Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for runc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1625-1 Rating: moderate References: #1193436 Cross-References: CVE-2021-43784 CVSS scores: CVE-2021-43784 (NVD) : 6 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for runc fixes the following issues: Update to runc v1.0.3. * CVE-2021-43784: Fixed a potential vulnerability related to the internal usage of netlink, which is believed to not be exploitable with any released versions of runc (bsc#1193436) * Fixed inability to start a container with read-write bind mount of a read-only fuse host mount. * Fixed inability to start when read-only /dev in set in spec. * Fixed not removing sub-cgroups upon container delete, when rootless cgroup v2 is used with older systemd. * Fixed returning error from GetStats when hugetlb is unsupported (which causes excessive logging for kubernetes). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-1625=1 Package List: - openSUSE Leap 15.2 (x86_64): runc-1.0.3-lp152.2.12.1 runc-debuginfo-1.0.3-lp152.2.12.1 References: https://www.suse.com/security/cve/CVE-2021-43784.html https://bugzilla.suse.com/1193436 . Debian Security Patch for runc mitigates CVE-2021-43784 classified as moderate risk. Detailedsetup guide provided.. openSUSE Security,runc Update,Container Management,Security Patch. . LinuxSecurity.com Team
iproute 2.4.7 and earlier allows local users to cause a denial of service via spoofed messages as other users to the kernel netlink interface.. Fedora Update Notification FEDORA-2004-115 2004-05-11 --------------------------------------------------------------------- Name : iproute Version : 2.4.7 Release : 13.2 Summary : Advanced IP routing and network device configuration tools. Description : The iproute package contains networking utilities (ip and rtmon, for example) which are designed to use the advanced networking capabilities of the Linux 2.4.x and 2.6.x kernel. --------------------------------------------------------------------- This update of the iproute package fixes a security problem found in netlink. See CAN-2003-0856. All users of the netlink application are very strongly advised to update to these latest packages. * Thu May 06 2004 Phil Knirsch 2.4.7-13.2 - Built security errata version for FC1. * Wed Apr 21 2004 Phil Knirsch 2.4.7-14 - Fixed -f option for ss (#118355). - Small description fix (#110997). - Added initialization of some vars (#74961). - Added patch to initialize "default" rule as well (#60693). * Fri Feb 13 2004 Elliot Lee - rebuilt * Wed Nov 05 2003 Phil Knirsch 2.4.7-12 - Security errata for netlink (CAN-2003-0856). --------------------------------------------------------------------- This update can be downloaded from: 742a66f04b4bb5f4e814908bd33fbdde SRPMS/iproute-2.4.7-13.2.src.rpm ece1fcf398e9e7b234584e942c08d6e1 i386/iproute-2.4.7-13.2.i386.rpm 842d74b8f79ebfe414a1ee1ca5f7ecc7 i386/debug/iproute-debuginfo-2.4.7-13.2.i386.rpm 738a0454d2d4f390d11fa484768dc7ce x86_64/iproute-2.4.7-13.2.x86_64.rpm 2a4e1ee78d017c593588ec0172159295 x86_64/debug/iproute-debuginfo-2.4.7-13.2.x86_64.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- -- Philipp Knirsch | Tel.: +49-711-96437-470 Development | Fax.: +49-711-96437-111 Red Hat GmbH | Email: Phil Knirsch Hauptstaetterstr. 58 | Web: Red Hat DACH-Region D-70178 Stuttgart Motd: You're only jealous cos the little penguins are talking to me. . A recent Fedora update addresses a Denial of Service flaw in iproute by implementing a patch to the kernel netlink subsystem.. Denial of Service,Fedora,iproute Update,Network Security,Kernel Patch. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.