- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202305-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: systemd: Multiple Vulnerabilities Date: May 03, 2023 Bugs: #880547, #830967 ID: 202305-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in systemd, the worst of which could result in denial of service. Background ========== A system and service manager. Affected packages ================= ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- Traceback (most recent call last): File "/usr/local/lib/python3.9/site-packages/glsamaker/models/glsa.py", line 326, in generate_mail_table return self._generate_mail_table() File "/usr/local/lib/python3.9/site-packages/glsamaker/models/glsa.py", line 297, in _generate_mail_table vuln.range_types_rev[vuln.pkg_range], vuln.version KeyError: None Description =========== Multiple vulnerabilities have been discovered in systemd. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All systemd users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=sys-apps/systemd-251.3" All systemd-utils users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=sys-apps/systemd-utils-251.3" Gentoo has discontinued support for sys-apps/systemd-tmpfiles, sys- boot/systemd-boot, and sys-fs/udev. See the 2022-04-19-systemd-utils news item. Users should unmerge it in favor of sys-apps/systemd-utils on non-systemd systems: # emerge --ask --depclean --verbose "sys-apps/systemd-tmpfiles" "sys-boot/systemd-boot" "sys-fs/udev" # emerge --ask --verbose --oneshot ">=sys-apps/systemd-utils-251.3" References ========== [ 1 ] CVE-2021-3997 https://nvd.nist.gov/vuln/detail/CVE-2021-3997 [ 2 ] CVE-2022-3821 https://nvd.nist.gov/vuln/detail/CVE-2022-3821 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202305-15 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2023 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5