SUSE-SU-2016:2475-1

Source
https://www.suse.com/support/update/announcement/2016/suse-su-20162475-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2016:2475-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2016:2475-1
Related
Published
2016-10-07T15:16:23Z
Modified
2016-10-07T15:16:23Z
Summary
Security update for systemd
Details

This update for systemd fixes the following security issue:

  • CVE-2016-7796: A zero-length message received over systemd's notification socket could make managerdispatchnotify_fd() return an error and, as a side effect, disable the notification handler completely. As the notification socket is world-writable, this could have allowed a local user to perform a denial-of-service attack against systemd. (bsc#1001765)

Additionally, the following non-security fixes are included:

  • Fix HMAC calculation when appending a data object to journal. (bsc#1000435)
  • Never accept file descriptors from file systems with mandatory locking enabled. (bsc#954374)
  • Do not warn about missing install info with 'preset'. (bsc#970293)
  • Save /run/systemd/users/UID before starting user@.service. (bsc#996269)
  • Make sure that /var/lib/systemd/sysv-convert/database is always initialized. (bsc#982211)
  • Remove daylight saving time handling and tzfile parser. (bsc#990074)
  • Make sure directory watch is started before cryptsetup. (bsc#987173)
  • Introduce sdpidnotify() and sdpidnotifyf() APIs. (bsc#987857)
  • Set KillMode=mixed for our daemons that fork worker processes.
  • Add nosuid and nodev options to tmp.mount.
  • Don't start console-getty.service when /dev/console is missing. (bsc#982251)
  • Correct segmentation fault in udev/path_id due to missing NULL check. (bsc#982210)
References

Affected packages

SUSE:Linux Enterprise Server for SAP Applications 12 / systemd

Package

Name
systemd
Purl
pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
210-70.58.1

Ecosystem specific

{
    "binaries": [
        {
            "libgudev-1_0-0-32bit": "210-70.58.1",
            "udev": "210-70.58.1",
            "libudev1-32bit": "210-70.58.1",
            "libudev1": "210-70.58.1",
            "libgudev-1_0-0": "210-70.58.1",
            "systemd-32bit": "210-70.58.1",
            "systemd-bash-completion": "210-70.58.1",
            "systemd": "210-70.58.1",
            "systemd-sysvinit": "210-70.58.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12-LTSS / systemd

Package

Name
systemd
Purl
pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
210-70.58.1

Ecosystem specific

{
    "binaries": [
        {
            "libgudev-1_0-0-32bit": "210-70.58.1",
            "udev": "210-70.58.1",
            "libudev1-32bit": "210-70.58.1",
            "libudev1": "210-70.58.1",
            "libgudev-1_0-0": "210-70.58.1",
            "systemd-32bit": "210-70.58.1",
            "systemd-bash-completion": "210-70.58.1",
            "systemd": "210-70.58.1",
            "systemd-sysvinit": "210-70.58.1"
        }
    ]
}