Fedora alert FEDORA-2025-ba86bed822 (systemd)
From: | updates--- via package-announce <package-announce@lists.fedoraproject.org> | |
To: | package-announce@lists.fedoraproject.org | |
Subject: | [SECURITY] Fedora 41 Update: systemd-256.15-1.fc41 | |
Date: | Tue, 03 Jun 2025 01:27:30 +0000 | |
Message-ID: | <20250603012730.C215B2051020@bastion01.iad2.fedoraproject.org> | |
Archive-link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-ba86bed822 2025-06-03 01:26:45.079792+00:00 -------------------------------------------------------------------------------- Name : systemd Product : Fedora 41 Version : 256.15 Release : 1.fc41 URL : https://systemd.io Summary : System and Service Manager Description : systemd is a system and service manager that runs as PID 1 and starts the rest of the system. It provides aggressive parallelization capabilities, uses socket and D-Bus activation for starting services, offers on-demand starting of daemons, keeps track of processes using Linux control groups, maintains mount and automount points, and implements an elaborate transactional dependency-based service control logic. systemd supports SysV and LSB init scripts and works as a replacement for sysvinit. Other parts of this package are a logging daemon, utilities to control basic system configuration like the hostname, date, locale, maintain a list of logged-in users, system accounts, runtime directories and settings, and a logging daemons. This package was built from the v256-stable branch of systemd. -------------------------------------------------------------------------------- Update Information: Fix for local information disclosure in systemd-coredump (CVE-2025-4598) Various other fixes -------------------------------------------------------------------------------- ChangeLog: * Thu May 29 2025 Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> - 256.15-1 - Version 257.6 - Fix for local information disclosure in systemd-coredump (CVE-2025-4598) - Various other fixes * Thu May 15 2025 Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> - 256.13-1 - Version 256.13 - Various small fixes in multiple components -------------------------------------------------------------------------------- References: [ 1 ] Bug #2369245 - CVE-2025-4598 systemd: race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2369245 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-ba86bed822' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------
Attachment: None (type=text/plain)
-- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue