Update to 1.9.23 — security hardening: - Use O_EXCL with sem_open to prevent semaphore pre-planting attacks - Fix OOB memory access in safein()/safeout() on socket errors - Reject command socket connections from different user namespaces - Use O_NOFOLLOW for PID file to prevent symlink attacks - Open random device with O_CLOEXEC, restrict semaphore to 0600 - Fix stale semaphore recovery after SIGKILL - Fix compilation when NO_COMMAND_MODE is defined
Please log in to add feedback.
This update has been submitted for testing by jhladky.
This update's test gating status has been changed to 'ignored'.
This update has been pushed to testing.
This update has been obsoleted by haveged-1.9.23-2.fc43.