Bug 1465610

Summary: resolved: an out-of-bounds write
Product: [Fedora] Fedora Reporter: Zbigniew Jędrzejewski-Szmek <zbyszek>
Component: systemdAssignee: systemd-maint
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 24CC: alick9188, awilliam, dkholia, johannbg, lnykryn, msekleta, muadda, ssahani, s, systemd-maint, zbyszek
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: AcceptedFreezeException
Fixed In Version: systemd-233-6.fc26 systemd-231-17.fc25 systemd-229-22.fc24 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-06-29 23:29:03 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1349189, 1463609    

Description Zbigniew Jędrzejewski-Szmek 2017-06-27 18:18:40 UTC
Description of problem:
CVE-2017-9445

Comment 1 Fedora Update System 2017-06-28 00:18:25 UTC
systemd-233-6.fc26 has been submitted as an update to Fedora 26. https://bodhi.fedoraproject.org/updates/FEDORA-2017-956e27bdd6

Comment 2 Fedora Update System 2017-06-28 00:18:36 UTC
systemd-231-17.fc25 has been submitted as an update to Fedora 25. https://bodhi.fedoraproject.org/updates/FEDORA-2017-29d909f5ec

Comment 3 Fedora Update System 2017-06-28 00:18:43 UTC
systemd-229-22.fc24 has been submitted as an update to Fedora 24. https://bodhi.fedoraproject.org/updates/FEDORA-2017-72f0c1ea9c

Comment 4 Zbigniew Jędrzejewski-Szmek 2017-06-28 00:19:05 UTC
https://github.com/systemd/systemd/pull/6214

Comment 5 Fedora Blocker Bugs Application 2017-06-28 00:24:54 UTC
Proposed as a Freeze Exception for 26-final by Fedora user zbyszek using the blocker tracking app because:

 It is a fix for a security vulnerability which would put the installed system at risk before updates are applied. It only applies when systemd-resolved is used (which is not the default), but some custom configuration do use it, and I would prefer the official image not to contain the vulnerability.

Comment 6 Zbigniew Jędrzejewski-Szmek 2017-06-28 13:02:22 UTC
*** Bug 1465728 has been marked as a duplicate of this bug. ***

Comment 7 Fedora Update System 2017-06-28 19:20:37 UTC
systemd-233-6.fc26 has been pushed to the Fedora 26 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-956e27bdd6

Comment 8 Fedora Update System 2017-06-28 21:51:22 UTC
systemd-229-22.fc24 has been pushed to the Fedora 24 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-72f0c1ea9c

Comment 9 Fedora Update System 2017-06-28 21:53:14 UTC
systemd-231-17.fc25 has been pushed to the Fedora 25 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-29d909f5ec

Comment 10 Adam Williamson 2017-06-29 19:35:00 UTC
Discussed at 2017-06-29 freeze exception review meeting: https://meetbot-raw.fedoraproject.org/fedora-blocker-review/2017-06-29/f26-blocker-review.2017-06-29-16.00.html . Accepted as a freeze exception as a significant security vulnerability. Note, we will be checking to ensure the update *only* fixes the security vulnerability, as we're not inclined to accept other changes to systemd this late in the game.

Comment 11 Fedora Update System 2017-06-29 23:29:03 UTC
systemd-233-6.fc26 has been pushed to the Fedora 26 stable repository. If problems still persist, please make note of it in this bug report.

Comment 12 Fedora Update System 2017-06-30 00:49:55 UTC
systemd-231-17.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.

Comment 13 Fedora Update System 2017-07-03 02:19:10 UTC
systemd-229-22.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.