Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Fedora 24: 2017-0a1b2d495a critical: systemd-resolved DNS crash

fedora
Calendar Grey June 11, 2017
Dist Fedora Esm H88
A vital security patch addressing a vulnerability in systemd-resolved triggered by malicious DNS packets, requiring no system restart.
A security fix for a systemd-resolved crash on a crafted DNS packet

Summary

systemd is a system and service manager for Linux, compatible with

SysV and LSB init scripts. systemd provides aggressive parallelization

capabilities, uses socket and D-Bus activation for starting services,

offers on-demand starting of daemons, keeps track of processes using

Linux cgroups, supports snapshotting and restoring of the system

state, maintains mount and automount points and implements an

elaborate transactional dependency-based service control logic.

A security fix for a systemd-resolved crash on a crafted DNS packet. Relevant

only to systemd-resolved users (not enabled by default). No need to reboot or

logout.

[ 1 ] Bug #1455493 - CVE-2017-9217 systemd: Null pointer dereference in dns_packet_is_reply_for function

https://bugzilla.redhat.com/show_bug.cgi?id=1455493

su -c 'dnf upgrade systemd' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 24
Version: 229
Release: 20.fc24
Summary: A System and Service Manager

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here