Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:0331-1

Опубликовано: 18 мар. 2020
Источник: suse-cvrf

Описание

Security update for systemd

This update for systemd fixes the following issues:

  • CVE-2020-1712 (bsc#bsc#1162108) Fix a heap use-after-free vulnerability, when asynchronous Polkit queries were performed while handling Dbus messages. A local unprivileged attacker could have abused this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted Dbus messages.

  • Unconfirmed fix for prevent hanging of systemctl during restart. (bsc#1139459)

  • Fix warnings thrown during package installation. (bsc#1154043)

  • Fix for system-udevd prevent crash within OES2018. (bsc#1151506)

  • Fragments of masked units ought not be considered for 'NeedDaemonReload'. (bsc#1156482)

  • Wait for workers to finish when exiting. (bsc#1106383)

  • Improve log message when inotify limit is reached. (bsc#1155574)

  • Mention in the man pages that alias names are only effective after command 'systemctl enable'. (bsc#1151377)

  • Introduce function for reading virtual files in 'sysfs' and 'procfs'. (bsc#1133495, bsc#1159814)

Список пакетов

Container caasp/v4/nginx-ingress-controller:beta1
libsystemd0-228-150.82.1
libudev1-228-150.82.1
systemd-228-150.82.1
Container suse/sles12sp3:latest
libsystemd0-228-150.82.1
libudev1-228-150.82.1
systemd-228-150.82.1
Container suse/sles12sp4:latest
libsystemd0-228-150.82.1
libudev1-228-150.82.1
HPE Helion OpenStack 8
libsystemd0-228-150.82.1
libsystemd0-32bit-228-150.82.1
libudev-devel-228-150.82.1
libudev1-228-150.82.1
libudev1-32bit-228-150.82.1
systemd-228-150.82.1
systemd-32bit-228-150.82.1
systemd-bash-completion-228-150.82.1
systemd-sysvinit-228-150.82.1
udev-228-150.82.1
SUSE Enterprise Storage 5
libsystemd0-228-150.82.1
libsystemd0-32bit-228-150.82.1
libudev-devel-228-150.82.1
libudev1-228-150.82.1
libudev1-32bit-228-150.82.1
systemd-228-150.82.1
systemd-32bit-228-150.82.1
systemd-bash-completion-228-150.82.1
systemd-sysvinit-228-150.82.1
udev-228-150.82.1
SUSE Linux Enterprise Desktop 12 SP4
libsystemd0-228-150.82.1
libsystemd0-32bit-228-150.82.1
libudev1-228-150.82.1
libudev1-32bit-228-150.82.1
systemd-228-150.82.1
systemd-32bit-228-150.82.1
systemd-bash-completion-228-150.82.1
systemd-sysvinit-228-150.82.1
udev-228-150.82.1
SUSE Linux Enterprise Server 12 SP2-BCL
libsystemd0-228-150.82.1
libsystemd0-32bit-228-150.82.1
libudev1-228-150.82.1
libudev1-32bit-228-150.82.1
systemd-228-150.82.1
systemd-32bit-228-150.82.1
systemd-bash-completion-228-150.82.1
systemd-sysvinit-228-150.82.1
udev-228-150.82.1
SUSE Linux Enterprise Server 12 SP2-LTSS
libsystemd0-228-150.82.1
libsystemd0-32bit-228-150.82.1
libudev-devel-228-150.82.1
libudev1-228-150.82.1
libudev1-32bit-228-150.82.1
systemd-228-150.82.1
systemd-32bit-228-150.82.1
systemd-bash-completion-228-150.82.1
systemd-sysvinit-228-150.82.1
udev-228-150.82.1
SUSE Linux Enterprise Server 12 SP3-BCL
libsystemd0-228-150.82.1
libsystemd0-32bit-228-150.82.1
libudev1-228-150.82.1
libudev1-32bit-228-150.82.1
