** Description changed:

  [ Impact ]
  
  This release syncs the latest Pro Client developments from GitHub into
  Launchpad to align supported Ubuntu releases with upstream release 38,
  following the Pro Client SRU exception process. It includes security and
  bug fixes for the pro client.
  
  The most important changes are:
  - Security Fixes (Already published via -security pocket): Addressed security 
vulnerabilities CVE-2026-12391, CVE-2026-11386, and CVE-2026-9494.
  - AppArmor Profile Fixes: Resolved AppArmor denials across profiles cloud_id, 
ubuntu_pro_esm_cache, and ubuntu_pro_esm_cache_systemd_detect_vir, unblocking 
CPC image build pipelines and fixing denials on Azure Noble VMs.
  - Cloud Enhancements: Added support for GCE Marketplace Pro licenses and 
Resolute GCP license IDs, and fixed aws-gov to aws mapping for correct FIPS 
flavor assignment.
  
  See the changelog entry below for a full list of changes and bugs.
  
  [ Test Plan ]
  
  The following development and SRU process was followed:
  https://documentation.ubuntu.com/sru/en/latest/reference/exception-
  UbuntuAdvantageTools-Updates
  
- Besides the full integration test runs, manual tests are executed to verify 
bugs:
+ The full integration test suite provides coverage. On top of this,
+ manual verification was done for each of these issues:
+ 
  - LP: #2153472 — The CPC team has manually tested this fix.
  - LP: #2143251 — The CPC team has manually tested this fix.
  - LP: #2131292 — SRU tests were created and run. Also verified system audit 
logs no longer report denied messages when /proc/device-tree or devicetree 
structures exist.
  
  [ Where problems could occur ]
  
  - AppArmor Scope: Modifying AppArmor profiles for cloud_id, 
ubuntu_pro_esm_cache, and ubuntu_pro_esm_cache_systemd_detect_vir carries risks 
of being overly restrictive or permissive. In this case where we added access, 
we risk exposing system resources.
  - Cloud Platform Detection: Typos or logic errors in AWS/GCP license matching 
could trigger Python exceptions during cloud-id detection or fail to 
auto-attach subscriptions on boot.
  - Security/CVE Regressions: Stricter validation and security controls around 
APT sources, token storage, and diagnostic archives could introduce unexpected 
regressions.
  
  [ Other Info ]
  
  By the following SRU process, ubuntu-advantage-tools has an SRU
  exception:
  https://documentation.ubuntu.com/sru/en/latest/reference/exception-
  UbuntuAdvantageTools-Updates
  
  [ Changelog ]
  
  ubuntu-advantage-tools (38ubuntu0) stonking; urgency=medium
  
    * d/apparmor: add cap perfmon to cloud_id AppArmor profile (LP: #2153472)
    * d/apparmor: add perfmon systemctl unix socket in AppArmor profiles
      (LP: #2143251)
    * d/apparmor: fix denied audit messages when devicetree exists
      (LP: #2131292)
    * d/apparmor: include PID directory in ubuntu_pro_esm_cache profile (GH: 
#3555)
    * d/apparmor: allow /usr/share/coreutils/locales/** in ubuntu_pro_esm_cache
      profile (GH: #3570)
    * New upstream release 38:
      - security:
        + fix CVE-2026-12391
        + fix CVE-2026-11386
        + fix CVE-2026-9494
      - clouds:
        + add support for GCE Marketplace Pro licenses (GH: #3573)
        + add resolute GCP license IDs (GH: #3532)
        + map aws-gov to aws for correct FIPS flavor (LP: #2144693)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163406

Title:
  [SRU] Update ubuntu-advantage-tools to v38 (AppArmor fixes, CVEs,
  cloud license updates) - Bionic, Focal, Jammy, Noble, Resolute

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/2163406/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to