Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE 15-SP4: 2022:3999-1 Moderate: Systemd Buffer Overrun

suse
Calendar Grey November 15, 2022
Dist Suse Esm H88
SUSE has issued a critical security patch for Systemd addressing a potential buffer overflow flaw. Affected systems should be patched without delay.
An update that solves one vulnerability and has one errata is now available

Summary

This update for systemd fixes the following issues: - CVE-2022-3821: Fixed buffer overrun in format_timespan() function (bsc#1204968). - Import commit 0cd50eedcc0692c1f907b24424215f8db7d3b428 * 0469b9f2bc pstore: do not try to load all known pstore modules * ad05f54439 pstore: Run after modules are loaded * ccad817445 core: Add trigger limit for path units * 281d818fe3 core/mount: also add default before dependency for automount mount units * ffe5b4afa8 logind: fix crash in logind on user-specified message string - Document udev naming scheme (bsc#1204179) - Make "sle15-sp3" net naming scheme still available for backward compatibility reason

References

#1204179 #1204968

Cross- CVE-2022-3821

CVSS scores:

CVE-2022-3821 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVE-2022-3821 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products:

SUSE Linux Enterprise Desktop 15-SP4

SUSE Linux Enterprise High Performance Computing 15-SP4

SUSE Linux Enterprise Micro 5.3

SUSE Linux Enterprise Module for Basesystem 15-SP4

SUSE Linux Enterprise Server 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15-SP4

SUSE Manager Proxy 4.3

SUSE Manager Retail Branch Server 4.3

SUSE Manager Server 4.3

openSUSE Leap 15.4

https://www.suse.com/security/cve/CVE-2022-3821.html

https://bugzilla.suse.com/1204179

https://bugzilla.suse.com/1204968

Announcement ID: SUSE-SU-2022:3999-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here