Bug 25404 - systemd new security issue CVE-2019-15718
Summary: systemd new security issue CVE-2019-15718
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-32-OK, MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks: 23801
  Show dependency treegraph
 
Reported: 2019-09-04 02:08 CEST by David Walser
Modified: 2019-11-19 22:18 CET (History)
5 users (show)

See Also:
Source RPM: systemd-241-10.mga8.src.rpm
CVE:
Status comment: Fixed upstream in 243


Attachments

Description David Walser 2019-09-04 02:08:34 CEST
A security issue has been fixed upstream in systemd:
https://www.openwall.com/lists/oss-security/2019/09/03/1

Commits to fix the issue are linked in the message above.

Mageia 6 and Mageia 7 are also affected.
David Walser 2019-09-04 02:08:46 CEST

Blocks: (none) => 23801
Whiteboard: (none) => MGA7TOO, MGA6TOO

David Walser 2019-09-04 02:09:23 CEST

Status comment: (none) => Fixed upstream in 243

Marja Van Waes 2019-09-04 10:38:11 CEST

Assignee: bugsquad => basesystem
CC: (none) => mageia, marja11

Comment 1 David Walser 2019-11-12 20:00:12 CET
RedHat has issued an advisory for this on November 5:
https://access.redhat.com/errata/RHSA-2019:3592
Comment 2 Thomas Backlund 2019-11-13 11:59:22 CET
This and a lot of other fixes in:

SRPM:
systemd-241-8.4.mga7.src.rpm

i586:
libsystemd0-241-8.4.mga7.i586.rpm
libudev1-241-8.4.mga7.i586.rpm
libudev-devel-241-8.4.mga7.i586.rpm
nss-myhostname-241-8.4.mga7.i586.rpm
systemd-241-8.4.mga7.i586.rpm
systemd-devel-241-8.4.mga7.i586.rpm
systemd-tests-241-8.4.mga7.i586.rpm
systemd-units-241-8.4.mga7.i586.rpm

x86_64:
lib64systemd0-241-8.4.mga7.x86_64.rpm
lib64udev1-241-8.4.mga7.x86_64.rpm
lib64udev-devel-241-8.4.mga7.x86_64.rpm
nss-myhostname-241-8.4.mga7.x86_64.rpm
systemd-241-8.4.mga7.x86_64.rpm
systemd-devel-241-8.4.mga7.x86_64.rpm
systemd-tests-241-8.4.mga7.x86_64.rpm
systemd-units-241-8.4.mga7.x86_64.rpm

Assignee: basesystem => qa-bugs
Version: Cauldron => 7
CC: (none) => tmb
Whiteboard: MGA7TOO, MGA6TOO => (none)

Comment 3 Thomas Andrews 2019-11-17 01:18:55 CET
Dell Inspiron 5100, 32-bit P4, 2GB RAM, Radeon RV200 graphics, old Atheros wifi, 32-bit Xfce system, using the desktop kernel.

The following 5 packages are going to be installed:

- libsystemd0-241-8.4.mga7.i586
- libudev1-241-8.4.mga7.i586
- nss-myhostname-241-8.4.mga7.i586
- systemd-241-8.4.mga7.i586
- systemd-units-241-8.4.mga7.i586

All packages installed cleanly. As expected, I was told to reboot. After reboot, everything seems to be working as it should.

Going to call this OK for 32-bit.

CC: (none) => andrewsfarm
Whiteboard: (none) => MGA7-32-OK

Comment 4 Thomas Andrews 2019-11-17 01:29:23 CET
Dell Dimension e520, Core 2 Quad Q6600, 4GB RAM, Intel graphics, Realtek usb wifi dongle, 64-bit Plasma system.

The following 5 packages are going to be installed:

- lib64systemd0-241-8.4.mga7.x86_64
- lib64udev1-241-8.4.mga7.x86_64
- nss-myhostname-241-8.4.mga7.x86_64
- systemd-241-8.4.mga7.x86_64
- systemd-units-241-8.4.mga7.x86_64

All packages installed cleanly. Reboot seemed to take a long time, but I believe this is due to other, unrelated factors. The 32-bit boot of Comment 3 was not extra-long.

After reboot, everything seems to be working as it should.

I believe this is OK for 64-bits, but will do another test on other hardware to confirm because of the long reboot.
Comment 5 Thomas Andrews 2019-11-17 02:12:13 CET
i5 2500 (Sandy Lake), 16GB RAM, Intel graphics, wired Internet, 64-bit Plasma system.

The following 7 packages are going to be installed:

- lib64systemd0-241-8.4.mga7.x86_64
- lib64udev-devel-241-8.4.mga7.x86_64
- lib64udev1-241-8.4.mga7.x86_64
- nss-myhostname-241-8.4.mga7.x86_64
- systemd-241-8.4.mga7.x86_64
- systemd-devel-241-8.4.mga7.x86_64
- systemd-units-241-8.4.mga7.x86_64

All packages installed cleanly. Reboot was of normal duration. After reboot, no regressions noted.

Forgot to mention before, all of the above tests were done with kernel 5.3.11-1, now in updates-testing awaiting validation.

Since the entire system depends on systemd, these tests should be adequate. Giving this a 64-bit OK, and Validating.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs
Whiteboard: MGA7-32-OK => MGA7-32-OK, MGA7-64-OK

Thomas Backlund 2019-11-19 18:29:27 CET

Keywords: (none) => advisory

Comment 6 Mageia Robot 2019-11-19 22:18:52 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2019-0330.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.