[Buildroot] [PATCH 2/2] package/network-manager: Add upstream patch to fix CVE-2018-15688
Peter Korsgaard
peter at korsgaard.com
Wed Nov 14 09:35:04 UTC 2018
>>>>> "Bernd" == Bernd Kuhls <bernd.kuhls at t-online.de> writes:
> NetworkManager includes some parts of the systemd-networkd code in its
> codebase. That can be found at src/systemd/src/libsystemd-networkd.
> The DHCP implementation provided by systemd-networkd is used when
> NetworkManager is configured to use the internal implementation,
> however the default is to use dhclient.
> When NetworkManager is configured to use the internal dhcp and an
> interface is setup with ipv6.method=auto (which is the default value)
> or ipv6.method=dhcp, this flaw can be exploited. When using
> ipv6.method=auto, the DHCPv6 client can be automatically started with a
> Router Advertisement packet.
> Signed-off-by: Bernd Kuhls <bernd.kuhls at t-online.de>
Committed to 2018.02.x and 2018.08.x, thanks.
--
Bye, Peter Korsgaard
More information about the buildroot
mailing list