Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:0845-1

Опубликовано: 15 мар. 2022
Источник: suse-cvrf

Описание

Security update for chrony

This update for chrony fixes the following issues:

Chrony was updated to 4.1, bringing features and bugfixes.

Update to 4.1

  • Add support for NTS servers specified by IP address (matching Subject Alternative Name in server certificate)
  • Add source-specific configuration of trusted certificates
  • Allow multiple files and directories with trusted certificates
  • Allow multiple pairs of server keys and certificates
  • Add copy option to server/pool directive
  • Increase PPS lock limit to 40% of pulse interval
  • Perform source selection immediately after loading dump files
  • Reload dump files for addresses negotiated by NTS-KE server
  • Update seccomp filter and add less restrictive level
  • Restart ongoing name resolution on online command
  • Fix dump files to not include uncorrected offset
  • Fix initstepslew to accept time from own NTP clients
  • Reset NTP address and port when no longer negotiated by NTS-KE server
  • Ensure the correct pool packages are installed for openSUSE and SLE (bsc#1180689).

  • Fix pool package dependencies, so that SLE prefers chrony-pool-suse over chrony-pool-empty. (bsc#1194229)

  • Enable syscallfilter unconditionally [bsc#1181826].

Update to 4.0

  • Enhancements

    • Add support for Network Time Security (NTS) authentication
    • Add support for AES-CMAC keys (AES128, AES256) with Nettle
    • Add authselectmode directive to control selection of unauthenticated sources
    • Add binddevice, bindacqdevice, bindcmddevice directives
    • Add confdir directive to better support fragmented configuration
    • Add sourcedir directive and 'reload sources' command to support dynamic NTP sources specified in files
    • Add clockprecision directive
    • Add dscp directive to set Differentiated Services Code Point (DSCP)
    • Add -L option to limit log messages by severity
    • Add -p option to print whole configuration with included files
    • Add -U option to allow start under non-root user
    • Allow maxsamples to be set to 1 for faster update with -q/-Q option
    • Avoid replacing NTP sources with sources that have unreachable address
    • Improve pools to repeat name resolution to get 'maxsources' sources
    • Improve source selection with trusted sources
    • Improve NTP loop test to prevent synchronisation to itself
    • Repeat iburst when NTP source is switched from offline state to online
    • Update clock synchronisation status and leap status more frequently
    • Update seccomp filter
    • Add 'add pool' command
    • Add 'reset sources' command to drop all measurements
    • Add authdata command to print details about NTP authentication
    • Add selectdata command to print details about source selection
    • Add -N option and sourcename command to print original names of sources
    • Add -a option to some commands to print also unresolved sources
    • Add -k, -p, -r options to clients command to select, limit, reset data
  • Bug fixes

    • Don’t set interface for NTP responses to allow asymmetric routing
    • Handle RTCs that don’t support interrupts
    • Respond to command requests with correct address on multihomed hosts
  • Removed features

    • Drop support for RIPEMD keys (RMD128, RMD160, RMD256, RMD320)
    • Drop support for long (non-standard) MACs in NTPv4 packets (chrony 2.x clients using non-MD5/SHA1 keys need to use option 'version 3')
    • Drop support for line editing with GNU Readline
  • By default we don't write log files but log to journald, so only recommend logrotate.

  • Adjust and rename the sysconfig file, so that it matches the expectations of chronyd.service (bsc#1173277).

Update to 3.5.1:

  • Create new file when writing pidfile (CVE-2020-14367, bsc#1174911)
  • Fixes for %_libexecdir changing to /usr/libexec (bsc#1174075)

  • Use iburst in the default pool statements to speed up initial synchronisation (bsc#1172113).

Update to 3.5:

  • Add support for more accurate reading of PHC on Linux 5.0
  • Add support for hardware timestamping on interfaces with read-only timestamping configuration
  • Add support for memory locking and real-time priority on FreeBSD, NetBSD, Solaris
  • Update seccomp filter to work on more architectures
  • Validate refclock driver options
  • Fix bindaddress directive on FreeBSD
  • Fix transposition of hardware RX timestamp on Linux 4.13 and later
  • Fix building on non-glibc systems
  • Fix location of helper script in chrony-dnssrv@.service (bsc#1128846).

  • Read runtime servers from /var/run/netconfig/chrony.servers to fix bsc#1099272.

  • Move chrony-helper to /usr/lib/chrony/helper, because there should be no executables in /usr/share.

Update to version 3.4

  • Enhancements

    • Add filter option to server/pool/peer directive
    • Add minsamples and maxsamples options to hwtimestamp directive
    • Add support for faster frequency adjustments in Linux 4.19
    • Change default pidfile to /var/run/chrony/chronyd.pid to allow chronyd without root privileges to remove it on exit
    • Disable sub-second polling intervals for distant NTP sources
    • Extend range of supported sub-second polling intervals
    • Get/set IPv4 destination/source address of NTP packets on FreeBSD
    • Make burst options and command useful with short polling intervals
    • Modify auto_offline option to activate when sending request failed
    • Respond from interface that received NTP request if possible
    • Add onoffline command to switch between online and offline state according to current system network configuration
    • Improve example NetworkManager dispatcher script
  • Bug fixes

    • Avoid waiting in Linux getrandom system call
    • Fix PPS support on FreeBSD and NetBSD

Update to version 3.3

  • Enhancements:

    • Add burst option to server/pool directive
    • Add stratum and tai options to refclock directive
    • Add support for Nettle crypto library
    • Add workaround for missing kernel receive timestamps on Linux
    • Wait for late hardware transmit timestamps
    • Improve source selection with unreachable sources
    • Improve protection against replay attacks on symmetric mode
    • Allow PHC refclock to use socket in /var/run/chrony
    • Add shutdown command to stop chronyd
    • Simplify format of response to manual list command
    • Improve handling of unknown responses in chronyc
  • Bug fixes:

    • Respond to NTPv1 client requests with zero mode
    • Fix -x option to not require CAP_SYS_TIME under non-root user
    • Fix acquisitionport directive to work with privilege separation
    • Fix handling of socket errors on Linux to avoid high CPU usage
    • Fix chronyc to not get stuck in infinite loop after clock step

Список пакетов

Container bci/bci-init:15.3
libaugeas0-1.10.1-3.9.1
Container bci/golang:1.16
libaugeas0-1.10.1-3.9.1
Container bci/golang:1.17
libaugeas0-1.10.1-3.9.1
Container bci/golang:latest
libaugeas0-1.10.1-3.9.1
Container bci/node:12
libaugeas0-1.10.1-3.9.1
Container bci/node:14
libaugeas0-1.10.1-3.9.1
Container bci/nodejs:latest
libaugeas0-1.10.1-3.9.1
Container bci/openjdk-devel:11
libaugeas0-1.10.1-3.9.1
Container bci/openjdk:latest
libaugeas0-1.10.1-3.9.1
Container bci/python:3
libaugeas0-1.10.1-3.9.1
Container bci/ruby:latest
libaugeas0-1.10.1-3.9.1
Container caasp/v4/cilium-operator:1.6.6
libaugeas0-1.10.1-3.9.1
Container caasp/v4/cilium:1.6.6
libaugeas0-1.10.1-3.9.1
Container caasp/v4/helm-tiller:2.16.12
libaugeas0-1.10.1-3.9.1
Container ses/6/cephcsi/cephcsi:latest
libaugeas0-1.10.1-3.9.1
Container ses/6/rook/ceph:latest
libaugeas0-1.10.1-3.9.1
Container ses/7.1/ceph/grafana:latest
libaugeas0-1.10.1-3.9.1
Container ses/7.1/ceph/haproxy:latest
libaugeas0-1.10.1-3.9.1
Container ses/7.1/ceph/keepalived:latest
libaugeas0-1.10.1-3.9.1
Container ses/7.1/ceph/prometheus-alertmanager:latest
libaugeas0-1.10.1-3.9.1
Container ses/7.1/ceph/prometheus-node-exporter:latest
libaugeas0-1.10.1-3.9.1
Container ses/7.1/ceph/prometheus-server:latest
libaugeas0-1.10.1-3.9.1
Container ses/7.1/ceph/prometheus-snmp_notifier:latest
libaugeas0-1.10.1-3.9.1
Container ses/7.1/cephcsi/cephcsi:latest
libaugeas0-1.10.1-3.9.1
Container ses/7.1/cephcsi/csi-attacher:v4.1.0
libaugeas0-1.10.1-3.9.1
Container ses/7.1/cephcsi/csi-node-driver-registrar:v2.7.0
libaugeas0-1.10.1-3.9.1
Container ses/7.1/cephcsi/csi-provisioner:v3.4.0
libaugeas0-1.10.1-3.9.1
Container ses/7.1/cephcsi/csi-resizer:v1.7.0
libaugeas0-1.10.1-3.9.1
Container ses/7.1/cephcsi/csi-snapshotter:v6.2.1
libaugeas0-1.10.1-3.9.1
Container ses/7.1/rook/ceph:latest
libaugeas0-1.10.1-3.9.1
Container ses/7/ceph/grafana:latest
libaugeas0-1.10.1-3.9.1
Container ses/7/ceph/prometheus-alertmanager:latest
libaugeas0-1.10.1-3.9.1
Container ses/7/ceph/prometheus-node-exporter:latest
libaugeas0-1.10.1-3.9.1
Container ses/7/ceph/prometheus-server:latest
libaugeas0-1.10.1-3.9.1
Container ses/7/cephcsi/cephcsi:latest
libaugeas0-1.10.1-3.9.1
Container ses/7/cephcsi/csi-attacher:v3.3.0
libaugeas0-1.10.1-3.9.1
Container ses/7/cephcsi/csi-livenessprobe:v1.1.0
libaugeas0-1.10.1-3.9.1
Container ses/7/cephcsi/csi-node-driver-registrar:v2.3.0
libaugeas0-1.10.1-3.9.1
Container ses/7/cephcsi/csi-provisioner:v3.0.0
libaugeas0-1.10.1-3.9.1
Container ses/7/cephcsi/csi-resizer:v1.3.0
libaugeas0-1.10.1-3.9.1
Container ses/7/cephcsi/csi-snapshotter:v4.2.0
libaugeas0-1.10.1-3.9.1
Container ses/7/prometheus-webhook-snmp:latest
libaugeas0-1.10.1-3.9.1
Container ses/7/rook/ceph:latest
libaugeas0-1.10.1-3.9.1
Container suse/ltss/sle15.3/bci-base:latest
libaugeas0-1.10.1-3.9.1
Container suse/sle-micro-rancher/5.2:latest
libaugeas0-1.10.1-3.9.1
Container suse/sle-micro/5.1/toolbox:latest
libaugeas0-1.10.1-3.9.1
Container suse/sle-micro/5.2/toolbox:latest
libaugeas0-1.10.1-3.9.1
Container suse/sle15:15.0
libaugeas0-1.10.1-3.9.1
Container suse/sle15:15.1
libaugeas0-1.10.1-3.9.1
Container suse/sle15:15.2
libaugeas0-1.10.1-3.9.1
Container suse/sle15:15.3
libaugeas0-1.10.1-3.9.1
Image SLES15-Azure-BYOS
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SAP-Azure-BYOS
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SAP-Azure-LI-BYOS-Production
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SAP-Azure-VLI-BYOS-Production
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP1-Azure-BYOS
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP1-Azure-HPC-BYOS
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP1-CHOST-BYOS-Azure
libaugeas0-1.10.1-3.9.1
Image SLES15-SP1-CHOST-BYOS-EC2
libaugeas0-1.10.1-3.9.1
Image SLES15-SP1-CHOST-BYOS-GCE
libaugeas0-1.10.1-3.9.1
Image SLES15-SP1-SAP-Azure-BYOS
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP1-SAPCAL-Azure
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP1-SAPCAL-EC2-HVM
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP1-SAPCAL-GCE
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-BYOS-Azure
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-BYOS-EC2-HVM
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-BYOS-GCE
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-CHOST-BYOS-Aliyun
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-CHOST-BYOS-Azure
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-CHOST-BYOS-EC2
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-CHOST-BYOS-GCE
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-HPC-BYOS-Azure
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-HPC-BYOS-EC2-HVM
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-Manager-4-1-Proxy-BYOS-Azure
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-Manager-4-1-Proxy-BYOS-EC2-HVM
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-Manager-4-1-Proxy-BYOS-GCE
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-SAP-Azure
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-SAP-BYOS-Azure
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-SAP-BYOS-EC2-HVM
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-SAP-BYOS-GCE
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-SAP-EC2-HVM
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP2-SAP-GCE
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-BYOS-Azure
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-BYOS-EC2-HVM
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-BYOS-GCE
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-CHOST-BYOS-Aliyun
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-CHOST-BYOS-Azure
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-CHOST-BYOS-EC2
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-CHOST-BYOS-GCE
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-CHOST-BYOS-SAP-CCloud
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-EC2-ECS-HVM
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-EC2-HVM
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-GCE
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-HPC-Azure
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-HPC-BYOS-Azure
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-HPC-BYOS-EC2-HVM
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-HPC-BYOS-GCE
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-Azure
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-EC2-HVM
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-GCE
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-Micro-5-1-BYOS-Azure
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-Micro-5-1-BYOS-EC2-HVM
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-Micro-5-1-BYOS-GCE
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-Micro-5-2-BYOS-Azure
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-Micro-5-2-BYOS-EC2-HVM
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-Micro-5-2-BYOS-GCE
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-SAP-Azure
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-SAP-Azure-LI-BYOS-Production
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-SAP-BYOS-Azure
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-SAP-BYOS-EC2-HVM
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-SAP-BYOS-GCE
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-SAP-EC2-HVM
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-SAP-GCE
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-SAPCAL-Azure
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-SAPCAL-EC2-HVM
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
Image SLES15-SP3-SAPCAL-GCE
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
SUSE Linux Enterprise Installer Updates 15 SP3
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
SUSE Linux Enterprise Micro 5.0
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1
SUSE Linux Enterprise Micro 5.1
augeas-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
SUSE Linux Enterprise Module for Basesystem 15 SP3
augeas-1.10.1-3.9.1
augeas-devel-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
chrony-4.1-150300.16.3.1
chrony-pool-empty-4.1-150300.16.3.1
chrony-pool-suse-4.1-150300.16.3.1
libaugeas0-1.10.1-3.9.1
SUSE Linux Enterprise Real Time 15 SP2
augeas-1.10.1-3.9.1
augeas-devel-1.10.1-3.9.1
augeas-lenses-1.10.1-3.9.1
libaugeas0-1.10.1-3.9.1

Описание

A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writing, chronyd does not check for an existing symbolic link with the same file name. This flaw allows an attacker with privileged access to create a symlink with the default PID file name pointing to any destination file in the system, resulting in data loss and a denial of service due to the path traversal.


Затронутые продукты
Container bci/bci-init:15.3:libaugeas0-1.10.1-3.9.1
Container bci/golang:1.16:libaugeas0-1.10.1-3.9.1
Container bci/golang:1.17:libaugeas0-1.10.1-3.9.1
Container bci/golang:latest:libaugeas0-1.10.1-3.9.1

Ссылки
Уязвимость SUSE-SU-2022:0845-1