Subcategories

  • 2 Topics
    2 Posts
    peat_psuwitP
    Vulnerability During the periodic scanning of the local media, gst-hybris gets loaded by Gstreamer, a media framework, to perform HW-accelerated video decoding. gst-hybris expected the rendering element ("sink") to be HW-accelerated as well, but media scanning does not use HW-accelerated rendering. This results in memory corruption, which could potentially be exploited by a specifically-crafted media. Info The pipeline constructing process of Gstreamer is dynamic; it can automatically pick the demuxer, decoder(s), and sink(s) based on the file type, file content, and component's capability. In this case, Gstreamer picks gst-hybris' HW-accelerated decoder as the decoder, but "fakesink" as the sink (as the scanner only wants to know certain metadata). Now, to perform HW-accelerated video rendering, gst-hybris has a dedicated sink which co-operate with the decoder in order to pass decoded video frame without copying the memory. When Gstreamer connects the decoder with the sink, the decoder can access the sink to perform necessary co-ordination. However, the decoder forgot to check if the sink it accesses is the one it can co-operate, which results in the code writing into the memory it's not supposed to access. In order for this to be exploited, the video has to be on the device, which subsequently leads to it being scanned. Video playback in other cases is not affected, as they always use HW-accelerated video rendering. CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') Severity: Medium Affected versions Affected versions: All Ubuntu Touch versions up to and including 20.04 OTA-10, 24.04-1.0. Fixed in versions: Ubuntu Touch 20.04 OTA-11 and 24.04-1.1. Solution Starting in Ubuntu Touch 20.04 OTA-11 and 24.04-1.1, gst-hybris checks the type of the sink before casting to the expected type. Fixed in: https://gitlab.com/ubports/development/core/hybris-support/gst-hybris/-/commit/58bb0e1ba2169bd85ac0930bf074ab865553356f Recommendations Update your device to Ubuntu Touch 20.04 OTA-11, 24.04-1.1 or newer. Do not download videos from untrusted sources. Timeline The issue was discovered on 30 September 2025, during a debugging of another issue. The issue was discovered before the release of Ubuntu Touch 24.04-1.0, but we did not manage to work it through and fix it in time for that release. Ubuntu Touch 20.04 OTA-11 and 24.04-1.1 was released on 1 December 2025, coordinated with the publication of this advisory. Credit Reported-by: Ratchanan Srirattanamet Patched-by: Ratchanan Sirrattanamet
  • This forum is all about the ongoing efforts to upgrade UT to the 20.04 codebase of Ubuntu.

    132 Topics
    954 Posts
    A
    @Moem @Luksus This is good news as this was a good phone with UBPorts
  • Changes/Fixes/Improvements?

    7
    0 Votes
    7 Posts
    878 Views
    M
    @moem Thanks, that should have been obvious, seeing as I must handle the device, I missed it. Basically to me, that's same as opening the app as I must clean my hands, handle the device. Regardless, a must have has been implemented for me!
  • FM radio: testing instructions and feedback

    fm-radio
    26
    6 Votes
    26 Posts
    9k Views
    D
    @mardy The Ukw radio for Ubuntu Touch seems to be set too high in sensitivity. There should be an option somewhere where you can change this. So some stations that are below the level do not run at all. I live in the countryside so it would be good to keep the squelch of the app as low as possible. I would recommend the value 10 if the app can do that.
  • Privacy on UT

    Moved
    5
    0 Votes
    5 Posts
    1k Views
    D
    I'm not commenting on whether it's real or not (not the skills for) but only drawing attention to the supposed issue (security flaw) I saw that day : https://github.com/ubports/ubuntu-touch/issues/2057 . See @dobey answer at the end which is rather reassuring.
  • Phoronix: Mir 2.9 w/XDG-Shell; Add'l Extensions: Any Impact on UBPorts?

    4
    0 Votes
    4 Posts
    693 Views
    E
    @alan_g Thanks for that! That answer satiated my curiosity for sure - but its unfortunate there are not enough volunteers! The only thing I can really volunteer to do is outreach - looking for volunteers on UBPorts-supported device forums on XDA, etc. Is there anything a user/fan like me can do to help?
  • VOLTE (Voice over Long Term Evolution)

    30
    -1 Votes
    30 Posts
    11k Views
    R
    @keneda @AppLee I guess abbreviated my statement a little too much leading to the impression I was a bit dimwitted. What I should have added was: "if your carrier kicks you off for lack of VoLTE support on your device -- and they did, then you don't get data or SMS either because you don't have service at all . . .because they kicked you off. Then you're really in a bind." Fortunately, I realized that I had an alternate phone I could put the SIM in to get the telegram code by SMS to the number I had originally used to register.
  • Call Forwarding for numbers not in your contacts

