Fedora has issued an advisory on June 6: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/ZSLYZOW4ASQ5GSHLIUW7HXHFCBZ2ADUQ/ Mageia 5 is also affected. libtirpc hasn't been fixed yet in Fedora, and the vulnerable code appears to be there in the get_reply: section of clnt_dg_call() in src/clnt_dg.c Fedora added this patch in glibc: http://pkgs.fedoraproject.org/cgit/rpms/glibc.git/plain/glibc-rh1337140.patch?h=f23&id=2d5168f40a40a16c331909945969a6baaf715b9c They also added two bugfix patches in the same update.
Whiteboard: (none) => MGA5TOO
glibc already fixed in cauldron since: Name : glibc Relocations: (not relocatable) Version : 2.22 Vendor: Mageia.Org Release : 18.mga6 Build Date: Mon 30 May 2016 03:24:53 PM CEST tmb <tmb> 6:2.22-18.mga6: + Revision: 1019403 - CVE-2016-4429: sunrpc: Do not use alloca in clntudp_call [BZ#20112]
Version: Cauldron => 5Whiteboard: MGA5TOO => (none)
Thanks. Marking Cauldron for now as libtirpc has not yet been fixed.
Version: 5 => CauldronWhiteboard: (none) => MGA5TOO
libtirpc-1.0.1-4.mga6 uploaded for Cauldron with the fix.
Updated packages built this morning: glibc-2.20-23.mga5 glibc-devel-2.20-23.mga5 glibc-static-devel-2.20-23.mga5 glibc-profile-2.20-23.mga5 nscd-2.20-23.mga5 glibc-utils-2.20-23.mga5 glibc-i18ndata-2.20-23.mga5 glibc-doc-2.20-23.mga5 libtirpc-0.2.5-3.1.mga5 libtirpc1-0.2.5-3.1.mga5 libtirpc-devel-0.2.5-3.1.mga5 from SRPMS: glibc-2.20-23.mga5.src.rpm libtirpc-0.2.5-3.1.mga5.src.rpm
Assigning to QA, rpm list in comment 4 I have this glibc update already running on mageia infra and on several of my own live servers (x86_64 arch) Will try to write advisory tomorrow
Assignee: tmb => qa-bugs
Running these packages fine with no issues on multiple Mageia 5 systems, both architectures.
Whiteboard: (none) => MGA5-32-OK MGA5-64-OK
Validating so this can ship with the kernel update.
Keywords: (none) => validated_updateCC: (none) => sysadmin-bugs
advisory added to svn
CC: (none) => tmbWhiteboard: MGA5-32-OK MGA5-64-OK => MGA5-32-OK MGA5-64-OK advisory
An update for this issue has been pushed to the Mageia Updates repository. http://advisories.mageia.org/MGASA-2016-0270.html
Status: NEW => RESOLVEDResolution: (none) => FIXED