Security update for util-linux
This update for util-linux fixes a number of bugs and two security issues. The following security bugs were fixed: - CVE-2016-5011: Infinite loop DoS in libblkid while parsing DOS partition (bsc#988361) - CVE-2017-2616: In su with PAM support it was possible for local users to send SIGKILL to selected other processes with root privileges (bsc#1023041). The following non-security bugs were fixed: - bsc#1008965: Ensure that the option 'users,exec,dev,suid' work as expected on NFS mounts - bsc#1012504: Fix regressions in safe loop re-use patch set for libmount - bsc#1012632: Disable ro checks for mtab - bsc#1020077: fstrim: De-duplicate btrfs sub-volumes for 'fstrim -a' and bind mounts - bsc#947494: mount -a would fail to recognize btrfs already mounted, address loop re-use in libmount - bsc#966891: Conflict in meaning of losetup -L. This switch in SLE12 SP1 and SP2 continues to carry the meaning of --logical-blocksize instead of upstream --nooverlap - bsc#978993: cfdisk would mangle some text output - bsc#982331: libmount: ignore redundant slashes - bsc#983164: mount uid= and gid= would reject valid non UID/GID values - bsc#987176: When mounting a subfolder of a CIFS share, mount -a would show the mount as busy - bsc#1019332: lscpu: Implement WSL detection and work around crash
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for util-linux fixes a number of bugs and two security issues. The following security bugs were fixed: - CVE-2016-5011: Infinite loop DoS in libblkid while parsing DOS partition (bsc#988361) - CVE-2017-2616: In su with PAM support it was possible for local users to send SIGKILL to selected other processes with root privileges (bsc#1023041). The following non-security bugs were fixed: - bsc#1008965: Ensure that the option 'users,exec,dev,suid' work as expected on NFS mounts - bsc#1012504: Fix regressions in safe loop re-use patch set for libmount - bsc#1012632: Disable ro checks for mtab - bsc#1020077: fstrim: De-duplicate btrfs sub-volumes for 'fstrim -a' and bind mounts - bsc#947494: mount -a would fail to recognize btrfs already mounted, address loop re-use in libmount - bsc#966891: Conflict in meaning of losetup -L. This switch in SLE12 SP1 and SP2 continues to carry the meaning of --logical-blocksize instead of upstream --nooverlap - bsc#978993: cfdisk would mangle some text output - bsc#982331: libmount: ignore redundant slashes - bsc#983164: mount uid= and gid= would reject valid non UID/GID values - bsc#987176: When mounting a subfolder of a CIFS share, mount -a would show the mount as busy - bsc#1019332: lscpu: Implement WSL detection and work around crash
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1008965
- https://bugzilla.suse.com/1012504
- https://bugzilla.suse.com/1012632
- https://bugzilla.suse.com/1019332
- https://bugzilla.suse.com/1020077
- https://bugzilla.suse.com/1023041
- https://bugzilla.suse.com/947494
- https://bugzilla.suse.com/966891
- https://bugzilla.suse.com/978993
- https://bugzilla.suse.com/982331
- https://bugzilla.suse.com/983164
- https://bugzilla.suse.com/987176
- https://bugzilla.suse.com/988361
- https://www.suse.com/security/cve/CVE-2016-5011
- https://www.suse.com/security/cve/CVE-2017-2616
- https://www.suse.com/support/update/announcement/2017/suse-su-20170553-1/