Ubuntu has issued an advisory today (August 31): https://ubuntu.com/security/notices/USN-5057-1 Mageia 8 is also affected.
Status comment: (none) => Patch available from UbuntuWhiteboard: (none) => MGA8TOO
Fedora has issued an advisory for this on August 30: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/RAOZ4BKWAC4Y3U2K5MMW3S77HWWXHQDL/
A coincidence: another update for a parentless SRPM which you tv have largely maintained.
Assignee: bugsquad => thierry.vignaud
Debian has issued an advisory for this on September 4: https://www.debian.org/security/2021/dsa-4967
Ubuntu has issued an advisory today (September 15): https://ubuntu.com/security/notices/USN-5078-1 Mageia 8 is also affected.
Summary: squashfs-tools new security issue CVE-2021-40153 => squashfs-tools new security issues CVE-2021-40153 and CVE-2021-41072Status comment: Patch available from Ubuntu => Patches available from Ubuntu
fixed in mga9
CC: (none) => mageiaStatus comment: Patches available from Ubuntu => (none)Version: Cauldron => 8
fixed in mga8: src: - squashfs-tools-4.4-3.git1.1.mga8
Assignee: thierry.vignaud => qa-bugs
Whiteboard: MGA8TOO => (none)
Fedora has issued an advisory on September 24: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/RGPPMRX4FP3CLIZKZFB2DODGNHXHPYD6/ They fixed an additional security issue.
Assignee: qa-bugs => mageiaWhiteboard: (none) => MGA8TOOVersion: 8 => CauldronStatus comment: (none) => Patch available from Cauldron
Status comment: Patch available from Cauldron => Patch available from Fedora
Debian has issued an advisory for the newer issue today (October 15): https://www.debian.org/security/2021/dsa-4987
Ubuntu has issued an advisory for the newer issue on October 13: https://ubuntu.com/security/notices/USN-5078-3
(In reply to David Walser from comment #7) > Fedora has issued an advisory on September 24: > https://lists.fedoraproject.org/archives/list/package-announce@lists. > fedoraproject.org/thread/RGPPMRX4FP3CLIZKZFB2DODGNHXHPYD6/ > > They fixed an additional security issue. this is not the same version ( 4.4 VS 4.5 ) i think we need to validate this and then see with our squashfs-tools maintainer to have his agreement for an update to version 4.5.
Assignee: mageia => qa-bugsStatus comment: Patch available from Fedora => (none)
(In reply to Nicolas Lécureuil from comment #10) > (In reply to David Walser from comment #7) > > Fedora has issued an advisory on September 24: > > https://lists.fedoraproject.org/archives/list/package-announce@lists. > > fedoraproject.org/thread/RGPPMRX4FP3CLIZKZFB2DODGNHXHPYD6/ > > > > They fixed an additional security issue. > > this is not the same version ( 4.4 VS 4.5 ) > > i think we need to validate this and then see with our squashfs-tools > maintainer to have his agreement for an update to version 4.5. Then you need to make a new bug for it and not just pretend it never happened.
MGA8-64, Gnome Installed squashfs followed the guidance in: https://tldp.org/HOWTO/SquashFS-HOWTO/creatingandusing.html I was able to test this out and it does work as expected.
CC: (none) => brtians1Whiteboard: MGA8TOO => MGA8TOO MGA8-64-OK
(In reply to David Walser from comment #11) > (In reply to Nicolas Lécureuil from comment #10) > > (In reply to David Walser from comment #7) > > > Fedora has issued an advisory on September 24: > > > https://lists.fedoraproject.org/archives/list/package-announce@lists. > > > fedoraproject.org/thread/RGPPMRX4FP3CLIZKZFB2DODGNHXHPYD6/ > > > > > > They fixed an additional security issue. > > > > this is not the same version ( 4.4 VS 4.5 ) > > > > i think we need to validate this and then see with our squashfs-tools > > maintainer to have his agreement for an update to version 4.5. > > Then you need to make a new bug for it and not just pretend it never > happened. I'm confused. I've held off from validating for Mageia 8 because I don't see a "new bug" yet. Should i continue to wait, or go ahead with the validation? And what about Cauldron? Should this be made a Mageia 8 only bug now, since Comment 5 says it's "fixed" there?
CC: (none) => andrewsfarm
Assigning back to Nicolas so Comment 10 and Comment 11 can be addressed in some manner.
Assignee: qa-bugs => mageia
updating first in cauldron. Mga8 will follow.
New version pushed in mga8/9 src: - squashfs-tools-4.5-1.git5ae723.1.mga8
Whiteboard: MGA8TOO MGA8-64-OK => (none)Assignee: mageia => qa-bugs
Nicolas, you changed this to a Cauldron-only bug, and I freely admit that I've been ignoring it because I don't go anywhere near Cauldron at this stage. But, I decided to take a look today anyway, and I see Comment 16 shows a mga8 src. Did you miss changing the "Version" field to Mageia 8?
Version: Cauldron => 8
MGA8-64 Plasma on Lenovo B50 in Dutch. No installation issues. Followed guidance as Brian pointed ti in Comment 12, went OK with the remark that I hadd to use the "-noappend" option to write to a formatted USB-stick. As far as I am concerned, this update is good, provided TJ and Brian and Nicolas have sorted out their problems.
CC: (none) => herman.viaene
I had no problem with Brian's test. We just needed another on the new package. Giving this an OK and validating.
Whiteboard: (none) => MGA8-64-OKKeywords: (none) => validated_updateCC: (none) => sysadmin-bugs
Keywords: (none) => advisoryCC: (none) => davidwhodgins
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2022-0010.html
Resolution: (none) => FIXEDStatus: NEW => RESOLVED