This update for systemd fixes the following issues:
Security issues fixed:
- CVE-2018-15688: A buffer overflow vulnerability in the dhcp6 client of
systemd allowed a malicious dhcp6 server to overwrite heap memory in
systemd-networkd. (bsc#1113632)
- CVE-2018-15686: A vulnerability in unit_deserialize of systemd allows an
attacker to supply arbitrary state across systemd re-execution via
NotifyAccess. This can be used to improperly influence systemd execution
and possibly lead to root privilege escalation. (bsc#1113665)
Non security issues fixed:
- dhcp6: split assert_return() to be more debuggable when hit
- core: skip unit deserialization and move to the next one when
unit_deserialize() fails
- core: properly handle deserialization of unknown unit types (#6476)
- core: don't create Requires for workdir if "missing ok" (bsc#1113083)
- logind: use manager_get_user_by_pid() where appropriate
- logind: rework...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-1382=1
- openSUSE Leap 15.0 (i586 x86_64):
libsystemd0-234-lp150.20.9.1
libsystemd0-debuginfo-234-lp150.20.9.1
libsystemd0-mini-234-lp150.20.9.1
libsystemd0-mini-debuginfo-234-lp150.20.9.1
libudev-devel-234-lp150.20.9.1
libudev-mini-devel-234-lp150.20.9.1
libudev-mini1-234-lp150.20.9.1
libudev-mini1-debuginfo-234-lp150.20.9.1
libudev1-234-lp150.20.9.1
libudev1-debuginfo-234-lp150.20.9.1
nss-myhostname-234-lp150.20.9.1
nss-myhostname-debuginfo-234-lp150.20.9.1
nss-mymachines-234-lp150.20.9.1
nss-mymachines-debuginfo-234-lp150.20.9.1
nss-systemd-234-lp150.20.9.1
nss-systemd-debuginfo-234-lp150.20.9.1
systemd-234-lp150.20.9.1
systemd-container-234-lp150.20.9.1
systemd-container-debuginfo-234-lp150.20.9.1
systemd-coredump-234-lp150.20.9.1
systemd-coredump-debuginfo-234-lp150.20.9.1
systemd-debuginfo-234-lp150.20.9.1
systemd-debugsource-234-lp150.20.9.1
systemd-devel-234-lp150.20.9.1
systemd-logger-234-lp150.20.9.1
systemd-mini-234-lp150.20.9.1
systemd-mini-container-mini-234-lp150.20.9.1
systemd-mini-container-mini-debuginf...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2018-15686.html
https://www.suse.com/security/cve/CVE-2018-15688.html
https://bugzilla.suse.com/1089761
https://bugzilla.suse.com/1090944
https://bugzilla.suse.com/1091677
https://bugzilla.suse.com/1093753
https://bugzilla.suse.com/1101040
https://bugzilla.suse.com/1102908
https://bugzilla.suse.com/1105031
https://bugzilla.suse.com/1107640
https://bugzilla.suse.com/1107941
https://bugzilla.suse.com/1109197
https://bugzilla.suse.com/1109252
https://bugzilla.suse.com/1110445
https://bugzilla.suse.com/1112024
https://bugzilla.suse.com/1113083
https://bugzilla.suse.com/1113632
https://bugzilla.suse.com/1113665
https://bugzilla.suse.com/1114135
https://bugzilla.suse.com/991901
--
Get the latest Linux and open source security news straight to your inbox.