QID 750033

QID 750033: SUSE Enterprise Linux Security Update for libu2f-host (SUSE-SU-2021:1755-1)

This update for libu2f-host fixes the following issues: this update ships the u2f-host package (jsc#eco-3687 bsc#1184648) version 1.1.10 (released 2019-05-15) - add new devices to udev rules.
- fix a potentially uninitialized buffer (cve-2019-9578, bsc#1128140) version 1.1.9 (released 2019-03-06) - fix cid copying from the init response, which broke compatibility with some devices.
version 1.1.8 (released 2019-03-05) - add udev rules - drop 70-old-u2f.rules and use 70-u2f.rules for everything - use a random nonce for setting up cid to prevent fingerprinting - cve-2019-9578: parse the response to init in a more stable way to prevent leakage of uninitialized stack memory back to the device (bsc#1128140).
version 1.1.7 (released 2019-01-08) - fix for trusting length from device in device init.
- fix for buffer overflow when receiving data from device. (
Ysa-2019-01, cve-2018-20340, bsc#1124781) - add udev rules for some new devices.
- add udev rule for feitian epass fido - add a timeout to the register and authenticate actions.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Successful exploitation allows attacker to compromise the system.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Upgrade to the latest package which contains the patch. To install this SUSE Security, Update use YaST online_update. Alternatively you can run the command listed for your product. To install packages using the command line interface, use command "yum update". Refer to Suse security advisory: SUSE-SU-2021:1755-1 to address this issue and obtain further details.

    CVEs related to QID 750033

    Software Advisories
    Advisory ID Software Component Link
    SUSE-SU-2021:1755-1 SUSE Enterprise Linux URL Logo lists.suse.com/pipermail/sle-security-updates/2021-May/008817.html