▲ 96 ▼ Canonical Says Ubuntu Infrastructure Is Facing Cross-Border DDoS Attack (linuxiac.com) submitted 4 months ago by cm0002@lemy.lol to c/linux@programming.dev 14 comments fedilink hide all child comments
[–] ZombieCyborgFromOuterSpace@piefed.ca 27 points 4 months ago (2 children) This hatred for Snaps is getting out of hand. permalink fedilink source hideshow 4 child comments replies: [–] Skyline969@piefed.ca 24 points 4 months ago (2 children) Ubuntu is one of the most used distros in both desktop and server environments. Take down the update servers, can’t patch CopyFail. Can’t patch CopyFail, more time to access affected systems. That’s my paranoid take anyway. permalink fedilink source parent hideshow 4 child comments replies: [–] kamstrup@programming.dev 11 points 4 months ago (3 children) Normally patches roll out before the vulnerability is disclosed. But I honestly don't know the status on CopyFail permalink fedilink source parent hideshow 6 child comments replies: [–] Jesus_666@lemmy.world 7 points 4 months ago (2 children) Most distros delivered patched kernels well before the vulnerability was publicly disclosed. Not sure if Ubuntu did but they had ample time to do so. permalink fedilink source parent hideshow 4 child comments replies: [–] lengau@midwest.social 5 points 4 months ago (1 child) Not true. None of the major distros were alerted and Ubuntu, Debian, RHEL, etc. were all struggling at the last minute. See: https://infosec.exchange/@wdormann/116489443704631952 However, none of those DDoS's took out the archive servers, so Ubuntu users could still get new kernels. permalink fedilink source parent hideshow 2 child comments replies: [–] Jesus_666@lemmy.world 3 points 4 months ago (1 child) Interesting. So only the fast distros were done patching by time of disclosure. The ones you wouldn't run a server on. Because only the kernel devs better informed. That's... pretty amateurish from the guys who discovered CopyFail. permalink fedilink source parent hideshow 2 child comments replies: [–] lengau@midwest.social 5 points 4 months ago Even then, some of the upstream LTS kernels didn't get the patch until the 30th. permalink fedilink source parent [–] Successful_Try543@feddit.org 4 points 4 months ago* Ubuntu 26.04 has already been patched, but not the older (LTS) releases. https://ubuntu.com/security/CVE-2026-31431 permalink fedilink source parent [–] lengau@midwest.social 3 points 4 months ago The people who found the vulnerability didn't do proper coordinated disclosure. See: https://infosec.exchange/@wdormann/116489443704631952 permalink fedilink source parent [–] Miaou@jlai.lu 2 points 4 months ago The Debian Bookworm fix was only rolled out last night. Bookworm was not directly affected though, so maybe that's why it took a bit more time permalink fedilink source parent [+] poinck@lemmy.world 3 points 4 months ago* (last edited 1 month ago) (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] Successful_Try543@feddit.org 1 point 4 months ago (1 child) Does Ubuntu, like Debian, make you choose a repository mirror during the installation? permalink fedilink source parent hideshow 2 child comments replies: [–] lengau@midwest.social 2 points 4 months ago Typically they use archive.ubuntu.com, which was not affected. permalink fedilink source parent [–] unexposedhazard@discuss.tchncs.de 3 points 4 months ago Add to that the recent announcement about adding AI poop to the OS. permalink fedilink source parent
[–] Skyline969@piefed.ca 24 points 4 months ago (2 children) Ubuntu is one of the most used distros in both desktop and server environments. Take down the update servers, can’t patch CopyFail. Can’t patch CopyFail, more time to access affected systems. That’s my paranoid take anyway. permalink fedilink source parent hideshow 4 child comments replies: [–] kamstrup@programming.dev 11 points 4 months ago (3 children) Normally patches roll out before the vulnerability is disclosed. But I honestly don't know the status on CopyFail permalink fedilink source parent hideshow 6 child comments replies: [–] Jesus_666@lemmy.world 7 points 4 months ago (2 children) Most distros delivered patched kernels well before the vulnerability was publicly disclosed. Not sure if Ubuntu did but they had ample time to do so. permalink fedilink source parent hideshow 4 child comments replies: [–] lengau@midwest.social 5 points 4 months ago (1 child) Not true. None of the