{"id":"openSUSE-SU-2020:0208-1","summary":"Security update for systemd","details":"This update for systemd fixes the following issues:\n\n- CVE-2020-1712 (bsc#bsc#1162108)\n  Fix a heap use-after-free vulnerability, when asynchronous\n  Polkit queries were performed while handling Dbus messages. A local\n  unprivileged attacker could have abused this flaw to crash systemd services or\n  potentially execute code and elevate their privileges, by sending specially\n  crafted Dbus messages.\n\n- Use suse.pool.ntp.org server pool on SLE distros (jsc#SLE-7683)\n\n- libblkid: open device in nonblock mode. (bsc#1084671)\n- udev/cdrom_id: Do not open CD-rom in exclusive mode. (bsc#1154256)\n- bus_open leak sd_event_source when udevadm trigger。 (bsc#1161436 CVE-2019-20386)\n- fileio: introduce read_full_virtual_file() for reading virtual files in sysfs, procfs (bsc#1133495 bsc#1159814)\n- fileio: initialize errno to zero before we do fread()\n- fileio: try to read one byte too much in read_full_stream()\n- logind: consider 'greeter' sessions suitable as 'display' sessions of a user (bsc#1158485)\n- logind: never elect a session that is stopping as display\n\n- journal: include kmsg lines from the systemd process which exec()d us (#8078)\n- udevd: don't use monitor after manager_exit()\n- udevd: capitalize log messages in on_sigchld()\n- udevd: merge conditions to decrease indentation\n- Revert 'udevd: fix crash when workers time out after exit is signal caught'\n- core: fragments of masked units ought not be considered for NeedDaemonReload (#7060) (bsc#1156482)\n- udevd: fix crash when workers time out after exit is signal caught\n- udevd: wait for workers to finish when exiting (bsc#1106383)\n\n- Improve bash completion support (bsc#1155207)\n  * shell-completion: systemctl: do not list template units in {re,}start\n  * shell-completion: systemctl: pass current word to all list_unit*\n  * bash-completion: systemctl: pass current partial unit to list-unit* (bsc#1155207)\n  * bash-completion: systemctl: use systemctl --no-pager\n  * bash-completion: also suggest template unit files\n  * bash-completion: systemctl: add missing options and verbs\n  * bash-completion: use the first argument instead of the global variable (#6457)\n\n- networkd: VXLan Make group and remote variable separate (bsc#1156213)\n- networkd: vxlan require Remote= to be a non multicast address (#8117) (bsc#1156213)\n- fs-util: let's avoid unnecessary strerror()\n- fs-util: introduce inotify_add_watch_and_warn() helper\n- ask-password: improve log message when inotify limit is reached (bsc#1155574)\n- shared/install: failing with -ELOOP can be due to the use of an alias in install_error() (bsc#1151377)\n- man: alias names can't be used with enable command (bsc#1151377)\n\n- Add boot option to not use swap at system start (jsc#SLE-7689)\n\n- Allow YaST to select Iranian (Persian, Farsi) keyboard layout\n  (bsc#1092920)\n  \nThis update was imported from the SUSE:SLE-15:Update update project.","modified":"2026-03-11T07:32:23.587823Z","published":"2020-02-11T19:12:44Z","related":["CVE-2019-20386","CVE-2020-1712"],"upstream":["CVE-2019-20386","CVE-2020-1712"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3SLX2X3J4XZECXPBKC7QV2ZINGO53ABE/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1084671"},{"type":"REPORT","url":"https://bugzilla.suse.com/1092920"},{"type":"REPORT","url":"https://bugzilla.suse.com/1106383"},{"type":"REPORT","url":"https://bugzilla.suse.com/1133495"},{"type":"REPORT","url":"https://bugzilla.suse.com/1151377"},{"type