An update that solves one vulnerability, contains one feature and has 10 fixes can now be installed.. # Security update for systemd Announcement ID: SUSE-SU-2026:20282-1 Release Date: 2025-02-03T08:54:00Z Rating: critical References: * bsc#1200723 * bsc#1204968 * bsc#1213873 * bsc#1218110 * bsc#1221906 * bsc#1226414 * bsc#1226415 * bsc#1228091 * bsc#1228223 * bsc#1228809 * bsc#1229518 * jsc#PED-5659 Cross-References: * CVE-2022-3821 CVSS scores: * CVE-2022-3821 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2022-3821 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2022-3821 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves one vulnerability, contains one feature and has 10 fixes can now be installed. ## Description: This update for systemd fixes the following issues: * Import commit 0512d0d1fc0b54a84964281708036a46ab39c153 0512d0d1fc cgroup: Rename effective limits internal table (jsc#PED-5659) 765846b70b cgroup: Restrict effective limits with global resource provision (jsc#PED-5659) e29909088b test: Add effective cgroup limits testing (jsc#PED-5659) beacac6df0 test: Convert rlimit test to subtest of generic limit testing (jsc#PED-5659) e3b789e512 cgroup: Add EffectiveMemoryMax=, EffectiveMemoryHigh= and EffectiveTasksMax= properties (jsc#PED-5659) 5aa063ae16 bus-print-properties: prettify more unset properties a53122c9bd bus-print-properties: ignore CGROUP_LIMIT_MAX for Memory*{Current, Peak} 8418791441 cgroup: rename TasksMax structure to CGroupTasksMax * Don't try to restart the udev socket units anymore (bsc#1228809) There's currently no way to restart a socket activable service and its socket units "atomically" and safely. * Make the 32bit version of libudev.so available again (bsc#1228223) The symlink for building 32bit applications was mistakenlydropped when the content of libudev-devel was merged into systemd-devel. Provide the 32bit flavor of systemd-devel again, which should restore the plug and play support in Wine for 32bit windows applications. * Import commit up to 5aa182660dff86fe9d5cba61b0c6542bb2f2db23 (merge of v254.17) ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-73=1 ## Package List: * SUSE Linux Micro Extras 6.0 (aarch64 ppc64le s390x x86_64) * systemd-devel-254.18-1.1 * systemd-debugsource-254.18-1.1 ## References: * https://www.suse.com/security/cve/CVE-2022-3821.html * https://bugzilla.suse.com/show_bug.cgi?id=1200723 * https://bugzilla.suse.com/show_bug.cgi?id=1204968 * https://bugzilla.suse.com/show_bug.cgi?id=1213873 * https://bugzilla.suse.com/show_bug.cgi?id=1218110 * https://bugzilla.suse.com/show_bug.cgi?id=1221906 * https://bugzilla.suse.com/show_bug.cgi?id=1226414 * https://bugzilla.suse.com/show_bug.cgi?id=1226415 * https://bugzilla.suse.com/show_bug.cgi?id=1228091 * https://bugzilla.suse.com/show_bug.cgi?id=1228223 * https://bugzilla.suse.com/show_bug.cgi?id=1228809 * https://bugzilla.suse.com/show_bug.cgi?id=1229518 * https://jira.suse.com/browse/PED-5659 . Critical security update for systemd addresses one vulnerability with 10 fixes for SUSE Micro 6.0.. SUSE Linux Micro, systemd security, Linux updates, critical patch. . Severity: Critical. LinuxSecurity.com Team
An update that solves one vulnerability, contains one feature and has 7 fixes is now available. . SUSE Security Update: Security update for ceph ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2817-1 Rating: important References: #1194131 #1194875 #1195359 #1196044 #1196733 #1196785 #1200064 #1200553 SES-2515 Cross-References: CVE-2021-3979 CVSS scores: CVE-2021-3979 (SUSE): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Enterprise Storage 7.1 ______________________________________________________________________________ An update that solves one vulnerability, contains one feature and has 7 fixes is now available. Description: This update for ceph fixes the following issues: - Update to 16.2.9-536-g41a9f9a5573: + (bsc#1195359, bsc#1200553) rgw: check bucket shard init status in RGWRadosBILogTrimCR + (bsc#1194131) ceph-volume: honour osd_dmcrypt_key_size option (CVE-2021-3979) - Update to 16.2.9-158-gd93952c7eea: + cmake: check for python(\d)\.