major distros were alerted and Ubuntu, Debian, RHEL, etc. were all struggling at the last minute. See: https://infosec.exchange/@wdormann/116489443704631952 However, none of those DDoS's took out the archive servers, so Ubuntu users could still get new kernels. permalink fedilink source parent hideshow 2 child comments replies: [–] Jesus_666@lemmy.world 3 points 4 months ago (1 child) Interesting. So only the fast distros were done patching by time of disclosure. The ones you wouldn't run a server on. Because only the kernel devs better informed. That's... pretty amateurish from the guys who discovered CopyFail. permalink fedilink source parent hideshow 2 child comments replies: [–] lengau@midwest.social 5 points 4 months ago Even then, some of the upstream LTS kernels didn't get the patch until the 30th. permalink fedilink source parent [–] Successful_Try543@feddit.org 4 points 4 months ago* Ubuntu 26.04 has already been patched, but not the older (LTS) releases. https://ubuntu.com/security/CVE-2026-31431 permalink fedilink source parent [–] lengau@midwest.social 3 points 4 months ago The people who found the vulnerability didn't do proper coordinated disclosure. See: https://infosec.exchange/@wdormann/116489443704631952 permalink fedilink source parent [–] Miaou@jlai.lu 2 points 4 months ago The Debian Bookworm fix was only rolled out last night. Bookworm was not directly affected though, so maybe that's why it took a bit more time permalink fedilink source parent [+] poinck@lemmy.world 3 points 4 months ago* (last edited 1 month ago) (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] Successful_Try543@feddit.org 1 point 4 months ago (1 child) Does Ubuntu, like Debian, make you choose a repository mirror during the installation? permalink fedilink source parent hideshow 2 child comments replies: [–] lengau@midwest.social 2 points 4 months ago Typically they use archive.ubuntu.com, which was not affected. permalink fedilink source parent
[–] kamstrup@programming.dev 11 points 4 months ago (3 children) Normally patches roll out before the vulnerability is disclosed. But I honestly don't know the status on CopyFail permalink fedilink source parent hideshow 6 child comments replies: [–] Jesus_666@lemmy.world 7 points 4 months ago (2 children) Most distros delivered patched kernels well before the vulnerability was publicly disclosed. Not sure if Ubuntu did but they had ample time to do so. permalink fedilink source parent hideshow 4 child comments replies: [–] lengau@midwest.social 5 points 4 months ago (1 child) Not true. None of the major distros were alerted and Ubuntu, Debian, RHEL, etc. were all struggling at the last minute. See: https://infosec.exchange/@wdormann/116489443704631952 However, none of those DDoS's took out the archive servers, so Ubuntu users could still get new kernels. permalink fedilink source parent hideshow 2 child comments replies: [–] Jesus_666@lemmy.world 3 points 4 months ago (1 child) Interesting. So only the fast distros were done patching by time of disclosure. The ones you wouldn't run a server on. Because only the kernel devs better informed. That's... pretty amateurish from the guys who discovered CopyFail. permalink fedilink source parent hideshow 2 child comments replies: [–] lengau@midwest.social 5 points 4 months ago Even then, some of the upstream LTS kernels didn't get the patch until the 30th. permalink fedilink source parent [–] Successful_Try543@feddit.org 4 points 4 months ago* Ubuntu 26.04 has already been patched, but not the older (LTS) releases. https://ubuntu.com/security/CVE-2026-31431 permalink fedilink source parent [–] lengau@midwest.social 3 points 4 months ago The people who found the vulnerability didn't do proper coordinated disclosure. See: https://infosec.exchange/@wdormann/116489443704631952 permalink fedilink source parent [–] Miaou@jlai.lu 2 points 4 months ago The Debian Bookworm fix was only rolled out last night. Bookworm was not directly affected though, so maybe that's why it took a bit more time permalink fedilink source parent
[–] Jesus_666@lemmy.world 7 points 4 months ago (2 children) Most distros delivered patched kernels well before the vulnerability was publicly disclosed. Not sure if Ubuntu did but they had ample time to do so. permalink fedilink source parent hideshow 4 child comments replies: [–] lengau@midwest.social 5 points 4 months ago (1 child) Not true. None of the major distros were alerted and Ubuntu, Debian, RHEL, etc. were all struggling at the last minute. See: https://infosec.exchange/@wdormann/116489443704631952 However, none of those DDoS's took out the archive servers, so Ubuntu users could still get new kernels. permalink fedilink source parent hideshow 2 child comments replies: [–] Jesus_666@lemmy.world 3 points 4 months ago (1 child) Interesting. So only the fast distros were done patching by time of disclosure. The ones you wouldn't run a server on. Because only the kernel devs better informed. That's... pretty amateurish from the guys who discovered CopyFail. permalink fedilink source parent hideshow 2 child comments replies: [–] lengau@midwest.social 5 points 4 months ago Even then, some of the upstream LTS kernels didn't get the patch until the 30th. permalink fedilink source parent [–] Successful_Try543@feddit.org 4 points 4 months ago* Ubuntu 26.04 has already been patched, but not the older (LTS) releases. https://ubuntu.com/security/CVE-2026-31431 permalink fedilink source parent
[–] lengau@midwest.social 5 points 4 months ago (1 child) Not true. None of the major distros were alerted and Ubuntu, Debian, RHEL, etc. were all struggling at the last minute. See: https://infosec.exchange/@wdormann/116489443704631952 However, none of those DDoS's took out the archive servers, so Ubuntu users could still get new kernels. permalink fedilink source parent hideshow 2 child comments replies: [–] Jesus_666@lemmy.world 3 points 4 months ago (1 child) Interesting. So only the fast distros were done patching by time of disclosure. The ones you wouldn't run a server on. Because only the kernel devs better informed. That's... pretty amateurish from the guys who discovered CopyFail. permalink fedilink source parent hideshow 2 child comments replies: [–] lengau@midwest.social 5 points 4 months ago Even then, some of the upstream LTS kernels didn't get the patch until the 30th. permalink fedilink source parent
[–] Jesus_666@lemmy.world 3 points 4 months ago (1 child) Interesting. So only the fast distros were done patching by time of disclosure. The ones you wouldn't run a server on. Because only the kernel devs better informed. That's... pretty amateurish from the guys who discovered CopyFail. permalink fedilink source parent hideshow 2 child comments replies: [–] lengau@midwest.social 5 points 4 months ago Even then, some of the upstream LTS kernels didn't get the patch until the 30th. permalink fedilink source parent
[–] lengau@midwest.social 5 points 4 months ago Even then, some of the upstream LTS kernels didn't get the patch until the 30th. permalink fedilink source parent
[–] Successful_Try543@feddit.org 4 points 4 months ago* Ubuntu 26.04 has already been patched, but not the older (LTS) releases. https://ubuntu.com/security/CVE-2026-31431 permalink fedilink source parent
[–] lengau@midwest.social 3 points 4 months ago The people who found the vulnerability didn't do proper coordinated disclosure. See: https://infosec.exchange/@wdormann/116489443704631952 permalink fedilink source parent
[–] Miaou@jlai.lu 2 points 4 months ago The Debian Bookworm fix was only rolled out last night. Bookworm was not directly affected though, so maybe that's why it took a bit more time permalink fedilink source parent
[+] poinck@lemmy.world 3 points 4 months ago* (last edited 1 month ago) (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] Successful_Try543@feddit.org 1 point 4 months ago (1 child) Does Ubuntu, like Debian, make you choose a repository mirror during the installation? permalink fedilink source parent hideshow 2 child comments replies: [–] lengau@midwest.social 2 points 4 months ago Typically they use archive.ubuntu.com, which was not affected. permalink fedilink source parent
[–] Successful_Try543@feddit.org 1 point 4 months ago (1 child) Does Ubuntu, like Debian, make you choose a repository mirror during the installation? permalink fedilink source parent hideshow 2 child comments replies: [–] lengau@midwest.social 2 points 4 months ago Typically they use archive.ubuntu.com, which was not affected. permalink fedilink source parent
[–] lengau@midwest.social 2 points 4 months ago Typically they use archive.ubuntu.com, which was not affected. permalink fedilink source parent
[–] unexposedhazard@discuss.tchncs.de 3 points 4 months ago Add to that the recent announcement about adding AI poop to the OS. permalink fedilink source parent