SUSE-SU-2017:1898-1
Dashboard / Vulnerabilities / SUSE-SU-2017:1898-1
SUSE-SU-2017:1898-1
Summary: Security update for systemd, dracut
Details: This update for systemd and dracut fixes the following issues: Security issues fixed: - CVE-2017-9445: Possible out-of-bounds write triggered by a specially crafted TCP payload from a DNS server. (bsc#1045290) Non-security issues fixed in systemd: - Automounter issue in combination with NFS volumes (bsc#1040968) - Missing symbolic link for SAS device in /dev/disk/by-path (bsc#1040153) - Add minimal support for boot.d/* scripts in systemd-sysv-convert (bsc#1046750) Non-security issues fixed in dracut: - Bail out if module directory does not exist. (bsc#1043900) - Suppress bogus error message. (bsc#1032029) - Fix module force loading with systemd. (bsc#986216) - Ship udev files required by systemd. (bsc#1040153) - Ignore module resolution errors (e.g. with kgraft). (bsc#1037120)
References: https://www.suse.com/support/update/announcement/2017/suse-su-20171898-1/, https://bugzilla.suse.com/1032029, https://bugzilla.suse.com/1033238, https://bugzilla.suse.com/1037120, https://bugzilla.suse.com/1040153, https://bugzilla.suse.com/1040968, https://bugzilla.suse.com/1043900, https://bugzilla.suse.com/1045290, https://bugzilla.suse.com/1046750, https://bugzilla.suse.com/986216, https://www.suse.com/security/cve/CVE-2017-9445
Affected packages
Package
Name: dracut
Purl: pkg:rpm/suse/dracut&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
