Описание
Security update for iproute2
This update for iproute2 fixes the following issue
- CVE-2024-58251: denial of service via terminal escape sequences (bsc#1254324).
Список пакетов
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
iproute2-4.12-16.9.1
libnetlink-devel-4.12-16.9.1
Ссылки
- Link for SUSE-SU-2026:3150-1
- E-Mail link for SUSE-SU-2026:3150-1
- SUSE Security Ratings
- SUSE Bug 1254324
- SUSE CVE CVE-2024-58251 page
Описание
In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:iproute2-4.12-16.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libnetlink-devel-4.12-16.9.1
Ссылки
- CVE-2024-58251
- SUSE Bug 1241700