Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8 MGASA-2021-0365 Critical: Systemd DoS and Memory Flaw

mageia
Calendar Grey July 22, 2021
Dist Mageia Esm H88
Systemd patch addresses severe security flaws in Mageia 8, tackling DoS attacks and issues related to memory management.
This systemd update provides the v246.15 maintenance release and fixes atleast the following security issues: An exploitable denial-of-service vulnerability exists in Systemd 245

Summary

This systemd update provides the v246.15 maintenance release and fixes atleast the following security issues:
An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server (CVE-2020-13529).
basic/unit-name.c in systemd 220 through 248 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash (CVE-2021-29270).

References

- https://bugs.mageia.org/show_bug.cgi?id=29270

- https://github.com/systemd/systemd-stable/compare/v246.13...v246.15

- https://www.openwall.com/lists/oss-security/2021/07/20/2

- https://www.cve.org/CVERecord?id=CVE-2020-13529

- https://www.cve.org/CVERecord?id=CVE-2021-33910

Resolution

SRPMS

- 8/core/systemd-246.15-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 22 Jul 2021
URL: https://advisories.mageia.org/MGASA-2021-0365.html
Type: security
CVE: CVE-2020-13529, CVE-2021-33910

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here