Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libnl3 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3208-1 Rating: moderate References: #1020123 Cross-References: CVE-2017-0386 CVSS scores: CVE-2017-0386 (NVD) : 7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2017-0386 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libnl3 fixes the following issues: - CVE-2017-0386: Fixed an issue that could enable a local malicious application to execute arbitrary code within the context of a different process. This only affects setups were libnl is passed untrusted arguments. (bsc#1020123) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-3208=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-3208=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libnl3-debugsource-3.2.23-4.7.1 libnl3-devel-3.2.23-4.7.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libnl3-200-3.2.23-4.7.1 libnl3-200-debuginfo-3.2.23-4.7.1 libnl3-debugsource-3.2.23-4.7.1 - SUSE Linux EnterpriseServer 12-SP5 (s390x x86_64): libnl3-200-32bit-3.2.23-4.7.1 libnl3-200-debuginfo-32bit-3.2.23-4.7.1 - SUSE Linux Enterprise Server 12-SP5 (noarch): libnl-config-3.2.23-4.7.1 References: https://www.suse.com/security/cve/CVE-2017-0386.html https://bugzilla.suse.com/1020123 . SUSE Security Patch for libnl3 addresses a significant flaw allowing local code execution, improving overall system safety.. SUSE Security Update, libnl3 fix, local code execution threat, software patch. . LinuxSecurity.com Team
An integer overflow leading to a heap-buffer overflow was found in the libnl library. An attacker could use this flaw to cause an application compiled with libnl to crash or possibly execute arbitrary code in the context of the user running such an application. (CVE-2017-0553) SL7 x86_64 NetworkManager-1.8.0-9.el7.x86_64.rpm NetworkManager-adsl-1.8.0-9.el7.x86_64.rpm NetworkMana [More...]. Synopsis: Moderate: NetworkManager and libnl3 security, bug fix Advisory ID: SLSA-2017:2299-1 Issue Date: 2017-08-01 CVE Numbers: CVE-2017-0553 -- The libnl3 packages contain a convenience library that simplifies using the Linux kernel's Netlink sockets interface for network manipulation. The following packages have been upgraded to a later upstream version: NetworkManager (1.8.0), network-manager-applet (1.8.0). Security Fix(es) in the libnl3 component: * An integer overflow leading to a heap-buffer overflow was found in the libnl library. An attacker could use this flaw to cause an application compiled with libnl to crash or possibly execute arbitrary code in the context of the user running such an application. (CVE-2017-0553) -- SL7 x86_64 NetworkManager-1.8.0-9.el7.x86_64.rpm NetworkManager-adsl-1.8.0-9.el7.x86_64.rpm NetworkManager-bluetooth-1.8.0-9.el7.x86_64.rpm NetworkManager-debuginfo-1.8.0-9.el7.i686.rpm NetworkManager-debuginfo-1.8.0-9.el7.x86_64.rpm NetworkManager-glib-1.8.0-9.el7.i686.rpm NetworkManager-glib-1.8.0-9.el7.x86_64.rpm NetworkManager-libnm-1.8.0-9.el7.i686.rpm NetworkManager-libnm-1.8.0-9.el7.x86_64.rpm NetworkManager-libreswan-1.2.4-2.el7.x86_64.rpm NetworkManager-libreswan-debuginfo-1.2.4-2.el7.x86_64.rpm NetworkManager-libreswan-gnome-1.2.4-2.el7.x86_64.rpm NetworkManager-ppp-1.8.0-9.el7.x86_64.rpm NetworkManager-team-1.8.0-9.el7.x86_64.rpm NetworkManager-tui-1.8.0-9.el7.x86_64.rpm NetworkManager-wifi-1.8.0-9.el7.x86_64.rpm NetworkManager-wwan-1.8.0-9.el7.x86_64.rpm libnl3-3.2.28-4.el7.i686.rpm libnl3-3.2.28-4.el7.x86_64.rpm libnl3-cli-3.2.28-4.el7.i686.rpm libnl3-cli-3.2.28-4.el7.x86_64.rpm libnl3-debuginfo-3.2.28-4.el7.i686.rpm libnl3-debuginfo-3.2.28-4.el7.x86_64.rpm libnm-gtk-1.8.0-3.el7.i686.rpm libnm-gtk-1.8.0-3.el7.x86_64.rpm libnma-1.8.0-3.el7.i686.rpm libnma-1.8.0-3.el7.x86_64.rpm network-manager-applet-debuginfo-1.8.0-3.el7.i686.rpm network-manager-applet-debuginfo-1.8.0-3.el7.x86_64.rpm nm-connection-editor-1.8.0-3.el7.x86_64.rpm