Publishing details

Changelog

pulseaudio (1:8.0-0ubuntu3.15) xenial-security; urgency=medium

  * SECURITY UPDATE: don't rely on SCM_CREDENTIALS to detect snap confined
    clients (LP: #1895928)
    - d/p/0418-pa-client-peer-apparmor-label.patch: records AppArmor label
      in pa_client struct for native connections using aa_getpeercon.
    - d/p/0452-add-snappy-policy-module.patch: use the AppArmor
      label in the pa_client rather than looking it up via the process ID
      from SCM_CREDENTIALS.
    - CVE-2020-16123
   * Don't block classic snaps from module loading/unloading (LP: #1886854)
    - d/p/0452-add-snappy-policy-module.patch: replace
      deny_to_snaps_hook with a version that allows classic snaps.

 -- James Henstridge <email address hidden>  Tue, 22 Sep 2020 12:30:20 +0800

Available diffs

Builds

Built packages

Package files