Описание
Security update for util-linux
This update for util-linux fixes the following issues:
- Improve throughput and reduce clock sequence increments for high load situation with time based version 1 uuids. (bsc#1194642)
- Prevent root owning of
/var/lib/libuuid/clock.txt. (bsc#1194642) - Warn if uuidd lock state is not usable. (bsc#1194642)
- Fix 'su -s' bash completion. (bsc#1172427)
- CVE-2021-37600: Fixed an integer overflow which could lead to buffer overflow in get_sem_elements. (bsc#1188921)
- Load /etc/default/su (bsc#1116347).
- Prevent outdated pam files (bsc#1082293, bsc#1081947#c68).
- Do not trim read-only volumes (bsc#1106214).
- libmount: To prevent incorrect behavior, recognize more pseudofs and netfs (bsc#1122417).
- agetty: Reload issue only if it is really needed (bsc#1085196)
- agetty: Return previous response of agetty for special characters (bsc#1085196, bsc#1125886)
- blockdev: Do not fail --report on kpartx-style partitions on multipath. (bsc#1168235)
- nologin: Add support for -c to prevent error from su -c. (bsc#1151708)
- Avoid triggering autofs in lookup_umount_fs_by_statfs. (bsc#1168389)
- libblkid: Do not trigger CDROM autoclose. (bsc#1084671)
- Avoid sulogin failing on not existing or not functional console devices. (bsc#1175514)
- Build with libudev support to support non-root users. (bsc#1169006)
- lscpu: avoid segfault on PowerPC systems with valid hardware configurations. (bsc#1175623, bsc#1178554, bsc#1178825)
- Fix for warning on mounts to CIFS with mount. (bsc#1174942)
Список пакетов
SUSE Linux Enterprise Server 12 SP2-BCL
libblkid1-2.28-44.35.1
libblkid1-32bit-2.28-44.35.1
libfdisk1-2.28-44.35.1
libmount1-2.28-44.35.1
libmount1-32bit-2.28-44.35.1
libsmartcols1-2.28-44.35.1
libuuid1-2.28-44.35.1
libuuid1-32bit-2.28-44.35.1
python-libmount-2.28-44.35.1
util-linux-2.28-44.35.1
util-linux-lang-2.28-44.35.1
util-linux-systemd-2.28-44.35.1
uuidd-2.28-44.35.1
Ссылки
- Link for SUSE-SU-2022:1103-1
- E-Mail link for SUSE-SU-2022:1103-1
- SUSE Security Ratings
- SUSE Bug 1038841
- SUSE Bug 1081947
- SUSE Bug 1082293
- SUSE Bug 1084671
- SUSE Bug 1085196
- SUSE Bug 1106214
- SUSE Bug 1116347
- SUSE Bug 1122417
- SUSE Bug 1125886
- SUSE Bug 1135534
- SUSE Bug 1135708
- SUSE Bug 1151708
- SUSE Bug 1168235
- SUSE Bug 1168389
- SUSE Bug 1169006
- SUSE Bug 1172427
- SUSE Bug 1174942
Описание
** DISPUTED ** An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is unexploitable in GNU C Library environments, and possibly in all realistic environments.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:libblkid1-2.28-44.35.1
SUSE Linux Enterprise Server 12 SP2-BCL:libblkid1-32bit-2.28-44.35.1
SUSE Linux Enterprise Server 12 SP2-BCL:libfdisk1-2.28-44.35.1
SUSE Linux Enterprise Server 12 SP2-BCL:libmount1-2.28-44.35.1
Ссылки
- CVE-2021-37600
- SUSE Bug 1188921