[Buildroot] [PATCH 2/2] package/network-manager: Add upstream patch to fix CVE-2018-15688

Peter Korsgaard peter at korsgaard.com
Wed Nov 14 09:35:04 UTC 2018


>>>>> "Bernd" == Bernd Kuhls <bernd.kuhls at t-online.de> writes:

 > NetworkManager includes some parts of the systemd-networkd code in its
 > codebase. That can be found at src/systemd/src/libsystemd-networkd.
 > The DHCP implementation provided by systemd-networkd is used when
 > NetworkManager is configured to use the internal implementation,
 > however the default is to use dhclient.

 > When NetworkManager is configured to use the internal dhcp and an
 > interface is setup with ipv6.method=auto (which is the default value)
 > or ipv6.method=dhcp, this flaw can be exploited. When using
 > ipv6.method=auto, the DHCPv6 client can be automatically started with a
 > Router Advertisement packet.

 > Signed-off-by: Bernd Kuhls <bernd.kuhls at t-online.de>

Committed to 2018.02.x and 2018.08.x, thanks.

-- 
Bye, Peter Korsgaard


More information about the buildroot mailing list