Описание
Security update for iproute2
This update for iproute2 fixes the following issues:
Security issues fixed:
- CVE-2024-58251: terminal lock up via ANSI terminal escape sequence set in
argv[0](bsc#1254324).
Other updates and bugfixes:
- Fix package for immutable mode (jsc#PED-14787).
- Add netshaper support (bsc#1253044).
- Add follow-up fixes included by upstream after the 6.12 release (bsc#1241316):
- Parse FQ band weights correctly
- bond: fix stack smash in xstats
- ip: support setting multiple features
- tc: gred: fix debug print
Список пакетов
openSUSE Leap 16.0
iproute2-6.12-160000.3.1
iproute2-arpd-6.12-160000.3.1
iproute2-bash-completion-6.12-160000.3.1
libnetlink-devel-6.12-160000.3.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1241316
- SUSE Bug 1253044
- SUSE Bug 1254324
- SUSE CVE CVE-2024-58251 page
Описание
In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
Затронутые продукты
openSUSE Leap 16.0:iproute2-6.12-160000.3.1
openSUSE Leap 16.0:iproute2-arpd-6.12-160000.3.1
openSUSE Leap 16.0:iproute2-bash-completion-6.12-160000.3.1
openSUSE Leap 16.0:libnetlink-devel-6.12-160000.3.1
Ссылки
- CVE-2024-58251
- SUSE Bug 1241700