USN-5656-1: JACK vulnerability
Publication date
4 October 2022
Overview
JACK could cause a crash in certain conditions.
Releases
Packages
- jackd2 - JACK Audio Connection Kit (server and example clients)
Details
Joseph Yasi discovered that JACK incorrectly handled the closing of a socket
in certain conditions. An attacker could potentially use this issue to
cause a crash.
Joseph Yasi discovered that JACK incorrectly handled the closing of a socket
in certain conditions. An attacker could potentially use this issue to
cause a crash.
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
| Ubuntu Release | Package Version | ||
|---|---|---|---|
| 16.04 LTS xenial | jackd2 – 1.9.10+20150825git1ed50c92~dfsg-1ubuntu1+esm1 | ||
| jackd2-firewire – 1.9.10+20150825git1ed50c92~dfsg-1ubuntu1+esm1 | |||
| libjack-jackd2-0 – 1.9.10+20150825git1ed50c92~dfsg-1ubuntu1+esm1 | |||
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.