Recommended update for firewalld and susefirewall2-to-firewalld

Announcement ID: SUSE-RU-2018:2675-1
Rating: moderate
References:
Affected Products:
  • Basesystem Module 15
  • Desktop Applications Module 15
  • SUSE Linux Enterprise Desktop 15
  • SUSE Linux Enterprise High Performance Computing 15
  • SUSE Linux Enterprise Server 15
  • SUSE Linux Enterprise Server for SAP Applications 15

An update that has five fixes can now be installed.

Description:

This update for firewalld and susefirewall2-to-firewalld fixes the following issues:

firewalld:

  • Drop global read permissions from the log file (bsc#1098986)
  • Add missing ipv6-icmp protocol to UI drop-down list (bsc#1099698)
  • Fix some untranslated strings in the creation of rich rules and firewall-config. (bsc#1096542)
  • fw: If failure occurs during startup set state to FAILED.
  • fw_direct: Avoid log for untracked passthrough queries.
  • Rich Rule Masquerade inverted source-destination in Forward Chain.
  • Don't forward interface to zone requests to NM for generated interfaces.
  • firewall-cmd, firewall-offline-cmd: Add --check-config option.
  • ipset: Check type when parsing ipset definition.
  • firewall-config: Add ipv6-icmp to the protocol dropdown box.
  • core/logger: Remove world-readable bit from logfile.
  • IPv6 rpfilter: Explicitly allow neighbor solicitation.

susefirewall2-to-firewalld:

  • Do not try to handle unknown iptables chains.
  • Handle source whitelisting. (bsc#1105157)

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • Basesystem Module 15
    zypper in -t patch SUSE-SLE-Module-Basesystem-15-2018-1861=1
  • Desktop Applications Module 15
    zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-2018-1861=1

Package List:

  • Basesystem Module 15 (noarch)
    • susefirewall2-to-firewalld-0.0.3-3.3.1
    • firewalld-lang-0.5.4-4.7.1
    • python3-firewall-0.5.4-4.7.1
    • firewall-macros-0.5.4-4.7.1
    • firewalld-0.5.4-4.7.1
  • Desktop Applications Module 15 (noarch)
    • firewall-applet-0.5.4-4.7.1
    • firewall-config-0.5.4-4.7.1

References: