Oval Definition:oval:org.opensuse.security:def:56047
Revision Date:2021-07-21Version:1
Title:Security update for systemd (Important)
Description:

This update for systemd fixes the following issues:

Security issues fixed:

- CVE-2021-33910: Fixed a denial of service (stack exhaustion) in systemd (PID 1) (bsc#1188063)

Other fixes:

- mount-util: shorten the loop a bit (#7545) - mount-util: do not use the official MAX_HANDLE_SZ (#7523) - mount-util: tape over name_to_handle_at() flakiness (#7517) (bsc#1184761) - mount-util: fix bad indenting - mount-util: EOVERFLOW might have other causes than buffer size issues - mount-util: fix error propagation in fd_fdinfo_mnt_id() - mount-util: drop exponential buffer growing in name_to_handle_at_loop() - udev: port udev_has_devtmpfs() to use path_get_mnt_id() - mount-util: add new path_get_mnt_id() call that queries the mnt ID of a path - mount-util: add name_to_handle_at_loop() wrapper around name_to_handle_at() - mount-util: accept that name_to_handle_at() might fail with EPERM (#5499) - basic: fallback to the fstat if we don't have access to the /proc/self/fdinfo - sysusers: use the usual comment style - test/TEST-21-SYSUSERS: add tests for new functionality - sysusers: allow admin/runtime overrides to command-line config - basic/strv: add function to insert items at position - sysusers: allow the shell to be specified - sysusers: move various user credential validity checks to src/basic/ - man: reformat table in sysusers.d(5) - sysusers: take configuration as positional arguments - sysusers: emit a bit more info at debug level when locking fails - sysusers: allow force reusing existing user/group IDs (#8037) - sysusers: ensure GID in uid:gid syntax exists - sysusers: make ADD_GROUP always create a group - test: add TEST-21-SYSUSERS test - sysuser: use OrderedHashmap - sysusers: allow uid:gid in sysusers.conf files - sysusers: fix memleak (#4430) - These commits implement the option '--replace' for systemd-sysusers so %sysusers_create_package can be introduced in SLE and packages can rely on this rpm macro without wondering whether the macro is available on the different target the package is submitted to. - Expect 644 permissions for /usr/lib/udev/compat-symlink-generation (bsc#1185807) - systemctl: add --value option - execute: make sure to call into PAM after initializing resource limits (bsc#1184967) - rlimit-util: introduce setrlimit_closest_all() - system-conf: drop reference to ShutdownWatchdogUsec= - core: rename ShutdownWatchdogSec to RebootWatchdogSec (bsc#1185331) - Return -EAGAIN instead of -EALREADY from unit_reload (bsc#1185046) - rules: don't ignore Xen virtual interfaces anymore (bsc#1178561) - write_net_rules: set execute bits (bsc#1178561) - udev: rework network device renaming - Revert 'Revert 'udev: network device renaming - immediately give up if the target name isn't available''
Family:unixClass:patch
Status:Reference(s):1019531
1020868
1020890
1020976
1021610
1022428
1023807
1023822
1023848
1027575
1029631
1034911
1035312
1038564
1042892
1046191
1046607
1050751
1057086
1083903
1103098
1120489
1124729
1124734
1128378
1141670
1157471
1163933
1178561
1184761
1184967
1185046
1185331
1185807
1188063
777565
856843
867362
873385
877642
879913
883380
884333
886785
891116
894936
907514
910258
915517
917830
917968
918984
919463
920016
920110
920250
920733
921430
923002
923245
923431
923967
924701
925705
925881
