Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

openSUSE Leap 15.0: 2019:0255-1 Important: systemd Crash Risk

opensuse
Calendar Grey February 27, 2019
Dist Opensuse Esm H88
openSUSE Security Update: Security update for systemd ______________________________________________
An update that solves one vulnerability and has 7 fixes is now available.

Description

This update for systemd fixes the following issues:

- CVE-2019-6454: Overlong DBUS messages could be used to crash systemd

(bsc#1125352)

- units: make sure initrd-cleanup.service terminates before switching to

rootfs (bsc#1123333)

- logind: fix bad error propagation

- login: log session state "closing" (as well as New/Removed)

- logind: fix borked r check

- login: don't remove all devices from PID1 when only one was removed

- login: we only allow opening character devices

- login: correct comment in session_device_free()

- login: remember that fds received from PID1 need to be removed eventually

- login: fix FDNAME in call to sd_pid_notify_with_fds()

- logind: fd 0 is a valid fd

- logind: rework sd_eviocrevoke()

- logind: check file is device node before using .st_rdev

- logind: use the new FDSTOREREMOVE=1 sd_notify() message (bsc#1124153)

- core: add a new sd_notify() message for removing fds from the FD store

again

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2019-255=1

Package List

- openSUSE Leap 15.0 (i586 x86_64):

libsystemd0-234-lp150.20.15.1

libsystemd0-debuginfo-234-lp150.20.15.1

libsystemd0-mini-234-lp150.20.15.1

libsystemd0-mini-debuginfo-234-lp150.20.15.1

libudev-devel-234-lp150.20.15.1

libudev-mini-devel-234-lp150.20.15.1

libudev-mini1-234-lp150.20.15.1

libudev-mini1-debuginfo-234-lp150.20.15.1

libudev1-234-lp150.20.15.1

libudev1-debuginfo-234-lp150.20.15.1

nss-myhostname-234-lp150.20.15.1

nss-myhostname-debuginfo-234-lp150.20.15.1

nss-mymachines-234-lp150.20.15.1

nss-mymachines-debuginfo-234-lp150.20.15.1

nss-systemd-234-lp150.20.15.1

nss-systemd-debuginfo-234-lp150.20.15.1

systemd-234-lp150.20.15.1

systemd-container-234-lp150.20.15.1

systemd-container-debuginfo-234-lp150.20.15.1

systemd-coredump-234-lp150.20.15.1

systemd-coredump-debuginfo-234-lp150.20.15.1

systemd-debuginfo-234-lp150.20.15.1

systemd-debugsource-234-lp150.20.15.1

systemd-devel-234-lp150.20.15.1

systemd-logger-234-lp150.20.15.1

systemd-mini-234-lp150.20.15.1

systemd-mini-container-mini-234-lp150.20.15.1

systemd-m...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2019-6454.html

https://bugzilla.suse.com/1117025

https://bugzilla.suse.com/1121563

https://bugzilla.suse.com/1122000

https://bugzilla.suse.com/1123333

https://bugzilla.suse.com/1123727

https://bugzilla.suse.com/1123892

https://bugzilla.suse.com/1124153

https://bugzilla.suse.com/1125352

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:0255-1
Rating: important
Affected Products: openSUSE Leap 15.0 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here