Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE Vulnerability Alert 2022:4785-2 for CoreUtils Directory Traversal Risk

suse
Calendar Grey October 19, 2021
Scroller Suse
The latest patch for SUSE's util-linux addresses a severe vulnerability related to buffer overflow, reinforcing the reliability and security of the system.
An update that solves one vulnerability and has 19 fixes is now available

Summary

This update for util-linux fixes the following issues: - CVE-2021-37600: Fixed an integer overflow which could lead to buffer overflow in get_sem_elements. (bsc#1188921) - Prevent outdated pam files (bsc#1082293, bsc#1081947#c68). - Do not trim read-only volumes (bsc#1106214). - libmount: To prevent incorrect behavior, recognize more pseudofs and netfs (bsc#1122417). - raw.service: Add RemainAfterExit=yes (bsc#1135534). - agetty: Reload issue only if it is really needed (bsc#1085196) - agetty: Return previous response of agetty for special characters (bsc#1085196, bsc#1125886) - blockdev: Do not fail --report on kpartx-style partitions on multipath. (bsc#1168235) - nologin: Add support for -c to prevent error from su -c. (bsc#1151708)

References

#1081947 #1082293 #1084671 #1085196 #1106214

#1122417 #1125886 #1135534 #1135708 #1151708

#1168235 #1168389 #1169006 #1174942 #1175514

#1175623 #1178236 #1178554 #1178825 #1188921

Cross- CVE-2021-37600

CVSS scores:

CVE-2021-37600 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2021-37600 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:

SUSE OpenStack Cloud Crowbar 8

SUSE OpenStack Cloud 8

SUSE Linux Enterprise Server for SAP 12-SP3

SUSE Linux Enterprise Server 12-SP3-LTSS

SUSE Linux Enterprise Server 12-SP3-BCL

HPE Helion Openstack 8

https://www.suse.com/security/cve/CVE-2021-37600.html

https://bugzilla.suse.com/1081947

https://bugzilla.suse.com/1082293

https://bugzilla.suse.com/1084671

https://bu...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:3463-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.