Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE Leap 15.2: openSUSE-SU-2021:1370-1 Moderate: systemd Fix

opensuse
Calendar Grey October 18, 2021
Dist Opensuse Esm H88
A crucial patch addresses a systemd bug in openSUSE Leap 15.2, improving both security measures and performance through various corrections.
An update that solves one vulnerability, contains one feature and has 8 fixes is now available

Description

This update for systemd fixes the following issues:

- CVE-2021-33910: Fixed use of strdupa() on a path (bsc#1188063).

- logind: terminate cleanly on SIGTERM/SIGINT (bsc#1188018).

- Adopting BFQ to control I/O (jsc#SLE-21032, bsc#1134353).

- Rules weren't applied to dm devices (multipath) (bsc#1188713).

- Ignore obsolete "elevator" kernel parameter (bsc#1184994, bsc#1190234).

- Make sure the versions of both udev and systemd packages are always the

same (bsc#1189480).

- Avoid error message when udev is updated due to udev being already

active when the sockets are started again (bsc#1188291).

- Allow the systemd sysusers config files to be overriden during system

installation (bsc#1171962).

This update was imported from the SUSE:SLE-15:Update update project.

Special Instructions and Notes:

Please reboot the system after installing this update.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-1370=1

Package List

- openSUSE Leap 15.2 (i586 x86_64):

libsystemd0-234-lp152.31.34.1

libsystemd0-debuginfo-234-lp152.31.34.1

libsystemd0-mini-234-lp152.31.34.1

libsystemd0-mini-debuginfo-234-lp152.31.34.1

libudev-devel-234-lp152.31.34.1

libudev-mini-devel-234-lp152.31.34.1

libudev-mini1-234-lp152.31.34.1

libudev-mini1-debuginfo-234-lp152.31.34.1

libudev1-234-lp152.31.34.1

libudev1-debuginfo-234-lp152.31.34.1

nss-myhostname-234-lp152.31.34.1

nss-myhostname-debuginfo-234-lp152.31.34.1

nss-mymachines-234-lp152.31.34.1

nss-mymachines-debuginfo-234-lp152.31.34.1

nss-systemd-234-lp152.31.34.1

nss-systemd-debuginfo-234-lp152.31.34.1

systemd-234-lp152.31.34.1

systemd-container-234-lp152.31.34.1

systemd-container-debuginfo-234-lp152.31.34.1

systemd-coredump-234-lp152.31.34.1

systemd-coredump-debuginfo-234-lp152.31.34.1

systemd-debuginfo-234-lp152.31.34.1

systemd-debugsource-234-lp152.31.34.1

systemd-devel-234-lp152.31.34.1

systemd-journal-remote-234-lp152.31.34.1

systemd-journal-remote-debuginfo-234-lp152.31.34.1

systemd-logger-234-lp152.3...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2021-33910.html

https://bugzilla.suse.com/1134353

https://bugzilla.suse.com/1171962

https://bugzilla.suse.com/1184994

https://bugzilla.suse.com/1188018

https://bugzilla.suse.com/1188063

https://bugzilla.suse.com/1188291

https://bugzilla.suse.com/1188713

https://bugzilla.suse.com/1189480

https://bugzilla.suse.com/1190234

Announcement ID: openSUSE-SU-2021:1370-1
Rating: moderate
Affected Products: openSUSE Leap 15.2 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here