Описание
Security update for wicked
This update for wicked fixes the following issues:
Changes in wicked:
- Update to version 0.6.79
- Fix an indirect remote shell command injection via unsanitized
dhcp strings and leaseinfo dump (bsc#1265221,CVE-2026-44932):
- Fix to escape single-quotes in leaseinfo dump output used by the
wicked test dhcp4andwicked test dhcp6and written to the /run/wicked/leaseinfo.* files, e.g. to pass them to netconfig. A netconfig modify filtered for strict key='value' lines without any escaped quotes and discarded these lines already before. - Fix posix-tz-dbname and tz-string option processing checks to permit only valid characters according to RFC4833.
- Discard string values containing single-quotes in other options.
- Trigger to regenerate initrd that may contain wicked binaries on updates from wicked versions <= 0.6.78.
- Fix to escape single-quotes in leaseinfo dump output used by the
- Fix an indirect remote shell command injection via unsanitized
dhcp strings and leaseinfo dump (bsc#1265221,CVE-2026-44932):
Список пакетов
openSUSE Leap 16.0
wicked-0.6.79-bp160.1.1
wicked-nbft-0.6.79-bp160.1.1
wicked-service-0.6.79-bp160.1.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1265221
- SUSE CVE CVE-2026-44932 page
Описание
unknown
Затронутые продукты
openSUSE Leap 16.0:wicked-0.6.79-bp160.1.1
openSUSE Leap 16.0:wicked-nbft-0.6.79-bp160.1.1
openSUSE Leap 16.0:wicked-service-0.6.79-bp160.1.1
Ссылки
- CVE-2026-44932
- SUSE Bug 1265221