iTnews Asia
  • Home
  • News
  • Security

Outage for Ubuntu users on Azure

Outage for Ubuntu users on Azure

Systemd security update broke DNS.

By Richard Chirgwin on Sep 1, 2022 12:08PM

A system security update has brought unexpected grief for Azure users running Ubuntu 18.04: it’s broken their DNS queries.

The ongoing outage began at around 6 am UTC (2 pm SGT) on August 30.

Microsoft Azure’s outage notice reveals a bonfire of dependencies: users of Bionic Beaver in Azure virtual machines, with unattended-upgrades enabled, would have had been pushed systemd version 237-3ubuntu10.54.

“A bug in this version will lead to DNS resolution errors,” Microsoft explained.

Those errors will affect any application that needs to retrieve DNS information.

“This bug and a potential fix have been highlighted on the Canonical / Ubuntu website, which we encourage impacted customers to read.

“An additional potential workaround customers can consider is to reboot impacted VM instances so that they receive a fresh DHCP lease and new DNS resolver(s). 

“If you are running a VM with Ubuntu 18.04 image, and you are experiencing connectivity issues, you can evaluate the above mitigation options,” Microsoft said.

Other Azure services are caught up in the downstream effects: “A large portion of impact has been to Azure Kubernetes Service (AKS) in multiple regions, and other Azure services reliant on AKS.”

Microsoft said it is testing “automatic mitigation steps” to apply to AKS resources once validated, and added that the offending Ubuntu updates have been removed for the time being.

Ironically, the offending systemd package was a security patch to protect the daemon against CVE-2022-2526, a medium-severity DNS vulnerability.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
azure microsoft outage security software systemd ubuntu

Related Articles

  • AI Agents are now driving a quantum shift in software development
  • Best practice tips for secure password management
  • Are third-party blind spots the weakest link in enterprise cybersecurity chain?
  • Fulbright University Vietnam adopts AI assistant to cut service delays
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Are third-party blind spots the weakest link in enterprise cybersecurity chain?

Are third-party blind spots the weakest link in enterprise cybersecurity chain?

Indonesia's national data centre suffers ransomware attack

Indonesia's national data centre suffers ransomware attack

Best practice tips for secure password management

Best practice tips for secure password management

PhilHealth estimates 13 to 20 million members affected by data breach

PhilHealth estimates 13 to 20 million members affected by data breach

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.