<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/meta-el-common.git/recipes-core/systemd, branch pyro</title>
<subtitle>Commmon distro layer for Enea Linux</subtitle>
<id>https://git.enea.com/cgit/linux/meta-el-common.git/atom?h=pyro</id>
<link rel='self' href='https://git.enea.com/cgit/linux/meta-el-common.git/atom?h=pyro'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/'/>
<updated>2018-10-26T13:22:22+00:00</updated>
<entry>
<title>systemd: fix CVE-2017-15908</title>
<updated>2018-10-26T13:22:22+00:00</updated>
<author>
<name>Dan Andresan</name>
<email>Dan.Andresan@enea.com</email>
</author>
<published>2018-10-26T13:18:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/commit/?id=7cfe300faae3259f59ff3e5eaf3c2c743b4cd374'/>
<id>urn:sha1:7cfe300faae3259f59ff3e5eaf3c2c743b4cd374</id>
<content type='text'>
systemd in the upstream pyro is 232

CVE: CVE-2017-15908

Reference:
https://github.com/systemd/systemd/commit/9f939335a07085aa9a9663efd1dca06ef6405d62

Change-Id: Ifb3c138b324fe943c8a80e646c06731420d69ec0
Signed-off-by: Andreas Wellving &lt;andreas.wellving@enea.com&gt;
Signed-off-by: Adrian Mangeac &lt;adrian.mangeac@enea.com&gt;
</content>
</entry>
<entry>
<title>systemd: Drop duplicat CVE patches</title>
<updated>2017-11-24T14:06:10+00:00</updated>
<author>
<name>Adrian Dudau</name>
<email>adrian.dudau@enea.com</email>
</author>
<published>2017-11-23T13:28:34+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/commit/?id=7fded7d7d61ab65530ec0bfd0a168d4a8afb322c'/>
<id>urn:sha1:7fded7d7d61ab65530ec0bfd0a168d4a8afb322c</id>
<content type='text'>
This patch has already been applied in upstream poky/pyro.

Signed-off-by: Adrian Dudau &lt;adrian.dudau@enea.com&gt;
</content>
</entry>
<entry>
<title>systemd: CVE-2017-1000082</title>
<updated>2017-10-04T07:58:01+00:00</updated>
<author>
<name>Sona Sarmadi</name>
<email>sona.sarmadi@enea.com</email>
</author>
<published>2017-10-03T08:55:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/commit/?id=d8a0f5de3d13e8747376af9e7fd2b5007ffb8aab'/>
<id>urn:sha1:d8a0f5de3d13e8747376af9e7fd2b5007ffb8aab</id>
<content type='text'>
refuse to load units with errors

If a unit has a statement such as User=0day where the username exists but is
strictly speaking invalid, the unit will be started as the root user instead.

Backport a patch from upstream to mitigate this by refusing to start units such
as this.

(From OE-Core rev: a6eaef0f179a341c0b96bb30aaec2d80862a11d6)

Reference:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000082

Backport from: http://git.yoctoproject.org/cgit/cgit.cgi/poky/commit/?h=pyro&amp;id=b7e7b5e294f944c27fb1d2be61c0cf38f6c81ba8

Signed-off-by: Ross Burton &lt;ross.burton@intel.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
Signed-off-by: Sona Sarmadi &lt;sona.sarmadi@enea.com&gt;
Signed-off-by: Adrian Dudau &lt;adrian.dudau@enea.com&gt;
</content>
</entry>
<entry>
<title>systemd: CVE-2017-9445</title>
<updated>2017-09-26T13:37:50+00:00</updated>
<author>
<name>Sona Sarmadi</name>
<email>sona.sarmadi@enea.com</email>
</author>
<published>2017-09-22T09:39:48+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-el-common.git/commit/?id=fc56bc51ea79b613d64b0389bf7b4877d3e45cbb'/>
<id>urn:sha1:fc56bc51ea79b613d64b0389bf7b4877d3e45cbb</id>
<content type='text'>
Out-of-bounds write in systemd-resolved due to allocating too
small buffer in dns_packet_new

References:
https://bugzilla.redhat.com/attachment.cgi?id=1290017
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9445

Signed-off-by: Sona Sarmadi &lt;sona.sarmadi@enea.com&gt;
Signed-off-by: Adrian Dudau &lt;adrian.dudau@enea.com&gt;
</content>
</entry>
</feed>