925903
926240
926953
927355
928988
929076
929142
929143
930092
930934
931620
932267
932350
932458
932882
933429
933721
933896
933904
933907
933936
934944
935053
935055
935572
935705
935866
935906
936077
936095
936118
936423
936637
936831
936875
936921
936925
937032
937256
937402
937444
937503
937641
937855
938485
939910
939994
940338
940398
940925
940966
941074
942204
942305
942350
942367
942404
942605
942688
942938
943477
944463
944697
947164
947165
950367
950590
950703
950705
950706
953187
956829
957162
983273
996821
CVE-2007-4129
CVE-2013-4969
CVE-2013-6369
CVE-2014-0222
CVE-2014-3248
CVE-2014-3250
CVE-2014-9728
CVE-2014-9729
CVE-2014-9730
CVE-2014-9731
CVE-2015-0777
CVE-2015-1420
CVE-2015-1805
CVE-2015-2150
CVE-2015-2830
CVE-2015-4037
CVE-2015-4167
CVE-2015-4700
CVE-2015-5239
CVE-2015-5364
CVE-2015-5366
CVE-2015-5707
CVE-2015-6252
CVE-2015-6815
CVE-2015-7311
CVE-2015-7512
CVE-2015-7835
CVE-2015-7969
CVE-2015-7971
CVE-2015-8345
CVE-2015-8899
CVE-2015-9542
CVE-2017-2636
CVE-2017-3302
CVE-2017-3313
CVE-2017-5209
CVE-2017-5545
CVE-2017-5834
CVE-2017-5835
CVE-2017-5836
CVE-2017-6440
CVE-2017-7526
CVE-2017-7533
CVE-2017-7645
CVE-2017-7982
CVE-2017-8890
CVE-2017-9242
CVE-2018-1000115
CVE-2018-20217
CVE-2018-5391
CVE-2019-19191
CVE-2019-6974
CVE-2019-7221
CVE-2019-9213
CVE-2021-33910
SUSE-SU-2015:1678-1
SUSE-SU-2015:1853-1
SUSE-SU-2016:0020-1
SUSE-SU-2016:3269-1
SUSE-SU-2017:1315-1
SUSE-SU-2017:1368-1
SUSE-SU-2017:1794-1
SUSE-SU-2017:2061-1
SUSE-SU-2018:1103-1
SUSE-SU-2019:0113-1
SUSE-SU-2020:0115-1
SUSE-SU-2020:1117-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Desktop 11 SP4
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP2-LTSS-SAP
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 6
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • apache2-2.4.33-lp150.1 is installed
  • OR apache2-doc-2.4.33-lp150.1 is installed
  • OR apache2-example-pages-2.4.33-lp150.1 is installed
  • OR apache2-prefork-2.4.33-lp150.1 is installed
  • OR apache2-utils-2.4.33-lp150.1 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • ncat-7.70-lp151.3.3 is installed
  • OR ndiff-7.70-lp151.3.3 is installed
  • OR nmap-7.70-lp151.3.3 is installed
  • OR nping-7.70-lp151.3.3 is installed
  • OR zenmap-7.70-lp151.3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP3 is installed
  • AND kvm-1.4.2-37 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP4 is installed
  • AND Package Information
  • kernel-default-3.0.101-65 is installed
  • OR kernel-default-base-3.0.101-65 is installed
  • OR kernel-default-devel-3.0.101-65 is installed
  • OR kernel-default-extra-3.0.101-65 is installed
  • OR kernel-pae-3.0.101-65 is installed
  • OR kernel-pae-base-3.0.101-65 is installed
  • OR kernel-pae-devel-3.0.101-65 is installed
  • OR kernel-pae-extra-3.0.101-65 is installed
  • OR kernel-source-3.0.101-65 is installed
  • OR kernel-syms-3.0.101-65 is installed
  • OR kernel-trace-3.0.101-65 is installed
  • OR kernel-trace-devel-3.0.101-65 is installed
  • OR kernel-xen-3.0.101-65 is installed
  • OR kernel-xen-base-3.0.101-65 is installed
  • OR kernel-xen-devel-3.0.101-65 is installed
  • OR kernel-xen-extra-3.0.101-65 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP1 is installed
  • AND Package Information
  • libplist-1.8-10.9 is installed
  • OR libplist++1-1.8-10.9 is installed
  • OR libplist1-1.8-10.9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP2 is installed
