Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2349-1

Опубликовано: 10 июн. 2026
Источник: suse-cvrf

Описание

Security update for wicked

This update for wicked fixes the following issue

  • CVE-2026-44932: indirect remote shell command injection via unsanitized DHCP options (bsc#1265221).

Changes for wicked:

  • Update to version 0.6.79
  • Fix to escape single-quotes in leaseinfo dump output used by the wicked test dhcp4 and wicked test dhcp6 and written to the /run/wicked/leaseinfo.* files, e.g. to pass them to netconfig. A netconfig modify filtered for strict key='value' lines without any escaped quotes and discarded these lines already before.
  • Fix posix-tz-dbname and tz-string option processing checks to permit only valid characters according to RFC4833.
  • Discard string values containing single-quotes in other options.
  • Trigger to regenerate initrd that may contain wicked binaries on updates from wicked versions <= 0.6.78.

Список пакетов

Image SLES15-SP7-Azure-3P
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-Azure-Basic
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-Azure-Standard
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-BYOS-Azure
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-BYOS-EC2
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-BYOS-GCE
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-CHOST-BYOS-Aliyun
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-CHOST-BYOS-Azure
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-CHOST-BYOS-EC2
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-CHOST-BYOS-GCE
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-CHOST-BYOS-GDC
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-CHOST-BYOS-SAP-CCloud
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-EC2
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-EC2-ECS-HVM
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-GCE
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-HPC-Azure
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-HPC-BYOS-Azure
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-HPC-BYOS-EC2
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-HPC-BYOS-GCE
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-Hardened-BYOS-Azure
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-Hardened-BYOS-EC2
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-Hardened-BYOS-GCE
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-SAP-Azure
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-SAP-Azure-3P
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-SAP-BYOS-Azure
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-SAP-BYOS-EC2
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-SAP-BYOS-GCE
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-SAP-EC2
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-SAP-GCE
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-SAP-Hardened-Azure
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-SAP-Hardened-BYOS-Azure
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-SAP-Hardened-BYOS-EC2
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-SAP-Hardened-BYOS-GCE
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-SAP-Hardened-GCE
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-SAPCAL-Azure
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-SAPCAL-EC2
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-SAPCAL-GCE
wicked-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
wicked-0.6.79-150700.3.3.1
wicked-nbft-0.6.79-150700.3.3.1
wicked-service-0.6.79-150700.3.3.1

Описание

Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.


Затронутые продукты
Image SLES15-SP7-Azure-3P:wicked-0.6.79-150700.3.3.1
Image SLES15-SP7-Azure-3P:wicked-service-0.6.79-150700.3.3.1
Image SLES15-SP7-Azure-Basic:wicked-0.6.79-150700.3.3.1
Image SLES15-SP7-Azure-Basic:wicked-service-0.6.79-150700.3.3.1

Ссылки