CVE-2019-11480: high-severity vulnerability in Canonical pc-kernel
Ubuntu kernel snap build process could use unauthenticated sources
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
The Ubuntu kernel snap build process accepted packages without verifying their authenticity, allowing an attacker performing a man-in-the-middle attack to inject malicious code into the kernel build. This is critical because compromised kernel packages could affect all systems using that snap.
The pc-kernel snap build process hardcoded apt options (--allow-insecure-repositories and --allow-unauthenticated) when constructing the build chroot, disabling package signature verification. An attacker positioned on the network path between the build environment and Ubuntu archive could perform a MITM attack to deliver malicious packages, resulting in arbitrary code execution within the build environment and potential distribution of compromised kernel binaries.