Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

SUSE Linux Enterprise 11-SP3 Advisory: Critical Util-Linux Buffer Overflow

suse
Calendar Grey April 14, 2021
Dist Suse Esm H88
Critical announcement for SUSE Linux Enterprise regarding a buffer overflow issue identified in util-linux, accompanied by various corrective measures.
An update that solves one vulnerability and has 9 fixes is now available

Summary

This update for util-linux fixes the following issues: - CVE-2015-5218: Prevent colcrt buffer overflow. (bsc#949754) These non-security issues were fixed: - Mount crashes when trying to mount `shmfs` while `SELinux` is active. (bsc#1040414) - Fix `lsblk -f` on `CCISS` and other devices with nodes in `/dev` subdirectory. (bsc#924994) - Fix `script(1)` hang caused by mis-interpreted EOF on big-endian platforms. (bsc#930236) - Do not segfault when TERM is not defined or wrong. (bsc#903440) - Update and fix mount XFS documentation. (bsc#925705) - Fix recognition of `/dev/dm-N` partitions names. (bsc#931607) - Follow SUSE Linux Enterprise 11 device mapper partition names configuration. (bsc#931607) - Fix recognition of device mapper partitions. (bsc#923904)

References

#1040414 #903440 #903738 #923777 #923904

#924994 #925705 #930236 #931607 #949754

Cross- CVE-2015-5218

Affected Products:

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2015-5218.html

https://bugzilla.suse.com/1040414

https://bugzilla.suse.com/903440

https://bugzilla.suse.com/903738

https://bugzilla.suse.com/923777

https://bugzilla.suse.com/923904

https://bugzilla.suse.com/924994

https://bugzilla.suse.com/925705

https://bugzilla.suse.com/930236

https://bugzilla.suse.com/931607

https://bugzilla.suse.com/949754

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:14693-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here