Security Fix for Focal

Asked by Josef Petermann

Hi,

will there be an update that fixes the current vulnerabilities in libzmq5?

Or will I need to upgrade to Jammy or Focal + Ubuntu Pro?

Currently libzmq5 is version 4.3.2-2-ubuntu1 in focal (vulnerable) and 4.3.4-2 in Jammy. (fixed?)

Thanks,
Josef

Question information

Language:
English Edit question
Status:
Solved
For:
Ubuntu zeromq3 Edit question
Assignee:
No assignee Edit question
Solved by:
Josef Petermann
Solved:
Last query:
Last reply:
Revision history for this message
Manfred Hampl (m-hampl) said :
#1

Can you please provide details? Which vulnerability are you referring to?
I do not see any that is fixed in jammy but not in focal
https://ubuntu.com/security/cves?q=&package=zeromq3

Revision history for this message
Bernard Stafford (bernard010) said :
#2

I am not seeing any backports for libzmq5 for focal.
Jammy is using: libzmq5 (4.3.4-2)
https://packages.ubuntu.com/jammy/libzmq5
When Ubuntu Noble 24.04 has its final release in a few days.
Noble will be: libzmq5 (4.3.5-1build2)
https://packages.ubuntu.com/noble/libzmq5

Revision history for this message
Josef Petermann (jptrmn) said (last edit ):
#3

Thanks for providing the overview page.

I am specifically referring to https://ubuntu.com/security/CVE-2021-20237 , which has a fix for Ubuntu-Pro|ESM. Will there be a fix available in vanilla focal as well, considering it shall be supported until Mar, 2025?

I see that https://ubuntu.com/security/CVE-2021-20236 is vulnerable in focal, but not in jammy as well.

Thanks,
Josef

Revision history for this message
Manfred Hampl (m-hampl) said :
#4

https://ubuntu.com/security/CVE-2021-20237 clearly states, that the fixes are available only with Ubuntu Pro.

Background is, that libzmq5 is in the "universe" category, that means community-maintained. There is no person in Ubuntu or Canonical responsible for patching that package, but the Ubuntu community has to provide new versions if required.

There may be PPAs with updated versions, see https://launchpad.net/ubuntu/+ppas?name_filter=zeromq3
e.g. https://launchpad.net/~savoury1/+archive/ubuntu/backports

Revision history for this message
Josef Petermann (jptrmn) said :
#5

OK, thanks for the clarification.