Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20949-1

Опубликовано: 12 июн. 2026
Источник: suse-cvrf

Описание

Security update for wicked

This update for wicked fixes the following issues:

Changes in wicked:

  • Update to version 0.6.79
    • Fix an indirect remote shell command injection via unsanitized dhcp strings and leaseinfo dump (bsc#1265221,CVE-2026-44932):
      • Fix to escape single-quotes in leaseinfo dump output used by the wicked test dhcp4 and wicked test dhcp6 and written to the /run/wicked/leaseinfo.* files, e.g. to pass them to netconfig. A netconfig modify filtered for strict key='value' lines without any escaped quotes and discarded these lines already before.
      • Fix posix-tz-dbname and tz-string option processing checks to permit only valid characters according to RFC4833.
      • Discard string values containing single-quotes in other options.
      • Trigger to regenerate initrd that may contain wicked binaries on updates from wicked versions <= 0.6.78.

Список пакетов

openSUSE Leap 16.0
wicked-0.6.79-bp160.1.1
wicked-nbft-0.6.79-bp160.1.1
wicked-service-0.6.79-bp160.1.1

Описание

unknown


Затронутые продукты
openSUSE Leap 16.0:wicked-0.6.79-bp160.1.1
openSUSE Leap 16.0:wicked-nbft-0.6.79-bp160.1.1
openSUSE Leap 16.0:wicked-service-0.6.79-bp160.1.1

Ссылки