MGASA-2022-0429 - Updated systemd packages fix security vulnerability

Publication date: 17 Nov 2022
URL: https://advisories.mageia.org/MGASA-2022-0429.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2022-3821

buffer overrun in format_timespan() function (bsc#1204968) (CVE-2022-3821)
Import commit 0cd50eedcc0692c1f907b24424215f8db7d3b428
  0469b9f2bc pstore: do not try to load all known pstore modules
  ad05f54439 pstore: Run after modules are loaded
  ccad817445 core: Add trigger limit for path units
  281d818fe3 core/mount: also add default before dependency for
  automount mount units
  ffe5b4afa8 logind: fix crash in logind on user-specified message string
Document udev naming scheme (bsc#1204179)
  Make "sle15-sp3" net naming scheme still available for backward
  compatibility reason

References:
- https://bugs.mageia.org/show_bug.cgi?id=31138
- https://lists.suse.com/pipermail/sle-security-updates/2022-November/012929.html
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/T7UQBLKONTL3NZED3YWCSO3BCXRPP3DW/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3821

SRPMS:
- 8/core/systemd-246.16-3.mga8

Mageia 2022-0429: systemd security update

buffer overrun in format_timespan() function (bsc#1204968) (CVE-2022-3821) Import commit 0cd50eedcc0692c1f907b24424215f8db7d3b428 0469b9f2bc pstore: do not try to load all known ...

Summary

buffer overrun in format_timespan() function (bsc#1204968) (CVE-2022-3821) Import commit 0cd50eedcc0692c1f907b24424215f8db7d3b428 0469b9f2bc pstore: do not try to load all known pstore modules ad05f54439 pstore: Run after modules are loaded ccad817445 core: Add trigger limit for path units 281d818fe3 core/mount: also add default before dependency for automount mount units ffe5b4afa8 logind: fix crash in logind on user-specified message string Document udev naming scheme (bsc#1204179) Make "sle15-sp3" net naming scheme still available for backward compatibility reason

References

- https://bugs.mageia.org/show_bug.cgi?id=31138

- https://lists.suse.com/pipermail/sle-security-updates/2022-November/012929.html

- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/T7UQBLKONTL3NZED3YWCSO3BCXRPP3DW/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3821

Resolution

MGASA-2022-0429 - Updated systemd packages fix security vulnerability

SRPMS

- 8/core/systemd-246.16-3.mga8

Severity
Publication date: 17 Nov 2022
URL: https://advisories.mageia.org/MGASA-2022-0429.html
Type: security
CVE: CVE-2022-3821

Related News