Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Fedora 39: 2023-9adf4a31cc Critical: Netconsole Buffer Overrun Fix

fedora
Calendar Grey September 7, 2023
Dist Fedora Esm H88
This patch addresses memory overflow vulnerabilities in the netconsole service for Fedora 39. Urgent installation advised.
Update to prevent invalid fragment values from leading to a buffer overrun

Summary

This is a daemon for receiving and processing logs from the Linux Kernel, as

emitted over a network by the kernel's netconsole module. It supports both the

old "legacy" text-only format, and the new extended format added in v4.4.

The core of the daemon does nothing but process messages and drop them: in order

to make the daemon useful, the user must supply one or more "output modules".

These modules are shared object files which expose a small ABI that is called by

netconsd with the content and metadata for netconsole messages it receives.

Update Information:

Update to prevent invalid fragment values from leading to a buffer overrun

Change Log

* Wed Sep 6 2023 Michel Lind - 0.3-1 - Update to 0.3 - Prevent invalid fragment values from leading to a buffer overrun - Use SPDX license identifier

References


[ 1 ] Bug #2237785 - netconsd prior to v0.3 susceptible to buffer overrun when processing invalid fragment values https://bugzilla.redhat.com/show_bug.cgi?id=2237785

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-9adf4a31cc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: netconsd
Product: Fedora 39
Version: 0.3
Release: 1.fc39
URL:
Summary: The Netconsole Daemon

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here