• [SECURITY] [DSA 5055-1] util-linux security update

    From Salvatore Bonaccorso@21:1/5 to All on Mon Jan 24 12:40:02 2022
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-5055-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso January 24, 2022 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : util-linux
    CVE ID : CVE-2021-3995 CVE-2021-3996

    The Qualys Research Labs discovered two vulnerabilities in util-linux's libmount. These flaws allow an unprivileged user to unmount other users' filesystems that are either world-writable themselves or mounted in a world-writable directory (CVE-2021-3996), or to unmount FUSE filesystems
    that belong to certain other users (CVE-2021-3995).

    For the stable distribution (bullseye), these problems have been fixed in version 2.36.1-8+deb11u1.

    We recommend that you upgrade your util-linux packages.

    For the detailed security status of util-linux please refer to its
    security tracker page at: https://security-tracker.debian.org/tracker/util-linux

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org
    -----BEGIN PGP SIGNATURE-----

    iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmHujUNfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0TD/BAAmjdIgQgYI0Bc7fcp4tMNHOADXbn5cJysAee0P55kb863q5TM49DzbHuB Xh5Fh7+f4O/rDUXZoW/2hm43pbwDs8EH8LGYjTkspHraRkFEq7mLR6753SIVXHTP U/k9eShfgqRggCq7OTiALBXC00yMNn75PGsd5GPKEv2egSG34+bdp2RPnKc+R7cC yLkwuN6oNq0+KW08HzQp6FSYX7V+a8gsO2QWdlgAuXQC4ICCtYV1jtYn/GJ2SB6E E98nNIUBSR5sf8bXKDpPTrxvbAF1Y0719A7MwGnZS9bNVIBMlx0tNHSCddLrE6/F BMHSyvTQo+xLs5t+Esxb2rfsjuOlrbwte++8GR/LnVr/Zi/vVrzkccwneQlhHPzp Ok8fJ7ipEVbpBWyWdomsQXb8y7o8RFHr9P374JmCQE/urMaOHq1Lc7C9ctVJ5VHb 3+BV/FpMAvY6KekNqriSiX9aXXfWr4HQr7OO6rlz84/rC7wlVpYOx4TRaRGPQPyD STfa8W1shaMlxgL9zgmAtgCu4nNOR4BqVi5ZbuxY8sdbBM7tFD4DuD6sIhNAFadL pIpbvGte7FFHci4vQX/TEZVUGP0yqbNkvuScvT9k9ca/vytJ+9JZf4BUjGF/tO7C HS76o443AhdoYbCm7xtQHf2sm3eqPY6ULXTBZmLgVN3q6jWiyhQ=
    =lcvO
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)