(\d+) when building boost + make-dist: patch boost source to support python 3.10 - Update to ceph-16.2.9-58-ge2e5cb80063: + (bsc#1200064, pr#480) Remove last vestiges of docker.io image paths - Update to 16.2.9.50-g7d9f12156fb: + (jsc#SES-2515) High-availability NFS export + (bsc#1196044) cephadm: prometheus: The generatorURL in alerts is only using hostname + (bsc#1196785) cephadm: avoid crashing on expected non-zero exit - Update to 16.2.7-969-g6195a460d89 + (jsc#SES-2515) High-availability NFS export - Update to v16.2.7-654-gd5a90ff46f0 + (bsc#1196733) remove build directory during %clean - Update to v16.2.7-652-gf5dc462fdb5 + (bsc#1194875) [SES7P] include/buffer: include memory Patch Instructions: To install this SUSE Security Update use the SUSE recommended installationmethods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Enterprise Storage 7.1: zypper in -t patch SUSE-Storage-7.1-2022-2817=1 Package List: - SUSE Enterprise Storage 7.1 (aarch64 x86_64): ceph-base-16.2.9.536+g41a9f9a5573-150300.3.3.1 ceph-base-debuginfo-16.2.9.536+g41a9f9a5573-150300.3.3.1 ceph-common-16.2.9.536+g41a9f9a5573-150300.3.3.1 ceph-common-debuginfo-16.2.9.536+g41a9f9a5573-150300.3.3.1 ceph-debugsource-16.2.9.536+g41a9f9a5573-150300.3.3.1 libcephfs2-16.2.9.536+g41a9f9a5573-150300.3.3.1 libcephfs2-debuginfo-16.2.9.536+g41a9f9a5573-150300.3.3.1 librados2-16.2.9.536+g41a9f9a5573-150300.3.3.1 librados2-debuginfo-16.2.9.536+g41a9f9a5573-150300.3.3.1 librbd1-16.2.9.536+g41a9f9a5573-150300.3.3.1 librbd1-debuginfo-16.2.9.536+g41a9f9a5573-150300.3.3.1 librgw2-16.2.9.536+g41a9f9a5573-150300.3.3.1 librgw2-debuginfo-16.2.9.536+g41a9f9a5573-150300.3.3.1 python3-ceph-argparse-16.2.9.536+g41a9f9a5573-150300.3.3.1 python3-ceph-common-16.2.9.536+g41a9f9a5573-150300.3.3.1 python3-cephfs-16.2.9.536+g41a9f9a5573-150300.3.3.1 python3-cephfs-debuginfo-16.2.9.536+g41a9f9a5573-150300.3.3.1 python3-rados-16.2.9.536+g41a9f9a5573-150300.3.3.1 python3-rados-debuginfo-16.2.9.536+g41a9f9a5573-150300.3.3.1 python3-rbd-16.2.9.536+g41a9f9a5573-150300.3.3.1 python3-rbd-debuginfo-16.2.9.536+g41a9f9a5573-150300.3.3.1 python3-rgw-16.2.9.536+g41a9f9a5573-150300.3.3.1 python3-rgw-debuginfo-16.2.9.536+g41a9f9a5573-150300.3.3.1 rbd-nbd-16.2.9.536+g41a9f9a5573-150300.3.3.1 rbd-nbd-debuginfo-16.2.9.536+g41a9f9a5573-150300.3.3.1 - SUSE Enterprise Storage 7.1 (noarch): cephadm-16.2.9.536+g41a9f9a5573-150300.3.3.1 References: https://www.suse.com/security/cve/CVE-2021-3979.html https://bugzilla.suse.com/1194131 https://bugzilla.suse.com/1194875 https://bugzilla.suse.com/1195359 https://bugzilla.suse.com/1196044 https://bugzilla.suse.com/1196733 https://bugzilla.suse.com/1196785 https://bugzilla.suse.com/1200064 https://bugzilla.suse.com/1200553 . SUSE Security Patch resolves urgent ceph vulnerability with essential enhancements and several remedies, boosting overall efficiency.. Ceph Security Update, SUSE Advisory, Storage Update, Important Software Fix. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability, contains one feature and has three fixes is now available. . SUSE Security Update: Security update for SUSE Manager Client Tools ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:14831-1 Rating: moderate References: #1181223 #1188977 #1190265 #1190512 ECO-3319 Cross-References: CVE-2021-21996 CVSS scores: CVE-2021-21996 (SUSE): 4.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L Affected Products: SUSE Manager Ubuntu 20.04-CLIENT-TOOLS ______________________________________________________________________________ An update that solves one vulnerability, contains one feature and has three fixes is now available. Description: This update fixes the following issues: salt: - Support querying for JSON data in external sql pillar - Exclude the full path of a download URL to prevent injection of malicious code (bsc#1190265) (CVE-2021-21996) - Fix wrong relative paths resolution with Jinja renderer when importing subdirectories scap-security-guide: - Updated to 0.1.57 release (jsc#ECO-3319) - CIS profile for RHEL 7 is updated - initial CIS profiles for Ubuntu 20.04 - Major improvement of RHEL 9 content - new release process implemented using Github actions spacecmd: - Version 4.2.13-1 * Update translation strings * configchannel_updatefile handles directory properly (bsc#1190512) * Add schedule_archivecompleted to mass archive actions (bsc#1181223) * Remove whoami from the list of unauthenticated commands (bsc#1188977) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Ubuntu 20.04-CLIENT-TOOLS: zypper in -t patchsuse-ubu204ct-client-tools-202110-14831=1 Package List: - SUSE Manager Ubuntu 20.04-CLIENT-TOOLS (all): salt-common-3002.2+ds-1+2.57.1 salt-minion-3002.2+ds-1+2.57.1 scap-security-guide-ubuntu-0.1.57-2.9.1 spacecmd-4.2.13-2.33.1 References: https://www.suse.com/security/cve/CVE-2021-21996.html https://bugzilla.suse.com/1181223 https://bugzilla.suse.com/1188977 https://bugzilla.suse.com/1190265 https://bugzilla.suse.com/1190512 . Critical patch released for SUSE Manager Client Tools to resolve significant vulnerabilities and improve overall performance.. SUSE Manager Tools, Security Update, Issue Resolution, Software Patch. . LinuxSecurity.com Team
