A new release of the Ubuntu Cloud Images for stable Ubuntu release 20.10 (Groovy Gorilla) is available at [1]. These new images superseded the existing images [2]. Images are available for download or immediate use on EC2 via publish AMI ids. Users who wish to update their existing installations can do so with: 'sudo apt-get update && sudo apt-get dist-upgrade && sudo reboot'. The following packages have been updated. Please see the full changelogs for a complete listing of changes: * git: 1:2.27.0-1ubuntu1 => 1:2.27.0-1ubuntu1.1 * glib2.0: 2.66.1-2 => 2.66.1-2ubuntu0.1 * libzstd: 1.4.5+dfsg-4 => 1.4.5+dfsg-4ubuntu0.1 * linux-meta: 5.8.0.44.49 => 5.8.0.45.50 * linux-signed: 5.8.0-44.50 => 5.8.0-45.51 * openssh: 1:8.3p1-1 => 1:8.3p1-1ubuntu0.1 * update-manager: 1:20.10.4 => 1:20.10.5 The following is a complete changelog for this image. new: {'linux-headers-5.8.0-45': '5.8.0-45.51', 'linux-modules-5.8.0-45-generic': '5.8.0-45.51', 'linux-headers-5.8.0-45-generic': '5.8.0-45.51'} removed: {'linux-headers-5.8.0-44-generic': '5.8.0-44.50', 'linux-headers-5.8.0-44': '5.8.0-44.50', 'linux-modules-5.8.0-44-generic': '5.8.0-44.50'} changed: ['git', 'git-man', 'libglib2.0-0:amd64', 'libglib2.0-bin', 'libglib2.0-data', 'libzstd1:amd64', 'linux-headers-generic', 'linux-headers-virtual', 'linux-image-5.8.0-45-generic', 'linux-image-virtual', 'linux-virtual', 'openssh-client', 'openssh-server', 'openssh-sftp-server', 'python3-update-manager', 'update-manager-core'] new snaps: {} removed snaps: {} changed snaps: ['lxd', 'snapd'] ==== git: 1:2.27.0-1ubuntu1 => 1:2.27.0-1ubuntu1.1 ==== ==== git git-man * SECURITY UPDATE: remote code exec during clone on case-insensitive FS - debian/patches/CVE-2021-21300.patch: fix bug that makes checkout follow symlinks in leading path in cache.h, compat/mingw.c, git-compat-util.h, run-command.c, symlinks.c, t/t0021-conversion.sh, t/t0021/rot13-filter.pl, t/t2006-checkout-index-basic.sh, unpack-trees.c. - CVE-2021-21300 ==== glib2.0: 2.66.1-2 => 2.66.1-2ubuntu0.1 ==== ==== libglib2.0-0:amd64 libglib2.0-bin libglib2.0-data * SECURITY UPDATE: g_byte_array_new_take length truncation - debian/patches/CVE-2021-2721x/CVE-2021-27218.patch: do not accept too large byte arrays in glib/garray.c, glib/gbytes.c, glib/tests/bytes.c. - CVE-2021-27218 * SECURITY UPDATE: integer overflow in g_bytes_new - debian/patches/CVE-2021-2721x/CVE-2021-27219*.patch: add internal g_memdup2() function and use it instead of g_memdup() in a bunch of places. - CVE-2021-27219 ==== libzstd: 1.4.5+dfsg-4 => 1.4.5+dfsg-4ubuntu0.1 ==== ==== libzstd1:amd64 * SECURITY UPDATE: race condition allows attacker to access world-readable destination file - debian/patches/0018-fix-file-permissions-on-compression.patch: set umask in programs/fileio.c, programs/util.c, programs/util.h. - CVE-2021-24031 - CVE-2021-24032 ==== linux-meta: 5.8.0.44.49 => 5.8.0.45.50 ==== ==== linux-headers-generic linux-headers-virtual linux-image-virtual linux-virtual * Bump ABI 5.8.0-45 ==== linux-signed: 5.8.0-44.50 => 5.8.0-45.51 ==== ==== linux-image-5.8.0-45-generic * Master version: 5.8.0-45.51 ==== openssh: 1:8.3p1-1 => 1:8.3p1-1ubuntu0.1 ==== ==== openssh-client openssh-server openssh-sftp-server * SECURITY UPDATE: double-free memory corruption in ssh-agent - debian/patches/CVE-2021-28041.patch: set ext_name to NULL after freeing it so it doesn't get freed again later on in ssh-agent.c. - CVE-2021-28041 ==== update-manager: 1:20.10.4 => 1:20.10.5 ==== ==== python3-update-manager update-manager-core * UpdateManager/Core/UpdateList.py: change to a regex from a static list of packages to be grouped under Ubuntu Base (LP: #1902025) * Clean up apt cache binary files left behind by tests * Rename meta_pkgs to ubuntu_base_pkgs to make it more clear to the reader which packages should be included * Add tests in to ensure Ubuntu base packages are not grouped when staged for removal (LP: #1912718) * Fix crash caused by adding apt package objects to a list of strings (LP: #1913476) -- [1] http://cloud-images.ubuntu.com/releases/groovy/release-20210315/ [2] http://cloud-images.ubuntu.com/releases/groovy/release-20210303/