Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libnl-1_1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3207-1 Rating: moderate References: #1020123 Cross-References: CVE-2017-0386 CVSS scores: CVE-2017-0386 (NVD) : 7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2017-0386 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libnl-1_1 fixes the following issues: - CVE-2017-0386: Fixed an issue that could enable a local malicious application to execute arbitrary code within the context of a different process. This only affects setups were libnl is passed untrusted arguments. (bsc#1020123) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-3207=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-3207=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libnl-1_1-debugsource-1.1.4-6.3.1 libnl-1_1-devel-1.1.4-6.3.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libnl-1_1-debugsource-1.1.4-6.3.1 libnl1-1.1.4-6.3.1 libnl1-debuginfo-1.1.4-6.3.1 - SUSE Linux EnterpriseServer 12-SP5 (s390x x86_64): libnl1-32bit-1.1.4-6.3.1 libnl1-debuginfo-32bit-1.1.4-6.3.1 References: https://www.suse.com/security/cve/CVE-2017-0386.html https://bugzilla.suse.com/1020123 . Patch for libnl-1_1 resolves localized execution flaws in SUSE 12-SP5, mitigating arbitrary code execution dangers.. SUSE Update, libnl Security, Local Execution Fix, Security Patch. . Severity: Important. LinuxSecurity.com Team
The package libnl before version 3.3.0-1 is vulnerable to privilege escalation. . Arch Linux Security Advisory ASA-201706-35 ========================================= Severity: Medium Date : 2017-06-28 CVE-ID : CVE-2017-0553 Package : libnl Type : privilege escalation Remote : No Link : https://security.archlinux.org/AVG-292 Summary ====== The package libnl before version 3.3.0-1 is vulnerable to privilege escalation. Resolution ========= Upgrade to 3.3.0-1. # pacman -Syu "libnl> =3.3.0-1" The problem has been fixed upstream in version 3.3.0. Workaround ========= None. Description ========== An integer overflow vulnerability has been found in the nlmsg_reserve() function of libnl < 3.3.0, allowing local privilege escalation. Impact ===== A local attacker is able to escalate privileges. References ========= http://git.infradead.org/users/tgr/libnl.git/commitdiff/3e18948f17148e6a3c4255bdeaaf01ef6081ceeb?hp=3dd2a0f26fa59896b4b4a262cf309a4be4aa70d3 https://security.archlinux.org/CVE-2017-0553 . The Debian Security Advisory DSA-2021-005 addresses a high severity vulnerability in OpenSSL prior to version 1.1.1k.. Arch Linux, libnl, privilege escalation, security advisory. . Severity: Medium. LinuxSecurity.com Team
libnl could be made to run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-3311-2 June 19, 2017 libnl3 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: libnl could be made to run programs as an administrator. Software Description: - libnl3: library for dealing with netlink sockets Details: USN-3311-1 fixed a vulnerability in libnl. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that libnl incorrectly handled memory when performing certain operations. A local attacker could possibly use this issue to cause libnl to crash, resulting in a denial of service, or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: libnl-3-200 3.2.3-2ubuntu2.1 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3311-2 https://ubuntu.com/security/notices/USN-3311-1 CVE-2017-0553 . =========================================================================Ubuntu Security Notice USN-. libnl, programs, administrator, ===========================================. . Severity: Critical. LinuxSecurity.com Team
libnl could be made to crash or run programs.. =========================================================================Ubuntu Security Notice USN-3311-1 June 06, 2017 libnl3 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 17.04 - Ubuntu 16.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: libnl could be made to crash or run programs. Software Description: - libnl3: library for dealing with netlink sockets Details: It was discovered that libnl incorrectly handled memory when performing certain operations. A local attacker could possibly use this issue to cause libnl to crash, resulting in a denial of service, or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 17.04: libnl-3-200 3.2.29-0ubuntu2.1 Ubuntu 16.10: libnl-3-200 3.2.27-1ubuntu0.16.10.1 Ubuntu 16.04 LTS: libnl-3-200 3.2.27-1ubuntu0.16.04.1 Ubuntu 14.04 LTS: libnl-3-200 3.2.21-1ubuntu4.1 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3311-1 CVE-2017-0553 Package Information: https://launchpad.net/ubuntu/+source/libnl3/3.2.29-0ubuntu2.1 https://launchpad.net/ubuntu/+source/libnl3/3.2.27-1ubuntu0.16.10.1 https://launchpad.net/ubuntu/+source/libnl3/3.2.27-1ubuntu0.16.04.1 https://launchpad.net/ubuntu/+source/libnl3/3.2.21-1ubuntu4.1 . Ubuntu Security Notice USN-3312-1 reports on a critical flaw in libcurl that poses threats to various distributions, potentially leading to data leaks.. Ubuntu Security Notice, libnl3, Denial Of Service, Memory Handling Issue. . Severity: Critical. LinuxSecurity.com Team
It was discovered that there was a FIXME in libnl, a FIXME... For Debian 7 "Wheezy", this issue has been fixed in libnl version 1.1-7+deb7u1. . Hash: SHA256 Package : libnl Version : 1.1-7+deb7u1 CVE ID : CVE-2017-0553 Debian Bug : It was discovered that there was a FIXME in libnl, a FIXME... For Debian 7 "Wheezy", this issue has been fixed in libnl version 1.1-7+deb7u1. We recommend that you upgrade your libnl packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Get the latest Linux and open source security news straight to your inbox.