Bug 30957

Summary: openssl new security issues CVE-2022-3358, CVE-2022-3602, and CVE-2022-3786
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Nicolas Salguero <nicolas.salguero>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal    
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: openssl-3.0.5-1.mga9.src.rpm CVE:
Status comment:

Description David Walser 2022-10-12 02:08:26 CEST
OpenSSL has issued an advisory today (October 11):
https://www.openssl.org/news/secadv/20221011.txt

The issue is fixed upstream in 3.0.6.

The update is committed in SVN for Cauldron, but has a test failure:
http://pkgsubmit.mageia.org/uploads/failure/cauldron/core/release/20221011211008.luigiwalser.duvel.3785240/log/openssl-3.0.6-1.mga9/build.aarch64.0.20221011215711.log
David Walser 2022-10-12 02:08:48 CEST

Status comment: (none) => Committed in SVN, has a test suite failure

Comment 1 Lewis Smith 2022-10-13 21:33:54 CEST
Assigning to NicolasS as you have several CVE updates to openssl to your credit.

Assignee: bugsquad => nicolas.salguero

Comment 2 David Walser 2022-10-26 18:45:11 CEST
3.0.7 will be released on November 1 with a critical security fix:
https://www.openwall.com/lists/oss-security/2022/10/25/4

It appears that 1.1.1 isn't affected.  Hopefully this will also fix the test suite.
Comment 3 David Walser 2022-11-01 17:43:07 CET
OpenSSL has issued an advisory today (November 1):
https://www.openssl.org/news/secadv/20221101.txt

The issues are fixed upstream in 3.0.7.

Status comment: Committed in SVN, has a test suite failure => Fixed upstream in 3.0.7
Summary: openssl new security issue CVE-2022-3358 => openssl new security issues CVE-2022-3358, CVE-2022-3602, and CVE-2022-3786

Comment 4 David Walser 2022-11-01 21:06:06 CET
The update is committed in SVN for Cauldron, but has a test failure:
http://pkgsubmit.mageia.org/uploads/failure/cauldron/core/release/20221101194220.luigiwalser.duvel.3503556/log/openssl-3.0.7-1.mga9/build.aarch64.0.20221101194314.log

Status comment: Fixed upstream in 3.0.7 => Committed in SVN, has a test suite failure

Comment 5 David Walser 2022-11-01 22:36:52 CET
Fixed for now by reverting to 3.0.5 and adding patches for the CVEs.  We should fix the failing test (or probably report it upstream) so we will be able to update it later.  We don't want to spend Mageia 9's whole lifetime patching it.

Resolution: (none) => FIXED
Status comment: Committed in SVN, has a test suite failure => (none)
Status: NEW => RESOLVED