[Bug 1795921] Re: Out-of-Bounds write in systemd-networkd dhcpv6 option handling

2018-12-18 Thread Sebastien Bacher
** Changed in: systemd (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1795921 Title: Out-of-Bounds write in systemd-networkd dhcpv6 option handling

[Bug 1795921] Re: Out-of-Bounds write in systemd-networkd dhcpv6 option handling

2018-12-06 Thread Launchpad Bug Tracker
** Merge proposal linked: https://code.launchpad.net/~kzapalowicz/snappy-hwe-snaps/+git/network-manager/+merge/360284 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1795921 Title: Out-of-Bounds w

[Bug 1795921] Re: Out-of-Bounds write in systemd-networkd dhcpv6 option handling

2018-11-05 Thread Alex Murray
@yassine-mrabet - In general, Ubuntu does not upgrade major versions of software and instead backports security fixes to the current version - also we track CVEs independently in our own CVE tracker - in this case please see https://people.canonical.com/~ubuntu- security/cve/2018/CVE-2018-15688.htm

[Bug 1795921] Re: Out-of-Bounds write in systemd-networkd dhcpv6 option handling

2018-11-05 Thread yassine-mrabet
Hi, There is still no updates available on bionic : according to security.gentoo.org affected versions < 'systemd-239', while candidate in bionic-updates is '237-3ubuntu10.3'. Is there any manual method to fix it, while waiting for the updated version ? Source: https://security.gentoo.org/glsa/20

[Bug 1795921] Re: Out-of-Bounds write in systemd-networkd dhcpv6 option handling

2018-10-31 Thread Clemens Fuchslocher
Zbyszek: Thank you for your clarification! Dimitri: You are right, on my Ubuntu 16.04 server installations the systemd-networkd service is disabled and the dhclient from the isc-dhcp- client package is used for the DHCP part: $ systemctl status systemd-networkd.service systemd-networkd.service

Re: [Bug 1795921] Re: Out-of-Bounds write in systemd-networkd dhcpv6 option handling

2018-10-31 Thread Dimitri John Ledkov
Hi, On Tue, 30 Oct 2018 at 20:31, Clemens Fuchslocher wrote: > > Are there any workarounds for Ubuntu 16.04? By default, networkd is not used on 16.04; unless one manually opted into it, or uses particular SKUs/images that choose to use networkd by default (e.g. Core images, and some cloud image

Re: [Bug 1795921] Re: Out-of-Bounds write in systemd-networkd dhcpv6 option handling

2018-10-31 Thread zbyszek
On Tue, Oct 30, 2018 at 08:16:27PM -, Clemens Fuchslocher wrote: > Are there any workarounds for Ubuntu 16.04? > > Can I set /proc/sys/net/ipv6/conf/all/accept_ra to 0 to ignore the > Router Advertisements? There are two settings: the accept_ra sysctl in the kernel, and IPv6AcceptRa= in syste

[Bug 1795921] Re: Out-of-Bounds write in systemd-networkd dhcpv6 option handling

2018-10-30 Thread Clemens Fuchslocher
Are there any workarounds for Ubuntu 16.04? Can I set /proc/sys/net/ipv6/conf/all/accept_ra to 0 to ignore the Router Advertisements? https://www.kernel.org/doc/Documentation/networking/ip-sysctl.txt Does this prevent the described security problem? -- You received this bug notification becaus

[Bug 1795921] Re: Out-of-Bounds write in systemd-networkd dhcpv6 option handling

2018-10-26 Thread Mathew Hodson
** Changed in: systemd (Ubuntu) Importance: Undecided => Medium -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1795921 Title: Out-of-Bounds write in systemd-networkd dhcpv6 option handling To man

[Bug 1795921] Re: Out-of-Bounds write in systemd-networkd dhcpv6 option handling

2018-10-25 Thread Seth Arnold
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1795921 Title: Out-of-Bounds write in systemd-networkd dhcpv6 option handling To m