Bug 23400

Summary: lxc new security issue CVE-2018-6556
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Bruno Cornec <bruno>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: major    
Priority: Normal CC: bruno, cjw, joequant, marja11, pterjan, thierry.vignaud
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: lxc-2.0.9-1.mga7.src.rpm CVE:
Status comment:

Description David Walser 2018-08-06 21:50:12 CEST
Ubuntu has issued an advisory today (August 6):
https://usn.ubuntu.com/3730-1/

The issue was introduced in 2.0.9, so Mageia 6 is not affected.

Much more details including patches on the Launchpad bug:
https://bugs.launchpad.net/ubuntu/%2Bsource/lxc/%2Bbug/1783591
Comment 1 Marja Van Waes 2018-08-07 07:36:15 CEST
Assigning to all packagers collectively, since there is no registered maintainer for this package.

CC'ing some committers.

Assignee: bugsquad => pkg-bugs
CC: (none) => cjw, joequant, marja11, pterjan, thierry.vignaud

Comment 2 Bruno Cornec 2018-10-26 01:20:23 CEST
lxc-2.0.9-3.mga7 on its way to cauldron with fixes mentionned in the Ubuntu BR applied, with an additional fix to make it complie + fixes on bash-completion not handled correctly anymore

CC: (none) => bruno
Status: NEW => ASSIGNED
Assignee: pkg-bugs => qa-bugs

Comment 3 David Walser 2018-10-26 01:27:02 CEST
QA doesn't handle Cauldron updates, so just mark this as FIXED when it actually builds.

Assignee: qa-bugs => bruno

Comment 4 Bruno Cornec 2018-10-26 03:01:14 CEST
lxc-2.0.9-3.mga7 now uploaded

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED