Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:0991-1

Опубликовано: 24 мар. 2026
Источник: suse-cvrf

Описание

Security update for systemd

This update for systemd fixes the following issue:

  • CVE-2026-4105: privilege escalation due to improper access control in RegisterMachine D-Bus method (bsc#1259650).
  • udev: check for invalid chars in various fields received from the kernel (bsc#1259697).

Changelog:

cbf8ee66ee machined: reject invalid class types when registering machines 1a55ad48da udev: fix review mixup 1eba76668c udev-builtin-net-id: print cescaped bad attributes cbd4b55380 udev: ensure tag parsing stays within bounds 5973d3b1cc udev: ensure there is space for trailing NUL before calling sprintf f038eb6c8b udev: check for invalid chars in various fields received from the kernel

Список пакетов

Image SLES12-SP5-Azure-BYOS
libsystemd0-228-157.75.1
libudev1-228-157.75.1
systemd-228-157.75.1
systemd-sysvinit-228-157.75.1
udev-228-157.75.1
Image SLES12-SP5-Azure-HPC-BYOS
libsystemd0-228-157.75.1
libudev1-228-157.75.1
systemd-228-157.75.1
systemd-sysvinit-228-157.75.1
udev-228-157.75.1
Image SLES12-SP5-Azure-HPC-On-Demand
libsystemd0-228-157.75.1
libudev1-228-157.75.1
systemd-228-157.75.1
systemd-sysvinit-228-157.75.1
udev-228-157.75.1
Image SLES12-SP5-Azure-SAP-BYOS
libsystemd0-228-157.75.1
libudev1-228-157.75.1
systemd-228-157.75.1
systemd-sysvinit-228-157.75.1
udev-228-157.75.1
Image SLES12-SP5-Azure-SAP-On-Demand
libsystemd0-228-157.75.1
libudev1-228-157.75.1
systemd-228-157.75.1
systemd-sysvinit-228-157.75.1
udev-228-157.75.1
Image SLES12-SP5-Azure-Standard-On-Demand
libsystemd0-228-157.75.1
libudev1-228-157.75.1
systemd-228-157.75.1
systemd-sysvinit-228-157.75.1
udev-228-157.75.1
Image SLES12-SP5-EC2-BYOS
libsystemd0-228-157.75.1
libudev1-228-157.75.1
systemd-228-157.75.1
systemd-sysvinit-228-157.75.1
udev-228-157.75.1
Image SLES12-SP5-EC2-ECS-On-Demand
libsystemd0-228-157.75.1
libudev1-228-157.75.1
systemd-228-157.75.1
systemd-sysvinit-228-157.75.1
udev-228-157.75.1
Image SLES12-SP5-EC2-On-Demand
libsystemd0-228-157.75.1
libudev1-228-157.75.1
systemd-228-157.75.1
systemd-sysvinit-228-157.75.1
udev-228-157.75.1
Image SLES12-SP5-EC2-SAP-BYOS
libsystemd0-228-157.75.1
libudev1-228-157.75.1
systemd-228-157.75.1
systemd-sysvinit-228-157.75.1
udev-228-157.75.1
Image SLES12-SP5-EC2-SAP-On-Demand
libsystemd0-228-157.75.1
libudev1-228-157.75.1
systemd-228-157.75.1
systemd-sysvinit-228-157.75.1
udev-228-157.75.1
Image SLES12-SP5-GCE-BYOS
libsystemd0-228-157.75.1
libudev1-228-157.75.1
systemd-228-157.75.1
systemd-sysvinit-228-157.75.1
udev-228-157.75.1
Image SLES12-SP5-GCE-On-Demand
libsystemd0-228-157.75.1
libudev1-228-157.75.1
systemd-228-157.75.1
systemd-sysvinit-228-157.75.1
udev-228-157.75.1
Image SLES12-SP5-GCE-SAP-BYOS
libsystemd0-228-157.75.1
libudev1-228-157.75.1
systemd-228-157.75.1
systemd-sysvinit-228-157.75.1
udev-228-157.75.1
Image SLES12-SP5-GCE-SAP-On-Demand
libsystemd0-228-157.75.1
libudev1-228-157.75.1
systemd-228-157.75.1
systemd-sysvinit-228-157.75.1
udev-228-157.75.1
SUSE Linux Enterprise Server 12 SP5-LTSS
libsystemd0-228-157.75.1
libsystemd0-32bit-228-157.75.1
libudev-devel-228-157.75.1
libudev1-228-157.75.1
libudev1-32bit-228-157.75.1
systemd-228-157.75.1
systemd-32bit-228-157.75.1
systemd-bash-completion-228-157.75.1
systemd-devel-228-157.75.1
systemd-sysvinit-228-157.75.1
udev-228-157.75.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
libsystemd0-228-157.75.1
libsystemd0-32bit-228-157.75.1
libudev-devel-228-157.75.1
libudev1-228-157.75.1
libudev1-32bit-228-157.75.1
systemd-228-157.75.1
systemd-32bit-228-157.75.1
systemd-bash-completion-228-157.75.1
systemd-devel-228-157.75.1
systemd-sysvinit-228-157.75.1
udev-228-157.75.1

Описание

A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.


Затронутые продукты
Image SLES12-SP5-Azure-BYOS:libsystemd0-228-157.75.1
Image SLES12-SP5-Azure-BYOS:libudev1-228-157.75.1
Image SLES12-SP5-Azure-BYOS:systemd-228-157.75.1
Image SLES12-SP5-Azure-BYOS:systemd-sysvinit-228-157.75.1

Ссылки