Summary: | <sys-apps/systemd-239-r2: Out-of-bounds heap write in systemd-networkd dhcpv6 option handling (CVE-2018-15688) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Matthew Thode ( prometheanfire ) <prometheanfire> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | alexander, systemd |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://nvd.nist.gov/vuln/detail/CVE-2018-15688 | ||
See Also: | https://github.com/systemd/systemd/pull/10518 | ||
Whiteboard: | A2 [glsa+ cve] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 669664 | ||
Bug Blocks: | 670040 |
Description
Matthew Thode ( prometheanfire )
2018-10-26 23:09:02 UTC
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=9189edf61c8e135c0cd28be3534d7624cafff239 commit 9189edf61c8e135c0cd28be3534d7624cafff239 Author: Mike Gilbert <floppym@gentoo.org> AuthorDate: 2018-10-28 22:53:46 +0000 Commit: Mike Gilbert <floppym@gentoo.org> CommitDate: 2018-10-28 23:21:05 +0000 sys-apps/systemd: backport several patches for 239 Closes: https://bugs.gentoo.org/662776 Bug: https://bugs.gentoo.org/669664 Bug: https://bugs.gentoo.org/669716 Package-Manager: Portage-2.3.51_p2, Repoman-2.3.11_p27 Signed-off-by: Mike Gilbert <floppym@gentoo.org> sys-apps/systemd/Manifest | 1 + sys-apps/systemd/systemd-239-r2.ebuild | 448 +++++++++++++++++++++++++++++++++ 2 files changed, 449 insertions(+) Added to an existing GLSA request. This issue was resolved and addressed in GLSA 201810-10 at https://security.gentoo.org/glsa/201810-10 by GLSA coordinator Thomas Deutschmann (whissi). Freeing CVE alias for tracker usage. |