Описание
Security update for systemd
This update for systemd fixes the following issues:
-
CVE-2020-1712 (bsc#bsc#1162108) Fix a heap use-after-free vulnerability, when asynchronous Polkit queries were performed while handling Dbus messages. A local unprivileged attacker could have abused this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted Dbus messages.
-
Use suse.pool.ntp.org server pool on SLE distros (jsc#SLE-7683)
-
libblkid: open device in nonblock mode. (bsc#1084671)
-
udev/cdrom_id: Do not open CD-rom in exclusive mode. (bsc#1154256)
-
bus_open leak sd_event_source when udevadm trigger。 (bsc#1161436 CVE-2019-20386)
-
fileio: introduce read_full_virtual_file() for reading virtual files in sysfs, procfs (bsc#1133495 bsc#1159814)
-
fileio: initialize errno to zero before we do fread()
-
fileio: try to read one byte too much in read_full_stream()
-
logind: consider 'greeter' sessions suitable as 'display' sessions of a user (bsc#1158485)
-
logind: never elect a session that is stopping as display
-
journal: include kmsg lines from the systemd process which exec()d us (#8078)
-
udevd: don't use monitor after manager_exit()
-
udevd: capitalize log messages in on_sigchld()
-
udevd: merge conditions to decrease indentation
-
Revert 'udevd: fix crash when workers time out after exit is signal caught'
-
core: fragments of masked units ought not be considered for NeedDaemonReload (#7060) (bsc#1156482)
-
udevd: fix crash when workers time out after exit is signal caught
-
udevd: wait for workers to finish when exiting (bsc#1106383)
-
Improve bash completion support (bsc#1155207)
- shell-completion: systemctl: do not list template units in {re,}start
- shell-completion: systemctl: pass current word to all list_unit*
- bash-completion: systemctl: pass current partial unit to list-unit* (bsc#1155207)
- bash-completion: systemctl: use systemctl --no-pager
- bash-completion: also suggest template unit files
- bash-completion: systemctl: add missing options and verbs
- bash-completion: use the first argument instead of the global variable (#6457)
-
networkd: VXLan Make group and remote variable separate (bsc#1156213)
-
networkd: vxlan require Remote= to be a non multicast address (#8117) (bsc#1156213)
-
fs-util: let's avoid unnecessary strerror()
-
fs-util: introduce inotify_add_watch_and_warn() helper
-
ask-password: improve log message when inotify limit is reached (bsc#1155574)
-
shared/install: failing with -ELOOP can be due to the use of an alias in install_error() (bsc#1151377)
-
man: alias names can't be used with enable command (bsc#1151377)
-
Add boot option to not use swap at system start (jsc#SLE-7689)
-
Allow YaST to select Iranian (Persian, Farsi) keyboard layout (bsc#1092920)
Список пакетов
Container caasp/v4/389-ds:1.4.2
Container caasp/v4/busybox:1.34.1
Container caasp/v4/caasp-dex:2.16.0
Container caasp/v4/cert-exporter:2.3.0
Container caasp/v4/cilium-etcd-operator:2.0.5
Container caasp/v4/cilium-init:1.5.3
Container caasp/v4/cilium-operator:1.6.6
Container caasp/v4/cilium:1.6.6
Container caasp/v4/cloud-provider-openstack:1.15.0
Container caasp/v4/configmap-reload:0.3.0
Container caasp/v4/coredns:1.6.7
Container caasp/v4/curl:7.60.0
Container caasp/v4/etcd:3.4.13
