This update for systemd fixes the following issues:
Security vulnerability fixed:
- CVE-2019-6454: Fixed a crash of PID1 by sending specially crafted D-BUS
message on the system bus by an unprivileged user (bsc#1125352)
Other bug fixes and changes:
- journal-remote: set a limit on the number of fields in a message
- journal-remote: verify entry length from header
- journald: set a limit on the number of fields (1k)
- journald: do not store the iovec entry for process commandline on stack
- core: include Found state in device dumps
- device: fix serialization and deserialization of DeviceFound
- fix path in btrfs rule (#6844)
- assemble multidevice btrfs volumes without external tools (#6607)
(bsc#1117025)
- Update systemd-system.conf.xml (bsc#1122000)
- units: inform user that the default target is started after exiting from
rescue or emergency mode
- manager: don't skip sigchld handler for main and control pid for
...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2019-268=1
- openSUSE Leap 42.3 (i586 x86_64):
libsystemd0-228-68.1
libsystemd0-debuginfo-228-68.1
libsystemd0-mini-228-68.1
libsystemd0-mini-debuginfo-228-68.1
libudev-devel-228-68.1
libudev-mini-devel-228-68.1
libudev-mini1-228-68.1
libudev-mini1-debuginfo-228-68.1
libudev1-228-68.1
libudev1-debuginfo-228-68.1
nss-myhostname-228-68.1
nss-myhostname-debuginfo-228-68.1
nss-mymachines-228-68.1
nss-mymachines-debuginfo-228-68.1
systemd-228-68.1
systemd-debuginfo-228-68.1
systemd-debugsource-228-68.1
systemd-devel-228-68.1
systemd-logger-228-68.1
systemd-mini-228-68.1
systemd-mini-debuginfo-228-68.1
systemd-mini-debugsource-228-68.1
systemd-mini-devel-228-68.1
systemd-mini-sysvinit-228-68.1
systemd-sysvinit-228-68.1
udev-228-68.1
udev-debuginfo-228-68.1
udev-mini-228-68.1
udev-mini-debuginfo-228-68.1
- openSUSE Leap 42.3 (x86_64):
libsystemd0-32bit-228-68.1
libsystemd0-debuginfo-32bit-228-68.1
libudev1-32bit-228-68.1
libudev1-debuginfo-32bit-228-68.1
nss-myhostname-32bit-228-68.1
nss-myhostname-debuginfo-32bit-228-68.1
systemd-32bit-22...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2019-6454.html
https://bugzilla.suse.com/1111498
https://bugzilla.suse.com/1117025
https://bugzilla.suse.com/1117382
https://bugzilla.suse.com/1120658
https://bugzilla.suse.com/1122000
https://bugzilla.suse.com/1122344
https://bugzilla.suse.com/1123333
https://bugzilla.suse.com/1123892
https://bugzilla.suse.com/1125352
--
Get the latest Linux and open source security news straight to your inbox.