USN-5583-1 caused a regression in systemd. =========================================================================Ubuntu Security Notice USN-5583-2 September 14, 2022 systemd regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: USN-5583-1 caused a regression in systemd Software Description: - systemd: system and service manager Details: USN-5583-1 fixed vulnerabilities in systemd. Unfortunately this caused a regression by introducing netowrking problems for some users. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that systemd incorrectly handled certain DNS requests, which leads to user-after-free vulnerability. An attacker could possibly use this issue to cause a crash or execute arbitrary code. (CVE-2022-2526) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: systemd 237-3ubuntu10.56 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5583-2 https://ubuntu.com/security/notices/USN-5583-1 https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1988119 Package Information: https://launchpad.net/ubuntu/+source/systemd/237-3ubuntu10.56 . USN-5584-1 tackles a security flaw within OpenSSL in Ubuntu 20.04 LTS leading to potential data breaches.. Ubuntu Systemd Update, Networking Bug Fix, USN-5583-2 Advisory. . Severity: Critical. LinuxSecurity.com Team
An update that contains security fixes can now be installed. . SUSE Security Update: Security update for xen ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:1580-1 Rating: important References: #1183790 #1185021 #1185196 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for xen fixes the following issues: - A recent systemd update caused a regression in 'xenstored.service' systemd now fails to track units that use systemd-notify. (bsc#1183790) - Add a fix to delay between the call to 'systemd-notify' and the final exit of the wrapper script. (bsc#1185021, bsc#1185196) - Run xenstored in a separeately, which will make processing of large and/or concurrent batches of xenstore accesses more robust. (fate#323663) Special Instructions and Notes: Please reboot the system after installing this update. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-1580=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-1580=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 x86_64): xen-debugsource-4.12.4_10-3.42.1 xen-devel-4.12.4_10-3.42.1 - SUSE Linux Enterprise Server 12-SP5 (x86_64): xen-4.12.4_10-3.42.1 xen-debugsource-4.12.4_10-3.42.1 xen-doc-html-4.12.4_10-3.42.1 xen-libs-32bit-4.12.4_10-3.42.1 xen-libs-4.12.4_10-3.42.1 xen-libs-debuginfo-32bit-4.12.4_10-3.42.1 xen-libs-debuginfo-4.12.4_10-3.42.1 xen-tools-4.12.4_10-3.42.1 xen-tools-debuginfo-4.12.4_10-3.42.1 xen-tools-domU-4.12.4_10-3.42.1 xen-tools-domU-debuginfo-4.12.4_10-3.42.1 References: https://bugzilla.suse.com/1183790 https://bugzilla.suse.com/1185021 https://bugzilla.suse.com/1185196 . SUSE Security Patch for xen resolves process vulnerabilities. Apply updates via zypper patch or YaST. A reboot is advised.. SUSE Linux Enterprise, xen fixes, security updates, systemd regression. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.