A new release of the Ubuntu Cloud Images for stable Ubuntu release 18.04 LTS (Bionic Beaver) is available at [1]. These new images superseded the existing images [2]. Images are available for download or immediate use on EC2 via publish AMI ids. Users who wish to update their existing installations can do so with: 'sudo apt-get update && sudo apt-get dist-upgrade && sudo reboot'. The following packages have been updated. Please see the full changelogs for a complete listing of changes: * base-files: 10.1ubuntu2.9 => 10.1ubuntu2.10 * libx11: 2:1.6.4-3ubuntu0.2 => 2:1.6.4-3ubuntu0.3 * linux-meta: 4.15.0.115.103 => 4.15.0.117.104 * linux-signed: 4.15.0-115.116 => 4.15.0-117.118 * ubuntu-meta: 1.417.4 => 1.417.5 The following is a complete changelog for this image. new: {'linux-headers-4.15.0-117-generic': '4.15.0-117.118', 'linux-modules-4.15.0-117-generic': '4.15.0-117.118', 'linux-headers-4.15.0-117': '4.15.0-117.118', 'motd-news-config': '10.1ubuntu2.10'} removed: {'linux-modules-4.15.0-115-generic': '4.15.0-115.116', 'linux-headers-4.15.0-115-generic': '4.15.0-115.116', 'linux-headers-4.15.0-115': '4.15.0-115.116'} changed: ['base-files', 'libx11-6:amd64', 'libx11-data', 'linux-headers-generic', 'linux-headers-virtual', 'linux-image-4.15.0-117-generic', 'linux-image-virtual', 'linux-virtual', 'ubuntu-minimal', 'ubuntu-server', 'ubuntu-standard'] new snaps: {} removed snaps: {} changed snaps: [] ==== base-files: 10.1ubuntu2.9 => 10.1ubuntu2.10 ==== ==== base-files [ Andreas Hasenack ] * motd/50-motd-news: don't include uptime in the user-agent string (LP: #1886572) * Move the /etc/default/motd-news conffile to the motd-news-config package (LP: #1888575): - d/base-files.maintscript: remove /etc/default/motd-news config file on upgrade - d/control: break on ubuntu-server << 1.417.5 to force an upgrade if it is installed, which will pull motd-news-config and the conffile back in - d/motd-news-config.postinst: + handle the upgrade case where the motd-news config file was changed while it belonged to base-files + disable motd-news if the config file was removed by hand before the upgrade - d/postinst.in: signal the motd-news-config package if the motd-news config file was removed manually before the upgrade - d/control: new motd-news-config package, carrying the configuration file for the /etc/update-motd.d/50-motd-news script. - d/rules, d/motd-news-config.install: /e/d/motd-news is in the motd-news-config package now [ Steve Langasek ] * motd/50-motd-news: use wget instead of curl, since wget is standard but curl is optional (LP: #1888572): - This changes the timeout behavior slightly because wget does not have an exact equivalent to curl's --max-time argument, we are using --timeout instead. ==== libx11: 2:1.6.4-3ubuntu0.2 => 2:1.6.4-3ubuntu0.3 ==== ==== libx11-6:amd64 libx11-data * SECURITY UPDATE: integer overflow and heap overflow in XIM client - debian/patches/CVE-2020-14344-1.patch: fix signed length values in modules/im/ximcp/imRmAttr.c. - debian/patches/CVE-2020-14344-2.patch: fix integer overflows in modules/im/ximcp/imRmAttr.c. - debian/patches/CVE-2020-14344-3.patch: fix more unchecked lengths in modules/im/ximcp/imRmAttr.c. - debian/patches/CVE-2020-14344-4.patch: zero out buffers in functions in modules/im/ximcp/imDefIc.c, modules/im/ximcp/imDefIm.c. - debian/patches/CVE-2020-14344-5.patch: change the data_len parameter to CARD16 in modules/im/ximcp/imRmAttr.c. - debian/patches/CVE-2020-14344-6.patch: fix size calculation in modules/im/ximcp/imRmAttr.c. - debian/patches/CVE-2020-14344-7.patch: fix input clients connecting to server in modules/im/ximcp/imRmAttr.c. - CVE-2020-14344 * SECURITY UPDATE: integer overflow and double free in locale handling - debian/patches/CVE-2020-14363.patch: fix an integer overflow in modules/om/generic/omGeneric.c. - CVE-2020-14363 ==== linux-meta: 4.15.0.115.103 => 4.15.0.117.104 ==== ==== linux-headers-generic linux-headers-virtual linux-image-virtual linux-virtual * Bump ABI 4.15.0-117 ==== linux-signed: 4.15.0-115.116 => 4.15.0-117.118 ==== ==== linux-image-4.15.0-117-generic * Master version: 4.15.0-117.118 ==== ubuntu-meta: 1.417.4 => 1.417.5 ==== ==== ubuntu-minimal ubuntu-server ubuntu-standard * d/control: ubuntu-server depends on motd-news-config (LP: #1888575) -- [1] http://cloud-images.ubuntu.com/releases/bionic/release-20200908/ [2] http://cloud-images.ubuntu.com/releases/bionic/release-20200901/