SUSE-SU-2017:0641-1
Dashboard / Vulnerabilities / SUSE-SU-2017:0641-1
SUSE-SU-2017:0641-1
Summary: Security update for dracut
Details: This update for dracut fixes the following issues: Security issues fixed: - CVE-2016-8637: When the early microcode loading was enabled during initrd creation, the initrd would be read-only available for all users, allowing local users to retrieve secrets stored in the initial ramdisk. (bsc#1008340) Non security issues fixed: - Allow booting from degraded MD arrays with systemd. (bsc#1017695) - Start multipath services before local-fs-pre.target. (bsc#1005410, bsc#1006118, bsc#1007925, bsc#986734, bsc#986838)
References: https://www.suse.com/support/update/announcement/2017/suse-su-20170641-1/, https://bugzilla.suse.com/1005410, https://bugzilla.suse.com/1006118, https://bugzilla.suse.com/1007925, https://bugzilla.suse.com/1008340, https://bugzilla.suse.com/1017695, https://bugzilla.suse.com/986734, https://bugzilla.suse.com/986838, https://www.suse.com/security/cve/CVE-2016-8637
Affected packages
Package
Name: dracut
Purl: pkg:rpm/suse/dracut&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
