Subcategories

  • 2 Topics
    2 Posts
    peat_psuwitP
    Vulnerability During the periodic scanning of the local media, gst-hybris gets loaded by Gstreamer, a media framework, to perform HW-accelerated video decoding. gst-hybris expected the rendering element ("sink") to be HW-accelerated as well, but media scanning does not use HW-accelerated rendering. This results in memory corruption, which could potentially be exploited by a specifically-crafted media. Info The pipeline constructing process of Gstreamer is dynamic; it can automatically pick the demuxer, decoder(s), and sink(s) based on the file type, file content, and component's capability. In this case, Gstreamer picks gst-hybris' HW-accelerated decoder as the decoder, but "fakesink" as the sink (as the scanner only wants to know certain metadata). Now, to perform HW-accelerated video rendering, gst-hybris has a dedicated sink which co-operate with the decoder in order to pass decoded video frame without copying the memory. When Gstreamer connects the decoder with the sink, the decoder can access the sink to perform necessary co-ordination. However, the decoder forgot to check if the sink it accesses is the one it can co-operate, which results in the code writing into the memory it's not supposed to access. In order for this to be exploited, the video has to be on the device, which subsequently leads to it being scanned. Video playback in other cases is not affected, as they always use HW-accelerated video rendering. CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') Severity: Medium Affected versions Affected versions: All Ubuntu Touch versions up to and including 20.04 OTA-10, 24.04-1.0. Fixed in versions: Ubuntu Touch 20.04 OTA-11 and 24.04-1.1. Solution Starting in Ubuntu Touch 20.04 OTA-11 and 24.04-1.1, gst-hybris checks the type of the sink before casting to the expected type. Fixed in: https://gitlab.com/ubports/development/core/hybris-support/gst-hybris/-/commit/58bb0e1ba2169bd85ac0930bf074ab865553356f Recommendations Update your device to Ubuntu Touch 20.04 OTA-11, 24.04-1.1 or newer. Do not download videos from untrusted sources. Timeline The issue was discovered on 30 September 2025, during a debugging of another issue. The issue was discovered before the release of Ubuntu Touch 24.04-1.0, but we did not manage to work it through and fix it in time for that release. Ubuntu Touch 20.04 OTA-11 and 24.04-1.1 was released on 1 December 2025, coordinated with the publication of this advisory. Credit Reported-by: Ratchanan Srirattanamet Patched-by: Ratchanan Sirrattanamet
  • This forum is all about the ongoing efforts to upgrade UT to the 20.04 codebase of Ubuntu.

    132 Topics
    954 Posts
    A
    @Moem @Luksus This is good news as this was a good phone with UBPorts
  • Broadpwn WiFi vulnerability fix ?

    3
    0 Votes
    3 Posts
    913 Views
    H
    There is work being done on a 3rd party fix - https://github.com/seemoo-lab/nexmon/issues/108
  • Confinement / Sandboxes

    21
    0 Votes
    21 Posts
    10k Views
    M
    @hoh61 i have an m10 fhd ML002151 if you need to download UT firmware http://www.mibqyyo.com/en-download/categorias/aquaris-m10-fhd-ubuntu-edition/
  • I try unsuccessfully to upgrade my version to 16.10 or 17.04.

    3
    0 Votes
    3 Posts
    976 Views
    advocatuxA
    @stefano don't worry about that guy, he/she is a spammer and that's why his/her post has been deleted
  • Xenial UI constantly freezing at least on MX4

    5
    0 Votes
    5 Posts
    2k Views
    S
    @advocatux Thanks for your report. So i will wait...
  • Mobile signature support?

    1
    0 Votes
    1 Posts
    723 Views
    No one has replied
  • Nexus 5 Screenshot Control

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Ubuntu UI Toolkit - who would join me if I tried to move it to QQC?

    18
    1 Votes
    18 Posts
    6k Views
    M
    I think @sverzegnassi has been working on the Suru style for QQC for some time. Would you share some information on what the status is and if anything has been done not only to style, but also SDK components (bottom edge, headers, swipeable list items etc.)? I decided not to take up any work in it currently and focus on an idea that might someday evolve into a decent app. I'll not shere more information though, as there is still a long way ahead and the entire thing is uncertain. But if the app will approach to materialization, I'll definitely consider implementing in QQC2 (if Suru style and component set is in good shape enough by this time), and maybe help out with the SDK in that time.
  • Running desktop applications on UBports (X11, Wayland, Mir and toolkits)

    4
    9 Votes
    4 Posts
    4k Views
    alan_gA
    A few links for tracking Mir's progress since the OP: Wayland support (for some extensions) is available in Mir already and will improve with the next release For non-Wayland applications: there are plans for X11 support (but this come later)
  • Global Online Accounts

    4
    1 Votes
    4 Posts
    2k Views
    mardyM
    @amolith We do have Online Accounts in Ubports; we just need more applications using them
  • UBPorts Installer - Excellent user experience

    5
    7 Votes
    5 Posts
    2k Views
    P
    Same for me . Great congratulation to the developpers for their excellent work. Keep going !
  • Bqm10 fhd wifi,forgets password

    13
    0 Votes
    13 Posts
    4k Views
    M
    @marathon2422 I got excellent customer service and an RMA to return my m10fhd,to get the nvram err x10 fixed
  • Detecting "silent SMS" and pagings to locate your mobile location

    1
    1 Votes
    1 Posts
    910 Views
    No one has replied
  • Pro 5 - basebands

    24
    0 Votes
    24 Posts
    11k Views
    T
    Please see the separate thread i just opened on a potential temp solution: https://forums.ubports.com/topic/929/update-meizu-pro-5-baseband
  • Ubuntu touch MEIZU Pro 5 - Back to the home button?

    meizu pro 5
    2
    3 Votes
    2 Posts
    2k Views
    mihaelM
    I am also interested in this. Maybe this could be added like a customization of shortcuts... like in a desktop OS - since not all the phones have the same physical buttons.
  • Testing OS before phone purchase

    4
    0 Votes
    4 Posts
    2k Views
    IngoI
    The new camera modules of the FP2 work with OTA-3 of 15.04 but without flash. And I'm a little surprised to see the virtual keyboard working in the video of 16.04 on the FP2, because it doesn't work for me + here is the corresponding issue: https://github.com/ubports/ubuntu-touch/issues/395
  • Exclude alarms in the "Other vibrations" option

    1
    0 Votes
    1 Posts
    673 Views
    No one has replied
  • Is there a list of what works and what doesn't on Xenial?

    20
    0 Votes
    20 Posts
    5k Views
    mihaelM
    For those interested I would like to add these two links about the progress: https://github.com/ubports/ubuntu-touch/issues/384 https://github.com/ubports/ubuntu-touch/issues/398
  • Block/unblock phone numbers

    12
    1 Votes
    12 Posts
    4k Views
    T
    I think that's a good solution. Thanks to this UT community can have some influence on the next update packages.
  • Ubuntu 16.04 on legacy devices

    4
    0 Votes
    4 Posts
    2k Views
    Z
    @marathon2422 Oh, no at all. I understand that what I've installed is not recommended for daily use. I was just curious whether the issues I've mentioned are also present on other devices as well. In any case the fact 16.04 is available for MX4 I haven't even hoped for is a good enough reason for me to at least play with it for a few days :). And since I've been mostly on Android after Canonical decided not to continue with the project I've found a really easy way to dualboot between both systems: https://iubuntu.cz/dualboot-mx4.html so I plan to keep 16.04 and add Android as another option once I install it again.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    1 Views
    No one has replied