Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2021:3348-1 Moderate: Systemd Fix for Issue CVE-2021-33910

suse
Calendar Grey October 12, 2021
Scroller Suse
SUSE issues a critical Security Patch for systemd addressing a vital vulnerability. Upgrade immediately to boost system efficiency and reliability.
An update that solves one vulnerability, contains one feature and has 8 fixes is now available

Summary

This update for systemd fixes the following issues: - CVE-2021-33910: Fixed use of strdupa() on a path (bsc#1188063). - logind: terminate cleanly on SIGTERM/SIGINT (bsc#1188018). - Adopting BFQ to control I/O (jsc#SLE-21032, bsc#1134353). - Rules weren't applied to dm devices (multipath) (bsc#1188713). - Ignore obsolete "elevator" kernel parameter (bsc#1184994, bsc#1190234). - Make sure the versions of both udev and systemd packages are always the same (bsc#1189480). - Avoid error message when udev is updated due to udev being already active when the sockets are started again (bsc#1188291). - Allow the systemd sysusers config files to be overriden during system installation (bsc#1171962).

References

#1134353 #1171962 #1184994 #1188018 #1188063

#1188291 #1188713 #1189480 #1190234 SLE-21032

Cross- CVE-2021-33910

CVSS scores:

CVE-2021-33910 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVE-2021-33910 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products:

SUSE Linux Enterprise Module for Basesystem 15-SP2

https://www.suse.com/security/cve/CVE-2021-33910.html

https://bugzilla.suse.com/1134353

https://bugzilla.suse.com/1171962

https://bugzilla.suse.com/1184994

https://bugzilla.suse.com/1188018

https://bugzilla.suse.com/1188063

https://bugzilla.suse.com/1188291

https://bugzilla.suse.com/1188713

https://bugzilla.suse.com/1189480

https://bugzilla.suse.com/1190234

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:3348-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.