Reverting the fix for CVE-2018-1108 to get this to work is not necessary
and not a good idea. The root cause has been identified upstream in
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=897572 and fixes
committed.

Turns out it was fontconfig generating a uuid that tripped over the CVE
fix. One commited fix is to copy the necessary fonts to initramfs so
genuuid is not needed. Another is a fix to randutils. Those are the
changes that need to be pushed to Ubuntu users.

How did this regression ever get into an Ubuntu software update for the
masses?

** Bug watch added: Debian Bug tracker #897572
   https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=897572

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1779827

Title:
  failure to boot with linux-image-4.15.0-24-generic

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+bug/1779827/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to