6.17' . | grep -v node_modulesリポジトリと本番環境の依存ファイル (package-lock.json / requirements.txt / go.sum / Gemfile.lock 等) で `linux-azure-6.17` を grep し、稼働しているサービス・バージョンを把握する。
-
6Apply patch patch
Upgrade linux-azure-6.17 to 6.17.0-1010.10~24.04.1ステージング環境で 6.17.0-1010.10~24.04.1 に上げて回帰テスト → 本番反映。回帰テストはアプリの主要ハッピーパスと、Step 3 で見つけた異常検知の続報チェックを含めること。
-
7Post-deployment verification verify
Confirm patched version is live in productionパッチ適用後、ステージングで PoC または同等の悪用パターンを再現して脆弱性が閉じたことを確認。本番では Step 3 と同じログクエリでアラート再発が無いか継続監視。
Paquets affectés
Ubuntu:24.04:LTS
linux-azure-6.17
[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.17.0-1010.10~24.04.1"}]}]
Ubuntu:25.10
linux-azure
[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.17.0-1010.10"}]}]
Références
- advisory https://ubuntu.com/security/notices/USN-8094-4
- report https://ubuntu.com/security/CVE-2025-68299
- report https://ubuntu.com/security/CVE-2025-68300
- report https://launchpad.net/bugs/2143853
- report https://ubuntu.com/security/CVE-2025-40246
- report https://ubuntu.com/security/CVE-2025-40247
- report https://ubuntu.com/security/CVE-2025-40248
- report https://ubuntu.com/security/CVE-2025-40249
- report https://ubuntu.com/security/CVE-2025-40250
- report https://ubuntu.com/security/CVE-2025-40251
- report https://ubuntu.com/security/CVE-2025-40252
- report https://ubuntu.com/security/CVE-2025-40253
- report https://ubuntu.com/security/CVE-2025-40254
- report https://ubuntu.com/security/CVE-2025-40255
- report https://ubuntu.com/security/CVE-2025-40257
- report https://ubuntu.com/security/CVE-2025-40258
- report https://ubuntu.com/security/CVE-2025-40259
- report https://ubuntu.com/security/CVE-2025-40260
- report https://ubuntu.com/security/CVE-2025-40261
- report https://ubuntu.com/security/CVE-2025-40262
- report https://ubuntu.com/security/CVE-2025-40263
- report https://ubuntu.com/security/CVE-2025-40264
- report https://ubuntu.com/security/CVE-2025-40265
- report https://ubuntu.com/security/CVE-2025-40266
- report https://ubuntu.com/security/CVE-2025-40290
- report https://ubuntu.com/security/CVE-2025-40345
- report https://ubuntu.com/security/CVE-2025-62626
- report https://ubuntu.com/security/CVE-2025-68212
- report https://ubuntu.com/security/CVE-2025-68213
- report https://ubuntu.com/security/CVE-2025-68214
- report https://ubuntu.com/security/CVE-2025-68215
- report https://ubuntu.com/security/CVE-2025-68217
- report https://ubuntu.com/security/CVE-2025-68218
- report https://ubuntu.com/security/CVE-2025-68219
- report https://ubuntu.com/security/CVE-2025-68220
- report https://ubuntu.com/security/CVE-2025-68221
- report https://ubuntu.com/security/CVE-2025-68222
- report https://ubuntu.com/security/CVE-2025-68223
- report https://ubuntu.com/security/CVE-2025-68225
- report https://ubuntu.com/security/CVE-2025-68227
- report https://ubuntu.com/security/CVE-2025-68228
- report https://ubuntu.com/security/CVE-2025-68229
- report https://ubuntu.com/security/CVE-2025-68230
- report https://ubuntu.com/security/CVE-2025-68231
- report https://ubuntu.com/security/CVE-2025-68232
- report https://ubuntu.com/security/CVE-2025-68233
- report https://ubuntu.com/security/CVE-2025-68234
- report https://ubuntu.com/security/CVE-2025-68235
- report https://ubuntu.com/security/CVE-2025-68236
- report https://ubuntu.com/security/CVE-2025-68237
- report https://ubuntu.com/security/CVE-2025-68238
- report https://ubuntu.com/security/CVE-2025-68254
- report https://ubuntu.com/security/CVE-2025-68255
- report https://ubuntu.com/security/CVE-2025-68256
- report https://ubuntu.com/security/CVE-2025-68257
- report https://ubuntu.com/security/CVE-2025-68258
- report https://ubuntu.com/security/CVE-2025-68259
- report https://ubuntu.com/security/CVE-2025-68261
- report https://ubuntu.com/security/CVE-2025-68262
- report https://ubuntu.com/security/CVE-2025-68263
- report https://ubuntu.com/security/CVE-2025-68264
- report https://ubuntu.com/security/CVE-2025-68265
- report https://ubuntu.com/security/CVE-2025-68266
- report https://ubuntu.com/security/CVE-2025-68281
- report https://ubuntu.com/security/CVE-2025-68282
- report https://ubuntu.com/security/CVE-2025-68283
- report https://ubuntu.com/security/CVE-2025-68284
- report https://ubuntu.com/security/CVE-2025-68285
- report https://ubuntu.com/security/CVE-2025-68286
- report https://ubuntu.com/security/CVE-2025-68287
- report https://ubuntu.com/security/CVE-2025-68288
- report https://ubuntu.com/security/CVE-2025-68289
- report https://ubuntu.com/security/CVE-2025-68290
- report https://ubuntu.com/security/CVE-2025-68292
- report https://ubuntu.com/security/CVE-2025-68293
- report https://ubuntu.com/security/CVE-2025-68294
- report https://ubuntu.com/security/CVE-2025-68295
- report https://ubuntu.com/security/CVE-2025-68296
- report https://ubuntu.com/security/CVE-2025-68297
- report https://ubuntu.com/security/CVE-2025-68298