systemd-228-150.82.1
systemd-32bit-228-150.82.1
systemd-bash-completion-228-150.82.1
systemd-sysvinit-228-150.82.1
udev-228-150.82.1
SUSE Linux Enterprise Server 12 SP3-LTSS
libsystemd0-228-150.82.1
libsystemd0-32bit-228-150.82.1
libudev-devel-228-150.82.1
libudev1-228-150.82.1
libudev1-32bit-228-150.82.1
systemd-228-150.82.1
systemd-32bit-228-150.82.1
systemd-bash-completion-228-150.82.1
systemd-sysvinit-228-150.82.1
udev-228-150.82.1
SUSE Linux Enterprise Server 12 SP4
libsystemd0-228-150.82.1
libsystemd0-32bit-228-150.82.1
libudev-devel-228-150.82.1
libudev1-228-150.82.1
libudev1-32bit-228-150.82.1
systemd-228-150.82.1
systemd-32bit-228-150.82.1
systemd-bash-completion-228-150.82.1
systemd-sysvinit-228-150.82.1
udev-228-150.82.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
libsystemd0-228-150.82.1
libsystemd0-32bit-228-150.82.1
libudev-devel-228-150.82.1
libudev1-228-150.82.1
libudev1-32bit-228-150.82.1
systemd-228-150.82.1
systemd-32bit-228-150.82.1
systemd-bash-completion-228-150.82.1
systemd-sysvinit-228-150.82.1
udev-228-150.82.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
libsystemd0-228-150.82.1
libsystemd0-32bit-228-150.82.1
libudev-devel-228-150.82.1
libudev1-228-150.82.1
libudev1-32bit-228-150.82.1
systemd-228-150.82.1
systemd-32bit-228-150.82.1
systemd-bash-completion-228-150.82.1
systemd-sysvinit-228-150.82.1
udev-228-150.82.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
libsystemd0-228-150.82.1
libsystemd0-32bit-228-150.82.1
libudev-devel-228-150.82.1
libudev1-228-150.82.1
libudev1-32bit-228-150.82.1
systemd-228-150.82.1
systemd-32bit-228-150.82.1
systemd-bash-completion-228-150.82.1
systemd-sysvinit-228-150.82.1
udev-228-150.82.1
SUSE Linux Enterprise Software Development Kit 12 SP4
libudev-devel-228-150.82.1
systemd-devel-228-150.82.1
SUSE OpenStack Cloud 7
libsystemd0-228-150.82.1
libsystemd0-32bit-228-150.82.1
libudev-devel-228-150.82.1
libudev1-228-150.82.1
libudev1-32bit-228-150.82.1
systemd-228-150.82.1
systemd-32bit-228-150.82.1
systemd-bash-completion-228-150.82.1
systemd-sysvinit-228-150.82.1
udev-228-150.82.1
SUSE OpenStack Cloud 8
libsystemd0-228-150.82.1
libsystemd0-32bit-228-150.82.1
libudev-devel-228-150.82.1
libudev1-228-150.82.1
libudev1-32bit-228-150.82.1
systemd-228-150.82.1
systemd-32bit-228-150.82.1
systemd-bash-completion-228-150.82.1
systemd-sysvinit-228-150.82.1
udev-228-150.82.1
SUSE OpenStack Cloud Crowbar 8
libsystemd0-228-150.82.1
libsystemd0-32bit-228-150.82.1
libudev-devel-228-150.82.1
libudev1-228-150.82.1
libudev1-32bit-228-150.82.1
systemd-228-150.82.1
systemd-32bit-228-150.82.1
systemd-bash-completion-228-150.82.1
systemd-sysvinit-228-150.82.1
udev-228-150.82.1

Описание

A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.


Затронутые продукты
Container caasp/v4/nginx-ingress-controller:beta1:libsystemd0-228-150.82.1
Container caasp/v4/nginx-ingress-controller:beta1:libudev1-228-150.82.1
Container caasp/v4/nginx-ingress-controller:beta1:systemd-228-150.82.1
Container suse/sles12sp3:latest:libsystemd0-228-150.82.1

Ссылки