Описание
Security update for systemd
This update for systemd fixes the following issues:
-
CVE-2020-1712 (bsc#bsc#1162108) Fix a heap use-after-free vulnerability, when asynchronous Polkit queries were performed while handling Dbus messages. A local unprivileged attacker could have abused this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted Dbus messages.
-
Unconfirmed fix for prevent hanging of systemctl during restart. (bsc#1139459)
-
Fix warnings thrown during package installation. (bsc#1154043)
-
Fix for system-udevd prevent crash within OES2018. (bsc#1151506)
-
Fragments of masked units ought not be considered for 'NeedDaemonReload'. (bsc#1156482)
-
Wait for workers to finish when exiting. (bsc#1106383)
-
Improve log message when inotify limit is reached. (bsc#1155574)
-
Mention in the man pages that alias names are only effective after command 'systemctl enable'. (bsc#1151377)
-
Introduce function for reading virtual files in 'sysfs' and 'procfs'. (bsc#1133495, bsc#1159814)
Список пакетов
Container caasp/v4/nginx-ingress-controller:beta1
Container suse/sles12sp3:latest
Container suse/sles12sp4:latest
HPE Helion OpenStack 8
SUSE Enterprise Storage 5
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Software Development Kit 12 SP4
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Ссылки
- Link for SUSE-SU-2020:0331-1
- E-Mail link for SUSE-SU-2020:0331-1
- SUSE Security Ratings
- SUSE Bug 1106383
- SUSE Bug 1133495
- SUSE Bug 1139459
- SUSE Bug 1151377
- SUSE Bug 1151506
- SUSE Bug 1154043
- SUSE Bug 1155574
- SUSE Bug 1156482
- SUSE Bug 1159814
- SUSE Bug 1162108
- SUSE CVE CVE-2020-1712 page
Описание
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.
Затронутые продукты
Ссылки
- CVE-2020-1712
- SUSE Bug 1162108