Описание
ELSA-2026-67585: firewalld security update (MODERATE)
[1.3.4-20.0.1]
- Red Hat Satellite and Red Hat high availaibility reference found in cockpit UI [Orabug: 30257573]
- discard empty RH-Satellite-6.xml [Orabug: 30328734]
- Remove capsule file as well, since it references removed config [Orabug: 33513329]
[1.3.4-20]
- fix(policy): use PK_ACTION_CONFIG for set{ZoneSettings2,PolicySettings} (CVE-2026-4948)
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
firewall-applet
1.3.4-20.0.1.el9_8
firewall-config
1.3.4-20.0.1.el9_8
firewalld
1.3.4-20.0.1.el9_8
firewalld-filesystem
1.3.4-20.0.1.el9_8
python3-firewall
1.3.4-20.0.1.el9_8
Oracle Linux x86_64
firewall-applet
1.3.4-20.0.1.el9_8
firewall-config
1.3.4-20.0.1.el9_8
firewalld
1.3.4-20.0.1.el9_8
firewalld-filesystem
1.3.4-20.0.1.el9_8
python3-firewall
1.3.4-20.0.1.el9_8
Связанные CVE
Связанные уязвимости
A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations.
A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations.
A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations.
Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
A flaw was found in firewalld. A local unprivileged user can exploit t ...