  • AND Package Information
  • libgcrypt-1.6.1-16.42 is installed
  • OR libgcrypt20-1.6.1-16.42 is installed
  • OR libgcrypt20-32bit-1.6.1-16.42 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND coolkey-1.1.0-147 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • kgraft-patch-3_12_67-60_64_18-default-9-2 is installed
  • OR kgraft-patch-3_12_67-60_64_18-xen-9-2 is installed
  • OR kgraft-patch-SLE12-SP1_Update_9-9-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • jakarta-commons-fileupload-1.1.1-120 is installed
  • OR jakarta-commons-fileupload-javadoc-1.1.1-120 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • glib2-2.48.2-12.12 is installed
  • OR glib2-lang-2.48.2-12.12 is installed
  • OR glib2-tools-2.48.2-12.12 is installed
  • OR libgio-2_0-0-2.48.2-12.12 is installed
  • OR libgio-2_0-0-32bit-2.48.2-12.12 is installed
  • OR libglib-2_0-0-2.48.2-12.12 is installed
  • OR libglib-2_0-0-32bit-2.48.2-12.12 is installed
  • OR libgmodule-2_0-0-2.48.2-12.12 is installed
  • OR libgmodule-2_0-0-32bit-2.48.2-12.12 is installed
  • OR libgobject-2_0-0-2.48.2-12.12 is installed
  • OR libgobject-2_0-0-32bit-2.48.2-12.12 is installed
  • OR libgthread-2_0-0-2.48.2-12.12 is installed
  • OR libgthread-2_0-0-32bit-2.48.2-12.12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • xen-4.7.6_04-43.39 is installed
  • OR xen-doc-html-4.7.6_04-43.39 is installed
  • OR xen-libs-4.7.6_04-43.39 is installed
  • OR xen-libs-32bit-4.7.6_04-43.39 is installed
  • OR xen-tools-4.7.6_04-43.39 is installed
  • OR xen-tools-domU-4.7.6_04-43.39 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_120-92_70-default-3-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_20-3-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • cpio-2.11-35 is installed
  • OR cpio-lang-2.11-35 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • libruby2_1-2_1-2.1.9-19.3 is installed
  • OR ruby2.1-2.1.9-19.3 is installed
  • OR ruby2.1-stdlib-2.1.9-19.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • libjavascriptcoregtk-4_0-18-2.20.3-2.23 is installed
  • OR libwebkit2gtk-4_0-37-2.20.3-2.23 is installed
  • OR typelib-1_0-JavaScriptCore-4_0-2.20.3-2.23 is installed
  • OR typelib-1_0-WebKit2-4_0-2.20.3-2.23 is installed
  • OR webkit2gtk-4_0-injected-bundles-2.20.3-2.23 is installed
  • OR webkit2gtk3-2.20.3-2.23 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • guestfs-data-1.32.4-21.3 is installed
  • OR guestfs-tools-1.32.4-21.3 is installed
  • OR guestfsd-1.32.4-21.3 is installed
  • OR libguestfs0-1.32.4-21.3 is installed
  • OR perl-Sys-Guestfs-1.32.4-21.3 is installed
  • OR python-libguestfs-1.32.4-21.3 is installed
  • OR virt-p2v-1.32.4-21.3 is installed
  • OR virt-v2v-1.32.4-21.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 6 is installed
  • AND crowbar-openstack-3.0+git.1521471181.2b39130da-39.10 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • xen-4.7.6_05-43.42 is installed
  • OR xen-doc-html-4.7.6_05-43.42 is installed
  • OR xen-libs-4.7.6_05-43.42 is installed
  • OR xen-libs-32bit-4.7.6_05-43.42 is installed
  • OR xen-tools-4.7.6_05-43.42 is installed
  • OR xen-tools-domU-4.7.6_05-43.42 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • cups-1.7.5-20.26 is installed
  • OR cups-client-1.7.5-20.26 is installed
  • OR cups-libs-1.7.5-20.26 is installed
  • OR cups-libs-32bit-1.7.5-20.26 is installed
  • BACK