Описание
Security update for systemd
This update for systemd fixes the following issue:
- CVE-2026-4105: privilege escalation due to improper access control in RegisterMachine D-Bus method (bsc#1259650).
- udev: check for invalid chars in various fields received from the kernel (bsc#1259697).
Changelog:
cbf8ee66ee machined: reject invalid class types when registering machines 1a55ad48da udev: fix review mixup 1eba76668c udev-builtin-net-id: print cescaped bad attributes cbd4b55380 udev: ensure tag parsing stays within bounds 5973d3b1cc udev: ensure there is space for trailing NUL before calling sprintf f038eb6c8b udev: check for invalid chars in various fields received from the kernel
Список пакетов
Image SLES12-SP5-Azure-BYOS
Image SLES12-SP5-Azure-HPC-BYOS
Image SLES12-SP5-Azure-HPC-On-Demand
Image SLES12-SP5-Azure-SAP-BYOS
Image SLES12-SP5-Azure-SAP-On-Demand
Image SLES12-SP5-Azure-Standard-On-Demand
Image SLES12-SP5-EC2-BYOS
Image SLES12-SP5-EC2-ECS-On-Demand
Image SLES12-SP5-EC2-On-Demand
Image SLES12-SP5-EC2-SAP-BYOS
Image SLES12-SP5-EC2-SAP-On-Demand
Image SLES12-SP5-GCE-BYOS
Image SLES12-SP5-GCE-On-Demand
Image SLES12-SP5-GCE-SAP-BYOS
Image SLES12-SP5-GCE-SAP-On-Demand
SUSE Linux Enterprise Server 12 SP5-LTSS
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
Ссылки
- Link for SUSE-SU-2026:0991-1
- E-Mail link for SUSE-SU-2026:0991-1
- SUSE Security Ratings
- SUSE Bug 1259650
- SUSE Bug 1259697
- SUSE CVE CVE-2026-4105 page
Описание
A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.
Затронутые продукты
Ссылки
- CVE-2026-4105
- SUSE Bug 1259650
- SUSE Bug 1265554