Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

SUSE Linux Enterprise 15: 2019:0426-1 Important: Systemd DoS Fix

suse
Calendar Grey February 18, 2019
Dist Suse Esm H88
Crucial SUSE patch for systemd addresses a vulnerability and introduces 7 improvements. Maintain your security!
An update that solves one vulnerability and has 7 fixes is now available

Summary

This update for systemd fixes the following issues: - CVE-2019-6454: Overlong DBUS messages could be used to crash systemd (bsc#1125352) - units: make sure initrd-cleanup.service terminates before switching to rootfs (bsc#1123333) - logind: fix bad error propagation - login: log session state "closing" (as well as New/Removed) - logind: fix borked r check - login: don't remove all devices from PID1 when only one was removed - login: we only allow opening character devices - login: correct comment in session_device_free() - login: remember that fds received from PID1 need to be removed eventually - login: fix FDNAME in call to sd_pid_notify_with_fds() - logind: fd 0 is a valid fd - logind: rework sd_eviocrevoke() - logind: check file is device node before using .st_rdev

References

#1117025 #1121563 #1122000 #1123333 #1123727

#1123892 #1124153 #1125352

Cross- CVE-2019-6454

Affected Products:

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2019-6454.html

https://bugzilla.suse.com/1117025

https://bugzilla.suse.com/1121563

https://bugzilla.suse.com/1122000

https://bugzilla.suse.com/1123333

https://bugzilla.suse.com/1123727

https://bugzilla.suse.com/1123892

https://bugzilla.suse.com/1124153

https://bugzilla.suse.com/1125352

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:0426-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here