{"id":"SUSE-SU-2021:2423-1","summary":"Security update for systemd","details":"This update for systemd fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2021-33910: Fixed a denial of service (stack exhaustion) in systemd (PID 1) (bsc#1188063)\n\nOther fixes:\n\n- mount-util: shorten the loop a bit (#7545)\n- mount-util: do not use the official MAX_HANDLE_SZ (#7523)\n- mount-util: tape over name_to_handle_at() flakiness (#7517) (bsc#1184761)\n- mount-util: fix bad indenting\n- mount-util: EOVERFLOW might have other causes than buffer size issues\n- mount-util: fix error propagation in fd_fdinfo_mnt_id()\n- mount-util: drop exponential buffer growing in name_to_handle_at_loop()\n- udev: port udev_has_devtmpfs() to use path_get_mnt_id()\n- mount-util: add new path_get_mnt_id() call that queries the mnt ID of a path\n- mount-util: add name_to_handle_at_loop() wrapper around name_to_handle_at()\n- mount-util: accept that name_to_handle_at() might fail with EPERM (#5499)\n- basic: fallback to the fstat if we don't have access to the /proc/self/fdinfo\n- sysusers: use the usual comment style\n- test/TEST-21-SYSUSERS: add tests for new functionality\n- sysusers: allow admin/runtime overrides to command-line config\n- basic/strv: add function to insert items at position\n- sysusers: allow the shell to be specified\n- sysusers: move various user credential validity checks to src/basic/\n- man: reformat table in sysusers.d(5)\n- sysusers: take configuration as positional arguments\n- sysusers: emit a bit more info at debug level when locking fails\n- sysusers: allow force reusing existing user/group IDs (#8037)\n- sysusers: ensure GID in uid:gid syntax exists\n- sysusers: make ADD_GROUP always create a group\n- test: add TEST-21-SYSUSERS test\n- sysuser: use OrderedHashmap\n- sysusers: allow uid:gid in sysusers.conf files\n- sysusers: fix memleak (#4430)\n- These commits implement the option '--replace' for systemd-sysusers\n  so %sysusers_create_package can be introduced in SLE and packages\n  can rely on this rpm macro without wondering whether the macro is\n  available on the different target the package is submitted to.\n- Expect 644 permissions for /usr/lib/udev/compat-symlink-generation (bsc#1185807)\n- systemctl: add --value option\n- execute: make sure to call into PAM after initializing resource limits (bsc#1184967)\n- rlimit-util: introduce setrlimit_closest_all()\n- system-conf: drop reference to ShutdownWatchdogUsec=\n- core: rename ShutdownWatchdogSec to RebootWatchdogSec (bsc#1185331)\n- Return -EAGAIN instead of -EALREADY from unit_reload (bsc#1185046)\n- rules: don't ignore Xen virtual interfaces anymore (bsc#1178561)\n- write_net_rules: set execute bits (bsc#1178561)\n- udev: rework network device renaming\n- Revert 'Revert 'udev: network device renaming - immediately give up if the target name isn't available''\n","modified":"2026-03-11T07:16:52.733100Z","published":"2021-07-21T09:04:20Z","related":["CVE-2021-33910"],"upstream":["CVE-2021-33910"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2021/suse-su-20212423-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178561"},{"type":"REPORT","url":"https://bugzilla.suse.com/1184761"},{"type":"REPORT","url":"https://bugzilla.suse.com/1184967"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185046"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185331"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185807"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188063"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-33910"}],"affected":[{"package":{"name":"systemd","ecosystem":"SUSE:HPE Helion OpenStack 8","purl":"pkg:rpm/suse/systemd&distro=HPE%20Helion%20OpenStack%208"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"228-150.98.1"}]}],"ecosystem_specific":{"binaries":[{"libudev-devel":"228-150.98.1","libudev1-32bit":"228-150.98.1","libudev1":"228-150.98.1","systemd-sysvinit":"228-150.98.1","systemd":"228-150.98.1","udev":"228-150.98.1","libsystemd0-32bit":"228-150.98.1","libsystemd0":"228-150.98.1","systemd-32bit":"228-150.98.1","systemd-bash-completion":"228-150.98.1","systemd-devel":"228-150.98.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:2423-1.json"}},{"package":{"name":"systemd","ecosystem":"SUSE:OpenStack Cloud 8","purl":"pkg:rpm/suse/systemd&distro=SUSE%20OpenStack%20Cloud%208"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"228-150.98.1"}]}],"ecosystem_specific":{"binaries":[{"libudev1-32bit":"228-150.98.1","systemd-bash-completion":"228-150.98.1","systemd-devel":"228-150.98.1","systemd-sysvinit":"228-150.98.1","systemd":"228-150.98.1","libsystemd0-32bit":"228-150.98.1","libsystemd0":"228-150.98.1","libudev-devel":"228-150.98.1","libudev1":"228-150.98.1","systemd-32bit":"228-150.98.1","udev":"228-150.98.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:2423-1.json"}},{"package":{"name":"systemd","ecosystem":"SUSE:OpenStack Cloud 9","purl":"pkg:rpm/suse/systemd&distro=SUSE%20OpenStack%20Cloud%209"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"228-150.98.1"}]}],"ecosystem_specific":{"binaries":[{"libudev1":"228-150.98.1","systemd-32bit":"228-150.98.1","systemd-devel":"228-150.98.1","systemd-sysvinit":"228-150.98.1","libsystemd0-32bit":"228-150.98.1","libsystemd0":"228-150.98.1","systemd-bash-completion":"228-150.98.1","systemd":"228-150.98.1","udev":"228-150.98.1","libudev-devel":"228-150.98.1","libudev1-32bit":"228-150.98.