    10
    1 Votes
    10 Posts
    3k Views
    D
    @keneda You can check, all is fixed now.
  • Password for wipe/reset

    Moved
    13
    0 Votes
    13 Posts
    2k Views
    KenedaK
    @dirussy check here : https://gitlab.com/ubports/development/core?filter=setting
  • OTA-23 Call for Testing Companion Post

    13
    9 Votes
    13 Posts
    3k Views
    MrT10001M
    @naizena Check this thread out - link.
  • Changing bluetooth package

    4
    0 Votes
    4 Posts
    833 Views
    H
    @keneda thank you for your insights.
  • will ubuntu touch ever be upgraded past ubuntu 16.10

    Moved
    20
    0 Votes
    20 Posts
    4k Views
    C
    @applee said in will ubuntu touch ever be upgraded past ubuntu 16.10: But service will not stop abruptly one day. That's good to know because it gives me some time to find an alternative phone or OS when my phone loses support.
  • green led above 90% (during charging)

    10
    0 Votes
    10 Posts
    2k Views
    BollyB
    @bolly said in green led above 90% (during charging): @cibersheep I always charge the battery with the tablet switched off.... I will check it. As @josevidal says, it seems to behave differently. The LED on the m10FHD turns green from 90% and red when it is below 90%. This is when the tablet is switched off.
  • Questions and Interest in the PinePhone Ubuntu Touch Project

    4
    0 Votes
    4 Posts
    843 Views
    CiberSheepC
    I don't know if you are onlly interested in the PinePhone development, but I'll answer in general as the questions are about UBports (if I understood that correctly). @privacylover said in Questions and Interest in the PinePhone Ubuntu Touch Project: [...] [...] is this truly like a decentralized community project or is it more organized? I would say there is a small core team working, but work from the community is needed. Are there any skills or contributions besides development which are missing or needed? Indeed. Translation, testing, documentation, promotion, etc. There is a post about this: https://forums.ubports.com/topic/6991/how-can-i-help/13 Who are the current participants who are actively helping the project along? Part is here: https://gitlab.com/ubports Part is here: github.com/ubports/ Part is here: https://gitlab.com/theopenstore/openstore-meta/ and open-store.io/ Part is here: https://translate.ubports.com/ And sponsors, and people spreading the word...
  • Ability to add VPN config with a .conf file

    1
    0 Votes
    1 Posts
    322 Views
    No one has replied
  • Call for testing: power indicator (esp. if it works for you now!)

    21
    1 Votes
    21 Posts
    6k Views
    ?
    The Upower Tool from the Test Thread works 100 Prozent oh the Xiaomi Redmi Note 9 Pro. Thank You Nice Tool. Update: Is this indicator APP also available somewhere as an executable version? I've always had bad luck installing them in the terminal. Actually a nice APP but the unsightly effect the device becomes unstable.
  • Changes to Release Candidate channel

    Moved
    1
    9 Votes
    1 Posts
    919 Views
    No one has replied
  • OTA-22 Call for Testing Companion Post

    32
    6 Votes
    32 Posts
    9k Views
    IanI
    @domubpkm Good idea. Stoping the bluetooth service from the terminal turns off the radio and saves my battery. Turning the service backon from the terminal followed by power off the phone and turn back on again gets bluetooth working to a BT speaker again..... but still unable to turn BT off either from the pull down menu from the indicators or from the settings page.
  • Make it possible to set default app

    9
    1 Votes
    9 Posts
    2k Views
    AppLeeA
    @ian Didn't know this one, thank you I'll try to remember it. :beaming_face_with_smiling_eyes:
  • Emergency broadcast

    emergency broadcast messages feature
    9
    0 Votes
    9 Posts
    2k Views
    dobeyD
    @ian said in Emergency broadcast: Has this feature been coded in UT? Emergency Broadcast messages support has not been integrated into UT as of yet. Indeed, I know of no other non-Android Linux OSes or shells that have them yet either. However, ofono does have some API for them, so it should be possible to do the work for them in UT. It just needs someone to spend the time to do all the work. I don't know if ModemManager has any support for them at all though, so implementing them for other shells may be even more work.
  • Allow certain notifications on silence mode

    Moved
    12
    1 Votes
    12 Posts
    1k Views
    dizzyD
    @klh Got it. Thanks for the explaination!
  • UT on pinephone vs halium based UT

    5
    0 Votes
    5 Posts
    1k Views
    N
    I think there are three things you should look into : PostmarketOS on the PinePhone64 (Pro) Ubuntu Touch on the Raspberry Pi 3B At some point indeed Lomiri in combination with regular Ubuntu Desktop either on x86-64 or ARM based hardware