Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

openSUSE Leap 15.0: Security Update for Systemd Buffer Overflow

opensuse
Calendar Grey November 10, 2018
Dist Opensuse Esm H88
Crucial Fedora patch for kernel resolves memory leak and various vulnerabilities, enhancing system stability and protection.
An update that solves two vulnerabilities and has 16 fixes is now available.

Description

This update for systemd fixes the following issues:

Security issues fixed:

- CVE-2018-15688: A buffer overflow vulnerability in the dhcp6 client of

systemd allowed a malicious dhcp6 server to overwrite heap memory in

systemd-networkd. (bsc#1113632)

- CVE-2018-15686: A vulnerability in unit_deserialize of systemd allows an

attacker to supply arbitrary state across systemd re-execution via

NotifyAccess. This can be used to improperly influence systemd execution

and possibly lead to root privilege escalation. (bsc#1113665)

Non security issues fixed:

- dhcp6: split assert_return() to be more debuggable when hit

- core: skip unit deserialization and move to the next one when

unit_deserialize() fails

- core: properly handle deserialization of unknown unit types (#6476)

- core: don't create Requires for workdir if "missing ok" (bsc#1113083)

- logind: use manager_get_user_by_pid() where appropriate

- logind: rework...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2018-1382=1

Package List

- openSUSE Leap 15.0 (i586 x86_64):

libsystemd0-234-lp150.20.9.1

libsystemd0-debuginfo-234-lp150.20.9.1

libsystemd0-mini-234-lp150.20.9.1

libsystemd0-mini-debuginfo-234-lp150.20.9.1

libudev-devel-234-lp150.20.9.1

libudev-mini-devel-234-lp150.20.9.1

libudev-mini1-234-lp150.20.9.1

libudev-mini1-debuginfo-234-lp150.20.9.1

libudev1-234-lp150.20.9.1

libudev1-debuginfo-234-lp150.20.9.1

nss-myhostname-234-lp150.20.9.1

nss-myhostname-debuginfo-234-lp150.20.9.1

nss-mymachines-234-lp150.20.9.1

nss-mymachines-debuginfo-234-lp150.20.9.1

nss-systemd-234-lp150.20.9.1

nss-systemd-debuginfo-234-lp150.20.9.1

systemd-234-lp150.20.9.1

systemd-container-234-lp150.20.9.1

systemd-container-debuginfo-234-lp150.20.9.1

systemd-coredump-234-lp150.20.9.1

systemd-coredump-debuginfo-234-lp150.20.9.1

systemd-debuginfo-234-lp150.20.9.1

systemd-debugsource-234-lp150.20.9.1

systemd-devel-234-lp150.20.9.1

systemd-logger-234-lp150.20.9.1

systemd-mini-234-lp150.20.9.1

systemd-mini-container-mini-234-lp150.20.9.1

systemd-mini-container-mini-debuginf...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-15686.html

https://www.suse.com/security/cve/CVE-2018-15688.html

https://bugzilla.suse.com/1089761

https://bugzilla.suse.com/1090944

https://bugzilla.suse.com/1091677

https://bugzilla.suse.com/1093753

https://bugzilla.suse.com/1101040

https://bugzilla.suse.com/1102908

https://bugzilla.suse.com/1105031

https://bugzilla.suse.com/1107640

https://bugzilla.suse.com/1107941

https://bugzilla.suse.com/1109197

https://bugzilla.suse.com/1109252

https://bugzilla.suse.com/1110445

https://bugzilla.suse.com/1112024

https://bugzilla.suse.com/1113083

https://bugzilla.suse.com/1113632

https://bugzilla.suse.com/1113665

https://bugzilla.suse.com/1114135

https://bugzilla.suse.com/991901

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:3695-1
Rating: important
Affected Products: openSUSE Leap 15.0 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here