- report https://ubuntu.com/security/CVE-2025-68301
- report https://ubuntu.com/security/CVE-2025-68302
- report https://ubuntu.com/security/CVE-2025-68303
- report https://ubuntu.com/security/CVE-2025-68304
- report https://ubuntu.com/security/CVE-2025-68305
- report https://ubuntu.com/security/CVE-2025-68306
- report https://ubuntu.com/security/CVE-2025-68307
- report https://ubuntu.com/security/CVE-2025-68308
- report https://ubuntu.com/security/CVE-2025-68323
- report https://ubuntu.com/security/CVE-2025-68324
- report https://ubuntu.com/security/CVE-2025-68325
- report https://ubuntu.com/security/CVE-2025-68326
- report https://ubuntu.com/security/CVE-2025-68327
- report https://ubuntu.com/security/CVE-2025-68328
- report https://ubuntu.com/security/CVE-2025-68329
- report https://ubuntu.com/security/CVE-2025-68330
- report https://ubuntu.com/security/CVE-2025-68331
- report https://ubuntu.com/security/CVE-2025-68332
- report https://ubuntu.com/security/CVE-2025-68333
- report https://ubuntu.com/security/CVE-2025-68334
- report https://ubuntu.com/security/CVE-2025-68335
- report https://ubuntu.com/security/CVE-2025-68336
- report https://ubuntu.com/security/CVE-2025-68337
- report https://ubuntu.com/security/CVE-2025-68338
- report https://ubuntu.com/security/CVE-2025-68339
- report https://ubuntu.com/security/CVE-2025-68340
- report https://ubuntu.com/security/CVE-2025-68341
- report https://ubuntu.com/security/CVE-2025-68342
- report https://ubuntu.com/security/CVE-2025-68343
- report https://ubuntu.com/security/CVE-2025-68344
- report https://ubuntu.com/security/CVE-2025-68345
- report https://ubuntu.com/security/CVE-2025-68346
- report https://ubuntu.com/security/CVE-2025-68347
- report https://ubuntu.com/security/CVE-2025-68348
- report https://ubuntu.com/security/CVE-2025-68349
- report https://ubuntu.com/security/CVE-2025-68352
- report https://ubuntu.com/security/CVE-2025-68354
- report https://ubuntu.com/security/CVE-2025-68356
- report https://ubuntu.com/security/CVE-2025-68358
- report https://ubuntu.com/security/CVE-2025-68359
- report https://ubuntu.com/security/CVE-2025-68360
- report https://ubuntu.com/security/CVE-2025-68361
- report https://ubuntu.com/security/CVE-2025-68362
- report https://ubuntu.com/security/CVE-2025-68363
- report https://ubuntu.com/security/CVE-2025-68364
- report https://ubuntu.com/security/CVE-2025-68366
- report https://ubuntu.com/security/CVE-2025-68367
- report https://ubuntu.com/security/CVE-2025-68369
- report https://ubuntu.com/security/CVE-2025-68370
- report https://ubuntu.com/security/CVE-2025-68371
- report https://ubuntu.com/security/CVE-2025-68372
- report https://ubuntu.com/security/CVE-2025-68373
- report https://ubuntu.com/security/CVE-2025-68374
- report https://ubuntu.com/security/CVE-2025-68375
- report https://ubuntu.com/security/CVE-2025-68376
- report https://ubuntu.com/security/CVE-2025-68378
- report https://ubuntu.com/security/CVE-2025-68379
- report https://ubuntu.com/security/CVE-2025-68380
- report https://ubuntu.com/security/CVE-2025-68724
- report https://ubuntu.com/security/CVE-2025-68726
- report https://ubuntu.com/security/CVE-2025-68727
- report https://ubuntu.com/security/CVE-2025-68728
- report https://ubuntu.com/security/CVE-2025-68729
- report https://ubuntu.com/security/CVE-2025-68730
- report https://ubuntu.com/security/CVE-2025-68732
- report https://ubuntu.com/security/CVE-2025-68733
- report https://ubuntu.com/security/CVE-2025-68735
- report https://ubuntu.com/security/CVE-2025-68738
- report https://ubuntu.com/security/CVE-2025-68739
- report https://ubuntu.com/security/CVE-2025-68740
- report https://ubuntu.com/security/CVE-2025-68741
- report https://ubuntu.com/security/CVE-2025-68742
- report https://ubuntu.com/security/CVE-2025-68743
- report https://ubuntu.com/security/CVE-2025-68744
- report https://ubuntu.com/security/CVE-2025-68746
- report https://ubuntu.com/security/CVE-2025-68747
- report https://ubuntu.com/security/CVE-2025-68748
- report https://ubuntu.com/security/CVE-2025-68749
- report https://ubuntu.com/security/CVE-2025-68751
- report https://ubuntu.com/security/CVE-2025-68752
- report https://ubuntu.com/security/CVE-2025-68753
- report https://ubuntu.com/security/CVE-2025-68754
- report https://ubuntu.com/security/CVE-2025-68755
- report https://ubuntu.com/security/CVE-2025-68756
- report https://ubuntu.com/security/CVE-2025-68757
- report https://ubuntu.com/security/CVE-2025-68758
- report https://ubuntu.com/security/CVE-2025-68759
- report https://ubuntu.com/security/CVE-2025-68760
- report https://ubuntu.com/security/CVE-2025-68762
- report https://ubuntu.com/security/CVE-2025-68763
- report https://ubuntu.com/security/CVE-2025-68764
- report https://ubuntu.com/security/CVE-2025-68765
- report https://ubuntu.com/security/CVE-2025-68766
- report https://ubuntu.com/security/CVE-2025-71128