QID 751324

Date Published: 2021-11-10

QID 751324: SUSE Enterprise Linux Security Update for systemd (SUSE-SU-2021:3611-1)

This update for systemd fixes the following issues: - machine-id-setup: generate machine-id from dmi product id on amazon ec2 - add timestamp to d-bus events to improve traceability. (
Jsc#sle-21894) - busctl: add a timestamp to the output of the busctl monitor command (bsc#1180225, jsc#sle-21894) - sysctl: configure kernel parameters in the order they occur in each sysctl configuration files (bsc#1191399) - basic/unit-name: do not use strdupa() on a path (bsc#1188063, cve-2021-33910) - logind: terminate cleanly on sigterm/sigint (bsc#1188018) - units: make fsck/grows/makefs/makeswap units conflict against shutdown.target - make sure the versions of both udev and systemd packages are always the same (bsc#1189480) - avoid the error message when udev is updated due to udev being already active when the sockets are started again (bsc#1188291) - allow systemd sysusers config files to be overriden during system installation (bsc#1171962)

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Successful exploitation allows attacker to compromise the system.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 4.9 severity.
  • Solution
    Upgrade to the latest package which contains the patch. To install this SUSE Security, Update use YaST online_update. Alternatively you can run the command listed for your product. To install packages using the command line interface, use command "yum update". Refer to Suse security advisory: SUSE-SU-2021:3611-1 to address this issue and obtain further details.

    CVEs related to QID 751324

    Software Advisories
    Advisory ID Software Component Link
    SUSE-SU-2021:3611-1 SUSE Enterprise Linux URL Logo lists.suse.com/pipermail/sle-security-updates/2021-November/009695.html