Bug 23400 - lxc new security issue CVE-2018-6556
Summary: lxc new security issue CVE-2018-6556
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Bruno Cornec
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-08-06 21:50 CEST by David Walser
Modified: 2018-10-26 03:01 CEST (History)
6 users (show)

See Also:
Source RPM: lxc-2.0.9-1.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2018-08-06 21:50:12 CEST
Ubuntu has issued an advisory today (August 6):
https://usn.ubuntu.com/3730-1/

The issue was introduced in 2.0.9, so Mageia 6 is not affected.

Much more details including patches on the Launchpad bug:
https://bugs.launchpad.net/ubuntu/%2Bsource/lxc/%2Bbug/1783591
Comment 1 Marja Van Waes 2018-08-07 07:36:15 CEST
Assigning to all packagers collectively, since there is no registered maintainer for this package.

CC'ing some committers.

Assignee: bugsquad => pkg-bugs
CC: (none) => cjw, joequant, marja11, pterjan, thierry.vignaud

Comment 2 Bruno Cornec 2018-10-26 01:20:23 CEST
lxc-2.0.9-3.mga7 on its way to cauldron with fixes mentionned in the Ubuntu BR applied, with an additional fix to make it complie + fixes on bash-completion not handled correctly anymore

CC: (none) => bruno
Status: NEW => ASSIGNED
Assignee: pkg-bugs => qa-bugs

Comment 3 David Walser 2018-10-26 01:27:02 CEST
QA doesn't handle Cauldron updates, so just mark this as FIXED when it actually builds.

Assignee: qa-bugs => bruno

Comment 4 Bruno Cornec 2018-10-26 03:01:14 CEST
lxc-2.0.9-3.mga7 now uploaded

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.