Bug 30670 - libgsasl new security issue CVE-2022-2469
Summary: libgsasl new security issue CVE-2022-2469
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-07-25 17:25 CEST by David Walser
Modified: 2022-08-25 23:22 CEST (History)
5 users (show)

See Also:
Source RPM: libgsasl-1.8.1-2.mga8.src.rpm
CVE: CVE-2022-2469
Status comment:


Attachments

Description David Walser 2022-07-25 17:25:09 CEST
Debian has issued an advisory on July 24:
https://www.debian.org/security/2022/dsa-5189

The issue is fixed upstream in 2.0.1.

Mageia 8 is also affected.
David Walser 2022-07-25 17:25:19 CEST

Status comment: (none) => Fixed upstream in 2.0.1
Whiteboard: (none) => MGA8TOO

Comment 1 Lewis Smith 2022-07-26 08:24:52 CEST
Assigning this update globally since 'libgsasl' is a pkg seldom touched, and with no particular associated packager.

Assignee: bugsquad => pkg-bugs

Comment 2 Nicolas Salguero 2022-08-22 16:32:28 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client. (CVE-2022-2469)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2469
https://www.debian.org/security/2022/dsa-5189
========================

Updated packages in core/updates_testing:
========================
lib(64)gsasl7-1.8.1-2.1.mga8
lib(64)gsasl-devel-1.8.1-2.1.mga8
libgsasl-1.8.1-2.1.mga8

from SRPM:
libgsasl-1.8.1-2.1.mga8.src.rpm

Version: Cauldron => 8
Whiteboard: MGA8TOO => (none)
CVE: (none) => CVE-2022-2469
Assignee: pkg-bugs => qa-bugs
CC: (none) => nicolas.salguero
Status: NEW => ASSIGNED
Source RPM: libgsasl-1.10.0-2.mga9.src.rpm => libgsasl-1.8.1-2.mga8.src.rpm
Status comment: Fixed upstream in 2.0.1 => (none)

Comment 3 Herman Viaene 2022-08-24 10:03:56 CEST
MGA8-64 Plasma o, Acer Aspire 5253
No installation issues, no previous updates.
# urpmq --whatrequires libgsasl
libgsasl
[root@mach7 ~]# urpmq --whatrequires lib64gsasl7
lib64gsasl-devel
lib64gsasl-devel
lib64gsasl7
lib64infinity0.7_0
lib64jreen-qt5_1
lib64jreen1
lib64vmime0
pokerth
pokerth-server
So installed and lauched pokerth and pushe some buttons in the game.
$ strace -o libgsasl.txt pokerth 
found ref. in trace file:
openat(AT_FDCWD, "/lib64/libgsasl.so.7", O_RDONLY|O_CLOEXEC) = 3
That'a as far as I go.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA8-64-OK

Comment 4 Thomas Andrews 2022-08-24 13:30:42 CEST
Validating. Advisory in Comment 2.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2022-08-24 23:12:46 CEST

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 5 Mageia Robot 2022-08-25 23:22:54 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0298.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.