Bug 30413

Summary: blender new security issues CVE-2022-054[4-6]
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: All Packagers <pkg-bugs>
Status: RESOLVED OLD QA Contact: Sec team <security>
Severity: critical    
Priority: Normal CC: geiger.david68210, nicolas.salguero
Version: 8   
Target Milestone: ---   
Hardware: All   
OS: Linux   
See Also: https://bugs.mageia.org/show_bug.cgi?id=30366
Whiteboard:
Source RPM: blender-2.83.10-3.1.mga8.src.rpm CVE:
Status comment: Patches available from Debian and Fedora

Description David Walser 2022-05-11 20:18:11 CEST
Fedora has issued an advisory today (May 11):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/GIZADV3AHTWZ2YKEFTVLNK3K4F4KTYLM/

I'm not sure if Mageia 8 is affected.
David Walser 2022-05-11 20:19:03 CEST

Status comment: (none) => Patch available from Fedora
See Also: (none) => https://bugs.mageia.org/show_bug.cgi?id=30366

Comment 1 Lewis Smith 2022-05-11 21:43:45 CEST
Blender is nominally with daviddavid, but has been dealt with by other people for nearly a year, so assigning this globally.

CC: (none) => geiger.david68210
Assignee: bugsquad => pkg-bugs

Comment 2 David Walser 2022-06-30 00:29:41 CEST
Debian-LTS has issued an advisory on June 28:
https://www.debian.org/lts/security/2022/dla-3060

It fixes two new CVEs (fixed upstream in 2.83.19) and the one Fedora fixed (fixed upstream, but possibly not in the 2.83.x branch).

Summary: blender new security issue CVE-2022-0546 => blender new security issues CVE-2022-054[4-6]
Whiteboard: (none) => MGA8TOO
Status comment: Patch available from Fedora => Patches available from Debian and Fedora

Comment 3 David Walser 2022-07-05 14:50:49 CEST
Debian has issued an advisory for this on July 4:
https://www.debian.org/security/2022/dsa-5176
Comment 4 David GEIGER 2023-06-27 03:01:30 CEST
On cauldron we have the 3.3.6 release so it should be fixed!
David Walser 2023-06-27 14:10:45 CEST

Version: Cauldron => 8
Whiteboard: MGA8TOO => (none)
Source RPM: blender-2.93.7-2.mga9.src.rpm => blender-2.83.10-3.1.mga8.src.rpm

Comment 5 Nicolas Salguero 2024-01-12 09:51:21 CET
Mageia 8 EOL

CC: (none) => nicolas.salguero
Status: NEW => RESOLVED
Resolution: (none) => OLD