This update for systemd fixes the following issues:
Security issues fixed:
- CVE-2018-15688: A buffer overflow vulnerability in the dhcp6 client of
systemd allowed a malicious dhcp6 server to overwrite heap memory in
systemd-networkd. (bsc#1113632)
- CVE-2018-15686: A vulnerability in unit_deserialize of systemd allows an
attacker to supply arbitrary state across systemd re-execution via
NotifyAccess. This can be used to improperly influence systemd execution
and possibly lead to root privilege escalation. (bsc#1113665)
Non-security issues fixed:
- dhcp6: split assert_return() to be more debuggable when hit
- core: skip unit deserialization and move to the next one when
unit_deserialize() fails
- core: properly handle deserialization of unknown unit types (#6476)
- core: don't create Requires for workdir if "missing ok" (bsc#1113083)
- logind: use manager_get_user_by_pid() where appropriate
- logind: rework...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2018-1423=1
- openSUSE Leap 42.3 (i586 x86_64):
libsystemd0-228-62.1
libsystemd0-debuginfo-228-62.1
libsystemd0-mini-228-62.1
libsystemd0-mini-debuginfo-228-62.1
libudev-devel-228-62.1
libudev-mini-devel-228-62.1
libudev-mini1-228-62.1
libudev-mini1-debuginfo-228-62.1
libudev1-228-62.1
libudev1-debuginfo-228-62.1
nss-myhostname-228-62.1
nss-myhostname-debuginfo-228-62.1
nss-mymachines-228-62.1
nss-mymachines-debuginfo-228-62.1
systemd-228-62.1
systemd-debuginfo-228-62.1
systemd-debugsource-228-62.1
systemd-devel-228-62.1
systemd-logger-228-62.1
systemd-mini-228-62.1
systemd-mini-debuginfo-228-62.1
systemd-mini-debugsource-228-62.1
systemd-mini-devel-228-62.1
systemd-mini-sysvinit-228-62.1
systemd-sysvinit-228-62.1
udev-228-62.1
udev-debuginfo-228-62.1
udev-mini-228-62.1
udev-mini-debuginfo-228-62.1
- openSUSE Leap 42.3 (x86_64):
libsystemd0-32bit-228-62.1
libsystemd0-debuginfo-32bit-228-62.1
libudev1-32bit-228-62.1
libudev1-debuginfo-32bit-228-62.1
nss-myhostname-32bit-228-62.1
nss-myhostname-debuginfo-32bit-228-62.1
systemd-32bit-22...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2018-15686.html
https://www.suse.com/security/cve/CVE-2018-15688.html
https://bugzilla.suse.com/1106923
https://bugzilla.suse.com/1108835
https://bugzilla.suse.com/1109252
https://bugzilla.suse.com/1110445
https://bugzilla.suse.com/1111278
https://bugzilla.suse.com/1112024
https://bugzilla.suse.com/1113083
https://bugzilla.suse.com/1113632
https://bugzilla.suse.com/1113665
--
Get the latest Linux and open source security news straight to your inbox.