** Description changed: [ Impact ] This release syncs the latest Pro Client developments from GitHub into Launchpad to align supported Ubuntu releases with upstream release 38, following the Pro Client SRU exception process. It includes security and bug fixes for the pro client. The most important changes are: - Security Fixes (Already published via -security pocket): Addressed security vulnerabilities CVE-2026-12391, CVE-2026-11386, and CVE-2026-9494. - AppArmor Profile Fixes: Resolved AppArmor denials across profiles cloud_id, ubuntu_pro_esm_cache, and ubuntu_pro_esm_cache_systemd_detect_vir, unblocking CPC image build pipelines and fixing denials on Azure Noble VMs. - Cloud Enhancements: Added support for GCE Marketplace Pro licenses and Resolute GCP license IDs, and fixed aws-gov to aws mapping for correct FIPS flavor assignment. See the changelog entry below for a full list of changes and bugs. [ Test Plan ] The following development and SRU process was followed: https://documentation.ubuntu.com/sru/en/latest/reference/exception- UbuntuAdvantageTools-Updates - Besides the full integration test runs, manual tests are executed to verify bugs: + The full integration test suite provides coverage. On top of this, + manual verification was done for each of these issues: + - LP: #2153472 — The CPC team has manually tested this fix. - LP: #2143251 — The CPC team has manually tested this fix. - LP: #2131292 — SRU tests were created and run. Also verified system audit logs no longer report denied messages when /proc/device-tree or devicetree structures exist. [ Where problems could occur ] - AppArmor Scope: Modifying AppArmor profiles for cloud_id, ubuntu_pro_esm_cache, and ubuntu_pro_esm_cache_systemd_detect_vir carries risks of being overly restrictive or permissive. In this case where we added access, we risk exposing system resources. - Cloud Platform Detection: Typos or logic errors in AWS/GCP license matching could trigger Python exceptions during cloud-id detection or fail to auto-attach subscriptions on boot. - Security/CVE Regressions: Stricter validation and security controls around APT sources, token storage, and diagnostic archives could introduce unexpected regressions. [ Other Info ] By the following SRU process, ubuntu-advantage-tools has an SRU exception: https://documentation.ubuntu.com/sru/en/latest/reference/exception- UbuntuAdvantageTools-Updates [ Changelog ] ubuntu-advantage-tools (38ubuntu0) stonking; urgency=medium * d/apparmor: add cap perfmon to cloud_id AppArmor profile (LP: #2153472) * d/apparmor: add perfmon systemctl unix socket in AppArmor profiles (LP: #2143251) * d/apparmor: fix denied audit messages when devicetree exists (LP: #2131292) * d/apparmor: include PID directory in ubuntu_pro_esm_cache profile (GH: #3555) * d/apparmor: allow /usr/share/coreutils/locales/** in ubuntu_pro_esm_cache profile (GH: #3570) * New upstream release 38: - security: + fix CVE-2026-12391 + fix CVE-2026-11386 + fix CVE-2026-9494 - clouds: + add support for GCE Marketplace Pro licenses (GH: #3573) + add resolute GCP license IDs (GH: #3532) + map aws-gov to aws for correct FIPS flavor (LP: #2144693)
-- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2163406 Title: [SRU] Update ubuntu-advantage-tools to v38 (AppArmor fixes, CVEs, cloud license updates) - Bionic, Focal, Jammy, Noble, Resolute To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/2163406/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