":"REPORT","url":"https://bugzilla.suse.com/1154256"},{"type":"REPORT","url":"https://bugzilla.suse.com/1155207"},{"type":"REPORT","url":"https://bugzilla.suse.com/1155574"},{"type":"REPORT","url":"https://bugzilla.suse.com/1156213"},{"type":"REPORT","url":"https://bugzilla.suse.com/1156482"},{"type":"REPORT","url":"https://bugzilla.suse.com/1158485"},{"type":"REPORT","url":"https://bugzilla.suse.com/1159814"},{"type":"REPORT","url":"https://bugzilla.suse.com/1161436"},{"type":"REPORT","url":"https://bugzilla.suse.com/1162108"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-20386"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-1712"}],"affected":[{"package":{"name":"systemd","ecosystem":"openSUSE:Leap 15.1","purl":"pkg:rpm/opensuse/systemd&distro=openSUSE%20Leap%2015.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"234-lp151.26.7.1"}]}],"ecosystem_specific":{"binaries":[{"systemd":"234-lp151.26.7.1","libsystemd0":"234-lp151.26.7.1","libudev-devel-32bit":"234-lp151.26.7.1","libudev-devel":"234-lp151.26.7.1","libudev1-32bit":"234-lp151.26.7.1","systemd-container":"234-lp151.26.7.1","systemd-mini-sysvinit":"234-lp151.26.7.1","libsystemd0-mini":"234-lp151.26.7.1","libudev1":"234-lp151.26.7.1","libsystemd0-32bit":"234-lp151.26.7.1","nss-myhostname-32bit":"234-lp151.26.7.1","nss-mymachines":"234-lp151.26.7.1","systemd-bash-completion":"234-lp151.26.7.1","systemd-logger":"234-lp151.26.7.1","systemd-mini-bash-completion":"234-lp151.26.7.1","systemd-mini-devel":"234-lp151.26.7.1","systemd-sysvinit":"234-lp151.26.7.1","nss-myhostname":"234-lp151.26.7.1","nss-mymachines-32bit":"234-lp151.26.7.1","systemd-32bit":"234-lp151.26.7.1","systemd-coredump":"234-lp151.26.7.1","systemd-mini-container-mini":"234-lp151.26.7.1","systemd-mini":"234-lp151.26.7.1","libudev-mini1":"234-lp151.26.7.1","systemd-devel":"234-lp151.26.7.1","systemd-mini-coredump-mini":"234-lp151.26.7.1","udev":"234-lp151.26.7.1","libudev-mini-devel":"234-lp151.26.7.1","nss-systemd":"234-lp151.26.7.1","udev-mini":"234-lp151.26.7.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0208-1.json"}},{"package":{"name":"systemd-mini","ecosystem":"openSUSE:Leap 15.1","purl":"pkg:rpm/opensuse/systemd-mini&distro=openSUSE%20Leap%2015.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"234-lp151.26.7.1"}]}],"ecosystem_specific":{"binaries":[{"libsystemd0":"234-lp151.26.7.1","nss-myhostname-32bit":"234-lp151.26.7.1","systemd-32bit":"234-lp151.26.7.1","systemd-mini-bash-completion":"234-lp151.26.7.1","systemd-mini-coredump-mini":"234-lp151.26.7.1","systemd-sysvinit":"234-lp151.26.7.1","libsystemd0-mini":"234-lp151.26.7.1","libudev-devel":"234-lp151.26.7.1","nss-mymachines":"234-lp151.26.7.1","systemd-mini":"234-lp151.26.7.1","systemd":"234-lp151.26.7.1","nss-mymachines-32bit":"234-lp151.26.7.1","systemd-mini-container-mini":"234-lp151.26.7.1","systemd-mini-devel":"234-lp151.26.7.1","udev-mini":"234-lp151.26.7.1","nss-myhostname":"234-lp151.26.7.1","nss-systemd":"234-lp151.26.7.1","systemd-coredump":"234-lp151.26.7.1","libudev1":"234-lp151.26.7.1","systemd-container":"234-lp151.26.7.1","systemd-mini-sysvinit":"234-lp151.26.7.1","libudev-mini-devel":"234-lp151.26.7.1","libudev-mini1":"234-lp151.26.7.1","systemd-bash-completion":"234-lp151.26.7.1","systemd-devel":"234-lp151.26.7.1","systemd-logger":"234-lp151.26.7.1","libudev-devel-32bit":"234-lp151.26.7.1","libudev1-32bit":"234-lp151.26.7.1","udev":"234-lp151.26.7.1","libsystemd0-32bit":"234-lp151.26.7.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0208-1.json"}}],"schema_version":"1.7.5"}