An update that solves two vulnerabilities, contains one feature and has 5 fixes is now available. . SUSE Security Update: Security update for crmsh ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0806-1 Rating: important References: #1154927 #1178454 #1178869 #1179999 #1180137 #1180571 #1180688 ECO-1658 Cross-References: CVE-2020-35459 CVE-2021-3020 CVSS scores: CVE-2020-35459 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2020-35459 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-3020 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise High Availability 15 ______________________________________________________________________________ An update that solves two vulnerabilities, contains one feature and has 5 fixes is now available. Description: This update for crmsh fixes the following issues: - Update to version 4.3.0+20210219.5d1bf034: * Fix: hb_report: walk through hb_report process under hacluster(CVE-2020-35459, bsc#1179999; CVE-2021-3020, bsc#1180571) * Fix: bootstrap: setup authorized ssh access for hacluster(CVE-2020-35459, bsc#1179999; CVE-2021-3020, bsc#1180571) * Dev: analyze: Add analyze sublevel and put preflight_check in it(jsc#ECO-1658) * Dev: utils: change default file mod as 644 for str2file function * Dev: hb_report: Detect if any ocfs2 partitions exist * Dev: lock: give more specific error message when raise ClaimLockError * Fix: Replace mktemp() to mkstemp() for security * Fix: Remove the duplicate --cov-report html in tox. * Fix: fix some lint issues. * Fix: Replace utils.msg_info to task.info * Fix: Solve a circular import error of utils.py * Fix: hb_report: run lsof with specific ocfs2 device(bsc#1180688) * Dev: corosync:change the permission of corosync.conf to 644 * Fix: preflight_check: task: raise error when report_path isn't a directory * Fix: bootstrap: Use class Watchdog to simplify watchdog config(bsc#1154927, bsc#1178869) * Dev: Polish the sbd feature. * Dev: Replace -f with -c and run check when no parameter provide. * Fix: Fix the yes option not working * Fix: Remove useless import and show help when no input. * Dev: Correct SBD device id inconsistenc during ASR * Fix: completers: return complete start/stop resource id list correctly(bsc#1180137) * Dev: Makefile.am: change makefile to integrate preflight_check * Medium: integrate preflight_check into crmsh(jsc#ECO-1658) * Fix: bootstrap: make sure sbd device UUID was the same between nodes(bsc#1178454) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise High Availability 15: zypper in -t patch SUSE-SLE-Product-HA-15-2021-806=1 Package List: - SUSE Linux Enterprise High Availability 15 (noarch): crmsh-4.3.0+20210219.5d1bf034-3.62.3 crmsh-scripts-4.3.0+20210219.5d1bf034-3.62.3 References: https://www.suse.com/security/cve/CVE-2020-35459.html https://www.suse.com/security/cve/CVE-2021-3020.html https://bugzilla.suse.com/1154927 https://bugzilla.suse.com/1178454 https://bugzilla.suse.com/1178869 https://bugzilla.suse.com/1179999 https://bugzilla.suse.com/1180137 https://bugzilla.suse.com/1180571 https://bugzilla.suse.com/1180688 . Crucial SUSE security patch addresses various vulnerabilities in crmsh, bolstering system robustness and dependability.. SUSE Security Update, Crmsh Fixes, Linux System Update. . Severity: Important. LinuxSecurity.com Team
A newer version of waagent is needed for several features of the Azure platform. For Debian 8 "Jessie", this problem has been fixed in version . Package : waagent Version : 2.2.18-3~deb8u1 A newer version of waagent is needed for several features of the Azure platform. For Debian 8 "Jessie", this problem has been fixed in version 2.2.18-3~deb8u1. We recommend that you upgrade your waagent packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Package : waagent Version : 2.2.18-3~deb8u1 A newer version of waagent is needed for several feature. newer, version, waagent, needed, features, azure, platform, debian, 'jessi. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.