SUSE-SU-2023:1776-1

Source
https://www.suse.com/support/update/announcement/2023/suse-su-20231776-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:1776-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2023:1776-1
Related
Published
2023-04-05T13:20:40Z
Modified
2023-04-05T13:20:40Z
Summary
Security update for systemd
Details

This update for systemd fixes the following issues:

  • CVE-2023-26604: Fixed a privilege escalation via the less pager. (bsc#1208958)
  • CVE-2022-4415: Fixed systemd-coredump that did not respect the fs.suid_dumpable kernel setting (bsc#1205000).
  • CVE-2022-3821: Fixed buffer overrun in format_timespan() function (bsc#1204968).

Bug fixes:

  • Restrict cpu rule to x86_64, and also update the rule files to make use of the 'CONST{arch}' syntax (bsc#1204423).
  • Fixed 'systemd --user' call pam_loginuid when creating user@.service (bsc#1198507).
  • Fixed 'systemd-detect-virt' refine hypervisor detection (bsc#1197244).
  • Fixed 'udev' 60-persistent-storage-tape.rules: handle duplicate device ID (bsc#1195529).
  • Fixed 'man' tweak description of auto/noauto (bsc#1191502).
References

Affected packages

SUSE:OpenStack Cloud 9 / systemd

Package

Name
systemd
Purl
pkg:rpm/suse/systemd&distro=SUSE%20OpenStack%20Cloud%209

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
228-150.108.2

Ecosystem specific

{
    "binaries": [
        {
            "libudev1-32bit": "228-150.108.2",
            "libsystemd0": "228-150.108.2",
            "systemd-devel": "228-150.108.2",
            "libudev-devel": "228-150.108.2",
            "udev": "228-150.108.2",
            "libudev1": "228-150.108.2",
            "systemd-32bit": "228-150.108.2",
            "systemd-bash-completion": "228-150.108.2",
            "libsystemd0-32bit": "228-150.108.2",
            "systemd": "228-150.108.2",
            "systemd-sysvinit": "228-150.108.2"
        }
    ]
}

SUSE:OpenStack Cloud Crowbar 9 / systemd

Package

Name
systemd
Purl
pkg:rpm/suse/systemd&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
228-150.108.2

Ecosystem specific

{
    "binaries": [
        {
            "libudev1-32bit": "228-150.108.2",
            "libsystemd0": "228-150.108.2",
            "systemd-devel": "228-150.108.2",
            "libudev-devel": "228-150.108.2",
            "udev": "228-150.108.2",
            "libudev1": "228-150.108.2",
            "systemd-32bit": "228-150.108.2",
            "systemd-bash-completion": "228-150.108.2",
            "libsystemd0-32bit": "228-150.108.2",
            "systemd": "228-150.108.2",
            "systemd-sysvinit": "228-150.108.2"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP4 / systemd

Package

Name
systemd
Purl
pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
228-150.108.2

Ecosystem specific

{
    "binaries": [
        {
            "libudev1-32bit": "228-150.108.2",
            "libsystemd0": "228-150.108.2",
            "systemd-devel": "228-150.108.2",
            "libudev-devel": "228-150.108.2",
            "udev": "228-150.108.2",
            "libudev1": "228-150.108.2",
            "systemd-32bit": "228-150.108.2",
            "systemd-bash-completion": "228-150.108.2",
            "libsystemd0-32bit": "228-150.108.2",
            "systemd": "228-150.108.2",
            "systemd-sysvinit": "228-150.108.2"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP2-BCL / systemd

Package

Name
systemd
Purl
pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
228-150.108.2

Ecosystem specific

{
    "binaries": [
        {
            "libudev1-32bit": "228-150.108.2",
            "libsystemd0": "228-150.108.2",
            "systemd-devel": "228-150.108.2",
            "udev": "228-150.108.2",
            "libudev1": "228-150.108.2",
            "systemd-32bit": "228-150.108.2",
            "systemd-bash-completion": "228-150.108.2",
            "libsystemd0-32bit": "228-150.108.2",
            "systemd": "228-150.108.2",
            "systemd-sysvinit": "228-150.108.2"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP4-ESPOS / systemd

Package

Name
systemd
Purl
pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
228-150.108.2

Ecosystem specific

{
    "binaries": [
        {
            "libudev1-32bit": "228-150.108.2",
            "libsystemd0": "228-150.108.2",
            "systemd-devel": "228-150.108.2",
            "libudev-devel": "228-150.108.2",
            "udev": "228-150.108.2",
            "libudev1": "228-150.108.2",
            "systemd-32bit": "228-150.108.2",
            "systemd-bash-completion": "228-150.108.2",
            "libsystemd0-32bit": "228-150.108.2",
            "systemd": "228-150.108.2",
            "systemd-sysvinit": "228-150.108.2"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP4-LTSS / systemd

Package

Name
systemd
Purl
pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
228-150.108.2

Ecosystem specific

{
    "binaries": [
        {
            "libudev1-32bit": "228-150.108.2",
            "libsystemd0": "228-150.108.2",
            "systemd-devel": "228-150.108.2",
            "libudev-devel": "228-150.108.2",
            "udev": "228-150.108.2",
            "libudev1": "228-150.108.2",
            "systemd-32bit": "228-150.108.2",
            "systemd-bash-completion": "228-150.108.2",
            "libsystemd0-32bit": "228-150.108.2",
            "systemd": "228-150.108.2",
            "systemd-sysvinit": "228-150.108.2"
        }
    ]
}