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:2423-1.json"}},{"package":{"name":"systemd","ecosystem":"SUSE:OpenStack Cloud Crowbar 8","purl":"pkg:rpm/suse/systemd&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"228-150.98.1"}]}],"ecosystem_specific":{"binaries":[{"libudev1-32bit":"228-150.98.1","systemd-sysvinit":"228-150.98.1","systemd":"228-150.98.1","udev":"228-150.98.1","libsystemd0-32bit":"228-150.98.1","libsystemd0":"228-150.98.1","libudev1":"228-150.98.1","systemd-32bit":"228-150.98.1","systemd-bash-completion":"228-150.98.1","systemd-devel":"228-150.98.1","libudev-devel":"228-150.98.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:2423-1.json"}},{"package":{"name":"systemd","ecosystem":"SUSE:OpenStack Cloud Crowbar 9","purl":"pkg:rpm/suse/systemd&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"228-150.98.1"}]}],"ecosystem_specific":{"binaries":[{"systemd-devel":"228-150.98.1","systemd-sysvinit":"228-150.98.1","systemd":"228-150.98.1","udev":"228-150.98.1","libsystemd0":"228-150.98.1","libudev-devel":"228-150.98.1","libudev1-32bit":"228-150.98.1","libudev1":"228-150.98.1","libsystemd0-32bit":"228-150.98.1","systemd-32bit":"228-150.98.1","systemd-bash-completion":"228-150.98.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:2423-1.json"}},{"package":{"name":"systemd","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP3","purl":"pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"228-150.98.1"}]}],"ecosystem_specific":{"binaries":[{"libsystemd0-32bit":"228-150.98.1","libudev-devel":"228-150.98.1","systemd-32bit":"228-150.98.1","systemd-devel":"228-150.98.1","systemd":"228-150.98.1","udev":"228-150.98.1","libsystemd0":"228-150.98.1","libudev1-32bit":"228-150.98.1","libudev1":"228-150.98.1","systemd-bash-completion":"228-150.98.1","systemd-sysvinit":"228-150.98.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:2423-1.json"}},{"package":{"name":"systemd","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","purl":"pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"228-150.98.1"}]}],"ecosystem_specific":{"binaries":[{"libudev1":"228-150.98.1","systemd-32bit":"228-150.98.1","systemd-bash-completion":"228-150.98.1","systemd":"228-150.98.1","libsystemd0":"228-150.98.1","libudev-devel":"228-150.98.1","systemd-devel":"228-150.98.1","systemd-sysvinit":"228-150.98.1","udev":"228-150.98.1","libsystemd0-32bit":"228-150.98.1","libudev1-32bit":"228-150.98.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:2423-1.json"}},{"package":{"name":"systemd","ecosystem":"SUSE:Linux Enterprise Server 12 SP2-BCL","purl":"pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"228-150.98.1"}]}],"ecosystem_specific":{"binaries":[{"libudev1-32bit":"228-150.98.1","libudev1":"228-150.98.1","systemd-bash-completion":"228-150.98.1","systemd-devel":"228-150.98.1","systemd":"228-150.98.1","libsystemd0-32bit":"228-150.98.1","systemd-32bit":"228-150.98.1","systemd-sysvinit":"228-150.98.1","udev":"228-150.98.1","libsystemd0":"228-150.98.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:2423-1.json"}},{"package":{"name":"systemd","ecosystem":"SUSE:Linux Enterprise Server 12 SP3-LTSS","purl":"pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"228-150.98.1"}]}],"ecosystem_specific":{"binaries":[{"libsystemd0":"228-150.98.1","libudev1":"228-150.98.1","systemd-32bit":"228-150.98.1","systemd-devel":"228-150.98.1","systemd-sysvinit":"228-150.98.1","libsystemd0-32bit":"228-150.98.1","libudev-devel":"228-150.98.1","libudev1-32bit":"228-150.98.1","systemd-bash-completion":"228-150.98.1","systemd":"228-150.98.1","udev":"228-150.98.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:2423-1.json"}},{"package":{"name":"systemd","ecosystem":"SUSE:Linux Enterprise Server 12 SP3-BCL","purl":"pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"228-150.98.1"}]}],"ecosystem_specific":{"binaries":[{"libsystemd0":"228-150.98.1","libudev1-32bit":"228-150.98.1","systemd-32bit":"228-150.98.1","systemd":"228-150.98.1","udev":"228-150.98.1","libsystemd0-32bit":"228-150.98.1","libudev1":"228-150.98.1","systemd-bash-completion":"228-150.98.1","systemd-devel":"228-150.98.1","systemd-sysvinit":"228-150.98.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:2423-1.json"}},{"package":{"name":"systemd","ecosystem":"SUSE:Linux Enterprise Server 12 SP4-LTSS","purl":"pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"228-150.98.1"}]}],"ecosystem_specific":{"binaries":[{"libsystemd0-32bit":"228-150.98.1","libsystemd0":"228-150.98.1","libudev-devel":"228-150.98.1","libudev1-32bit":"228-150.98.1","libudev1":"228-150.98.1","systemd-32bit":"228-150.98.1","systemd-devel":"228-150.98.1","systemd-sysvinit":"228-150.98.1","systemd-bash-completion":"228-150.98.1","systemd":"228-150.98.1","udev":"228-150.98.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:2423-1.json"}}],"schema_version":"1.7.5"}