An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for udisks2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3160-1 Rating: moderate References: #1098797 #1190606 Cross-References: CVE-2021-3802 CVSS scores: CVE-2021-3802 (NVD) : 4.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H CVE-2021-3802 (SUSE): 4.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud Crowbar 9 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for udisks2 fixes the following issues: - CVE-2021-3802: Fixed insecure defaults in user-accessible mount helpers (bsc#1190606). - Fixed vulnerability that allowed mounting ext4 devices over existing entries in fstab (bsc#1098797). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2022-3160=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2022-3160=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-3160=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2022-3160=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-3160=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2022-3160=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2022-3160=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2022-3160=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): libudisks2-0-2.1.3-3.8.1 libudisks2-0-debuginfo-2.1.3-3.8.1 udisks2-2.1.3-3.8.1 udisks2-debuginfo-2.1.3-3.8.1 udisks2-debugsource-2.1.3-3.8.1 - SUSE OpenStack Cloud Crowbar 9 (noarch): udisks2-lang-2.1.3-3.8.1 - SUSE OpenStack Cloud 9 (x86_64): libudisks2-0-2.1.3-3.8.1 libudisks2-0-debuginfo-2.1.3-3.8.1 udisks2-2.1.3-3.8.1 udisks2-debuginfo-2.1.3-3.8.1 udisks2-debugsource-2.1.3-3.8.1 - SUSE OpenStack Cloud 9 (noarch): udisks2-lang-2.1.3-3.8.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): udisks2-debuginfo-2.1.3-3.8.1 udisks2-debugsource-2.1.3-3.8.1 udisks2-devel-2.1.3-3.8.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): libudisks2-0-2.1.3-3.8.1 libudisks2-0-debuginfo-2.1.3-3.8.1 udisks2-2.1.3-3.8.1 udisks2-debuginfo-2.1.3-3.8.1 udisks2-debugsource-2.1.3-3.8.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (noarch): udisks2-lang-2.1.3-3.8.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libudisks2-0-2.1.3-3.8.1 libudisks2-0-debuginfo-2.1.3-3.8.1 udisks2-2.1.3-3.8.1 udisks2-debuginfo-2.1.3-3.8.1 udisks2-debugsource-2.1.3-3.8.1 - SUSE Linux Enterprise Server 12-SP5 (noarch): udisks2-lang-2.1.3-3.8.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64 ppc64le s390x x86_64): libudisks2-0-2.1.3-3.8.1 libudisks2-0-debuginfo-2.1.3-3.8.1 udisks2-2.1.3-3.8.1 udisks2-debuginfo-2.1.3-3.8.1 udisks2-debugsource-2.1.3-3.8.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (noarch): udisks2-lang-2.1.3-3.8.1 - SUSE Linux Enterprise Server 12-SP3-BCL (noarch): udisks2-lang-2.1.3-3.8.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): libudisks2-0-2.1.3-3.8.1 libudisks2-0-debuginfo-2.1.3-3.8.1 udisks2-2.1.3-3.8.1 udisks2-debuginfo-2.1.3-3.8.1 udisks2-debugsource-2.1.3-3.8.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): libudisks2-0-2.1.3-3.8.1 libudisks2-0-debuginfo-2.1.3-3.8.1 udisks2-2.1.3-3.8.1 udisks2-debuginfo-2.1.3-3.8.1 udisks2-debugsource-2.1.3-3.8.1 - SUSE Linux Enterprise Server 12-SP2-BCL (noarch): udisks2-lang-2.1.3-3.8.1 References: https://www.suse.com/security/cve/CVE-2021-3802.html https://bugzilla.suse.com/1098797 https://bugzilla.suse.com/1190606 . SUSE Security Patch targets CVE-2021-1234 that impacts udisks. Check the update specifics to fortify your devices.. SUSE Update, Udisks2 Security, Mount Issue Fix. . LinuxSecurity.com Team
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for runc ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0944-1 Rating: moderate References: #1149954 #1160452 Cross-References: CVE-2019-19921 Affected Products: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 SUSE Linux Enterprise Module for Containers 15-SP1 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for runc fixes the following issues: runc was updated to v1.0.0~rc10 - CVE-2019-19921: Fixed a mount race condition with shared mounts (bsc#1160452). - Fixed an issue where podman run hangs when spawned by salt-minion process (bsc#1149954). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2020-944=1 - SUSE Linux Enterprise Module for Containers 15-SP1: zypper in -t patch SUSE-SLE-Module-Containers-15-SP1-2020-944=1 Package List: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (noarch): runc-test-1.0.0~rc10-1.9.1 - SUSE Linux Enterprise Module for Containers 15-SP1 (aarch64 ppc64le s390x x86_64): runc-1.0.0~rc10-1.9.1 runc-debuginfo-1.0.0~rc10-1.9.1 References: https://www.suse.com/security/cve/CVE-2019-19921.html https://bugzilla.suse.com/1149954 https://bugzilla.suse.com/1160452 _______________________________________________ sle-security-updates mailinglist
Several security issues were fixed in the kernel.. =========================================================================Ubuntu Security Notice USN-2317-1 August 18, 2014 linux-lts-trusty vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: - linux-lts-trusty: Linux hardware enablement kernel from Trusty Details: Eric W. Biederman discovered a flaw with the mediation of mount flags in the Linux kernel's user namespace subsystem. An unprivileged user could exploit this flaw to by-pass mount restrictions, and potentially gain administrative privileges. (CVE-2014-5207) Kenton Varda discovered a flaw with read-only bind mounds when used with user namespaces. An unprivileged local user could exploit this flaw to gain full write privileges to a mount that should be read only. (CVE-2014-5206) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: linux-image-3.13.0-34-generic 3.13.0-34.60~precise1 linux-image-3.13.0-34-generic-lpae 3.13.0-34.60~precise1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-2317-1 CVE-2014-5206, CVE-2014-5207 PackageInformation: https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-34.60~precise1 . The Ubuntu Security Notice USN-2317-1 addresses Linux kernel vulnerabilities with crucial updates to mitigate security risks and protect system integrity. Ubuntu Kernel Updates, Trusty HWE Issues, Kernel Security Fixes. . Severity: Critical. LinuxSecurity.com Team
initramfs-tools used incorrect mount options.. =========================================================================Ubuntu Security Notice USN-2153-1 March 24, 2014 initramfs-tools vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.10 - Ubuntu 12.04 LTS Summary: initramfs-tools used incorrect mount options. Software Description: - initramfs-tools: tools for generating an initramfs Details: Kees Cook discovered that initramfs-tools incorrectly mounted /run without the noexec option, contrary to expected behaviour. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: initramfs-tools 0.103ubuntu0.2.2 Ubuntu 12.04 LTS: initramfs-tools 0.99ubuntu13.5 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2153-1 https://bugs.launchpad.net/ubuntu/+source/initramfs-tools/+bug/1152744 Package Information: https://launchpad.net/ubuntu/+source/initramfs-tools/0.103ubuntu0.2.2 https://launchpad.net/ubuntu/+source/initramfs-tools/0.99ubuntu13.5 . Resolve the Ubuntu Security Notice USN-2153-1 by updating your package index, upgrading initramfs-tools, rebuilding the initramfs image, and rebooting. initramfs-tools, mount options, ubuntu security notice. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.