Container caasp/v4/gangway:3.1.0
Container caasp/v4/grafana:7.5.12
Container caasp/v4/helm-tiller:2.16.12
Container caasp/v4/hyperkube:v1.17.17
Container caasp/v4/k8s-sidecar:0.1.75
Container caasp/v4/kube-state-metrics:1.9.3
Container caasp/v4/kubernetes-client:1.17.17
Container caasp/v4/kucero:1.3.0
Container caasp/v4/kured:1.3.0
Container caasp/v4/metrics-server:0.3.6
Container caasp/v4/prometheus-alertmanager:0.16.2
Container caasp/v4/prometheus-node-exporter:1.1.2
Container caasp/v4/prometheus-pushgateway:0.6.0
Container caasp/v4/prometheus-server:2.7.1
Container caasp/v4/rsyslog:8.39.0
Container caasp/v4/skuba-tooling:0.1.0
Container caasp/v4/test-update:beta
Container caasp/v4/velero-plugin-for-aws:1.0.1
Container caasp/v4/velero-plugin-for-gcp:1.0.1
Container caasp/v4/velero-plugin-for-microsoft-azure:1.0.1
Container caasp/v4/velero-restic-restore-helper:1.3.1
Container caasp/v4/velero:1.3.1
Container ses/6/cephcsi/cephcsi:latest
Container ses/6/rook/ceph:latest
Container ses/7/ceph/ceph:latest
Container ses/7/ceph/grafana:latest
Container ses/7/ceph/prometheus-alertmanager:latest
Container ses/7/ceph/prometheus-node-exporter:latest
Container ses/7/ceph/prometheus-server:latest
Container ses/7/cephcsi/cephcsi:latest
Container ses/7/cephcsi/csi-attacher:v2.1.0
Container ses/7/cephcsi/csi-attacher:v3.3.0
Container ses/7/cephcsi/csi-livenessprobe:v1.1.0
Container ses/7/cephcsi/csi-node-driver-registrar:v1.2.0
Container ses/7/cephcsi/csi-node-driver-registrar:v2.3.0
Container ses/7/cephcsi/csi-provisioner:v1.6.0
Container ses/7/cephcsi/csi-provisioner:v3.0.0
Container ses/7/cephcsi/csi-resizer:v0.4.0
Container ses/7/cephcsi/csi-resizer:v1.3.0
Container ses/7/cephcsi/csi-snapshotter:v2.1.0
Container ses/7/cephcsi/csi-snapshotter:v2.1.1
Container ses/7/cephcsi/csi-snapshotter:v4.2.0
Container ses/7/prometheus-webhook-snmp:latest
Container ses/7/rook/ceph:latest
Container suse/sle-micro/5.0/toolbox:latest
Container suse/sle15:15.0
Container suse/sle15:15.1
Container suse/sle15:15.2
Container suse/sles/15.2/virt-api:0.38.1
Container suse/sles/15.2/virt-controller:0.38.1
Container suse/sles/15.2/virt-handler:0.38.1
Container suse/sles/15.2/virt-launcher:0.38.1
Container suse/sles/15.2/virt-operator:0.38.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS
SUSE Linux Enterprise High Performance Computing 15-LTSS
SUSE Linux Enterprise Module for Basesystem 15
SUSE Linux Enterprise Module for Basesystem 15 SP1
SUSE Linux Enterprise Server 15-LTSS
SUSE Linux Enterprise Server for SAP Applications 15
Ссылки
- Link for SUSE-SU-2020:0335-1
- E-Mail link for SUSE-SU-2020:0335-1
- SUSE Security Ratings
- SUSE Bug 1084671
- SUSE Bug 1092920
- SUSE Bug 1106383
- SUSE Bug 1133495
- SUSE Bug 1151377
- SUSE Bug 1154256
- SUSE Bug 1155207
- SUSE Bug 1155574
- SUSE Bug 1156213
- SUSE Bug 1156482
- SUSE Bug 1158485
- SUSE Bug 1159814
- SUSE Bug 1161436
- SUSE Bug 1162108
- SUSE CVE CVE-2019-20386 page
- SUSE CVE CVE-2020-1712 page
Описание
An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.
Затронутые продукты
Ссылки
- CVE-2019-20386
- SUSE Bug 1161436
Описание
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.
Затронутые продукты
Ссылки
- CVE-2020-1712
- SUSE Bug 1162108