NetworkManager-glib-devel-1.8.0-9.el7.i686.rpm NetworkManager-glib-devel-1.8.0-9.el7.x86_64.rpm NetworkManager-libnm-devel-1.8.0-9.el7.i686.rpm NetworkManager-libnm-devel-1.8.0-9.el7.x86_64.rpm libnl3-devel-3.2.28-4.el7.i686.rpm libnl3-devel-3.2.28-4.el7.x86_64.rpm libnl3-doc-3.2.28-4.el7.x86_64.rpm libnm-gtk-devel-1.8.0-3.el7.i686.rpm libnm-gtk-devel-1.8.0-3.el7.x86_64.rpm libnma-devel-1.8.0-3.el7.i686.rpm libnma-devel-1.8.0-3.el7.x86_64.rpm network-manager-applet-1.8.0-3.el7.x86_64.rpm noarch NetworkManager-config-server-1.8.0-9.el7.noarch.rpm NetworkManager-dispatcher-routing-rules-1.8.0-9.el7.noarch.rpm - Scientific Linux Development Team . A significant alert has been released concerning NetworkManager and libnl3 to address a severe buffer overflow vulnerability, necessitating prompt measures for resolution.. NetworkManager Update, libnl3 Security, SL7 Advisory, Buffer Overflow Fix. . LinuxSecurity.com Team
lib: check for integer overflow in nlmsg_reserve() (rh#1440788, rh#1440789, CVE-2017-0553). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-7a5363b41d 2017-05-04 13:28:25.130390 --------------------------------------------------------------------------------Name : libnl3 Product : Fedora 24 Version : 3.2.28 Release : 5.fc24 URL : http://www.infradead.org/~tgr/libnl/ Summary : Convenience library for kernel netlink sockets Description : This package contains a convenience library to simplify using the Linux kernel's netlink sockets interface for network manipulation --------------------------------------------------------------------------------Update Information: lib: check for integer overflow in nlmsg_reserve() (rh#1440788, rh#1440789, CVE-2017-0553) --------------------------------------------------------------------------------References: [ 1 ] Bug #1440789 - CVE-2017-0553 libnl3: libnl: Integer overflow in nlmsg_reserve() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1440789 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libnl3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
It was discovered that there was an integer overflow in libnl3, a library for dealing with netlink sockets. A missing check in nlmsg_reserve() could have allowed a malicious application . Hash: SHA256 Package : libnl3 Version : 3.2.7-4+deb7u1 CVE ID : CVE-2017-0553 Debian Bug : #859948 It was discovered that there was an integer overflow in libnl3, a library for dealing with netlink sockets. A missing check in nlmsg_reserve() could have allowed a malicious application to execute arbitrary code within the context of the WiFi service. For Debian 7 "Wheezy", this issue has been fixed in libnl3 version 3.2.7-4+deb7u1. We recommend that you upgrade your libnl3 packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
check valid input arguments for nla_reserve() (rh #1414305, CVE-2017-0386). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-1423c7b4b0 2017-01-22 21:10:28.834963 -------------------------------------------------------------------------------- Name : libnl3 Product : Fedora 24 Version : 3.2.28 Release : 4.fc24 URL : http://www.infradead.org/~tgr/libnl/ Summary : Convenience library for kernel netlink sockets Description : This package contains a convenience library to simplify using the Linux kernel's netlink sockets interface for network manipulation -------------------------------------------------------------------------------- Update Information: check valid input arguments for nla_reserve() (rh #1414305, CVE-2017-0386) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1414304 - CVE-2017-0386 libnl: Privilege escalation due to insufficient data checks in nla_reserve and nla_put https://bugzilla.redhat.com/show_bug.cgi?id=1414304 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libnl3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update with patches from upstream - check valid input arguments for nla_reserve() (rh #1414305, CVE-2017-0386) - fix crash during SRIOV parsing - lazyly read psched settings - use O_CLOEXEC when creating file descriptors with fopen(). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-090a9c11db 2017-01-20 14:15:21.264545 -------------------------------------------------------------------------------- Name : libnl3 Product : Fedora 25 Version : 3.2.29 Release : 2.fc25 URL : http://www.infradead.org/~tgr/libnl/ Summary : Convenience library for kernel netlink sockets Description : This package contains a convenience library to simplify using the Linux kernel's netlink sockets interface for network manipulation -------------------------------------------------------------------------------- Update Information: Update with patches from upstream - check valid input arguments for nla_reserve() (rh #1414305, CVE-2017-0386) - fix crash during SRIOV parsing - lazyly read psched settings - use O_CLOEXEC when creating file descriptorswith fopen() -------------------------------------------------------------------------------- References: [ 1 ] Bug #1414304 - CVE-2017-0386 libnl: Privilege escalation due to insufficient data checks in nla_reserve and nla_put https://bugzilla.redhat.com/show_bug.cgi?id=1414304 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libnl3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
- Enable libnl3 (see rhbz#1207386, rhbz#1247566) - Remove airpcap switch (doesn't have any effect on Linux) - Backport patch no. 11 - Fixed building with F24+ * Ver. 1.12.7. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-13945 2015-10-07 03:46:09.915520 -------------------------------------------------------------------------------- Name : wireshark Product : Fedora 22 Version : 1.12.7 Release : 2.fc22 URL : https://www.wireshark.org/ Summary : Network traffic analyzer Description : Wireshark is a network traffic analyzer for Unix-ish operating systems. This package lays base for libpcap, a packet capture and filtering library, contains command-line utilities, contains plugins and documentation for wireshark. A graphical user interface is packaged separately to GTK+ package. -------------------------------------------------------------------------------- Update Information: - Enable libnl3 (see rhbz#1207386, rhbz#1247566) - Remove airpcap switch (doesn't have any effect on Linux) - Backport patch no. 11 - Fixed building with F24+ * Ver. 1.12.7 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1253361 - CVE-2015-6249 wireshark: WCCP dissector crash (wnpa-sec-2015-29) https://bugzilla.redhat.com/show_bug.cgi?id=1253361 [ 2 ] Bug #1253352 - CVE-2015-6241 wireshark: protocol tree crash (wnpa-sec-2015-21) https://bugzilla.redhat.com/show_bug.cgi?id=1253352 [ 3 ] Bug #1253353 - CVE-2015-6242 wireshark: memory manager crash (wnpa-sec-2015-22) https://bugzilla.redhat.com/show_bug.cgi?id=1253353 [ 4 ] Bug #1253354 - CVE-2015-6243 wireshark: Dissector table crash (wnpa-sec-2015-23) https://bugzilla.redhat.com/show_bug.cgi?id=1253354 [ 5 ] Bug #1253355 - CVE-2015-6244 wireshark: ZigBee dissector crash (wnpa-sec-2015-24) https://bugzilla.redhat.com/show_bug.cgi?id=1253355 [ 6 ] Bug#1253356 - CVE-2015-6245 wireshark: GSM RLC/MAC dissector infinite loop (wnpa-sec-2015-25) https://bugzilla.redhat.com/show_bug.cgi?id=1253356 [ 7 ] Bug #1253357 - CVE-2015-6246 wireshark: WaveAgent dissector crash (wnpa-sec-2015-26) https://bugzilla.redhat.com/show_bug.cgi?id=1253357 [ 8 ] Bug #1253359 - CVE-2015-6247 wireshark: OpenFlow dissector infinite loop (wnpa-sec-2015-27) https://bugzilla.redhat.com/show_bug.cgi?id=1253359 [ 9 ] Bug #1253360 - CVE-2015-6248 wireshark: Ptvcursor crash (wnpa-sec-2015-28) https://bugzilla.redhat.com/show_bug.cgi?id=1253360 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update wireshark' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.