Bug 30715 - zlib new security issue CVE-2022-37434
Summary: zlib new security issue CVE-2022-37434
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-08-06 15:24 CEST by David Walser
Modified: 2022-09-16 21:41 CEST (History)
6 users (show)

See Also:
Source RPM: zlib-1.2.12-1.1.mga8.src.rpm
CVE: CVE-2022-37434
Status comment:


Attachments

Description David Walser 2022-08-06 15:24:13 CEST
A security issue fixed upstream in zlib has been announced on August 5:
https://www.cve.org/CVERecord?id=CVE-2022-37434

Mageia 8 is also affected.
David Walser 2022-08-06 15:24:31 CEST

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Patch available from upstream

Comment 1 Lewis Smith 2022-08-06 21:01:41 CEST
This SRPM has had different maintainers, so assigning the update globally.
CC'ing tmb & NicolasS who have dealt with it recently, and might want to do this update.

Assignee: bugsquad => pkg-bugs
CC: (none) => nicolas.salguero, tmb

Comment 2 Nicolas Lécureuil 2022-08-08 14:36:48 CEST
fixed in mga8/9

src:
    - zlib-1.2.12-1.2.mga8

CC: (none) => mageia
Version: Cauldron => 8
Status comment: Patch available from upstream => (none)
Assignee: pkg-bugs => qa-bugs
Whiteboard: MGA8TOO => (none)

Comment 3 David Walser 2022-08-08 15:54:28 CEST
libzlib-devel-1.2.12-1.2.mga8
libzlib-static-devel-1.2.12-1.2.mga8
libzlib1-1.2.12-1.2.mga8
libminizip1-1.2.12-1.2.mga8
libminizip-devel-1.2.12-1.2.mga8

from zlib-1.2.12-1.2.mga8.src.rpm
Comment 4 David Walser 2022-08-09 16:48:06 CEST
See here:
https://www.openwall.com/lists/oss-security/2022/08/09/1

A second commit needs to be added to fix a regression.

Keywords: (none) => feedback

Comment 5 David Walser 2022-08-18 17:06:46 CEST
Ubuntu has issued an advisory for this on August 17:
https://ubuntu.com/security/notices/USN-5570-1

Assignee: qa-bugs => mageia
Keywords: feedback => (none)

Comment 6 David Walser 2022-08-26 17:16:31 CEST
Debian has issued an advisory for this on August 25:
https://www.debian.org/security/2022/dsa-5218

Status comment: (none) => Second patch needs to be added to fix regression

Comment 7 Nicolas Salguero 2022-08-29 13:29:42 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference). (CVE-2022-37434)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37434
https://www.openwall.com/lists/oss-security/2022/08/09/1
https://ubuntu.com/security/notices/USN-5570-1
https://www.debian.org/security/2022/dsa-5218
========================

Updated packages in core/updates_testing:
========================
lib(64)minizip1-1.2.12-1.3.mga8
lib(64)minizip-devel-1.2.12-1.3.mga8
lib(64)zlib1-1.2.12-1.3.mga8
lib(64)zlib-devel-1.2.12-1.3.mga8
lib(64)zlib-static-devel-1.2.12-1.3.mga8

from SRPM:
zlib-1.2.12-1.3.mga8.src.rpm

CVE: (none) => CVE-2022-37434
Assignee: mageia => qa-bugs
Status comment: Second patch needs to be added to fix regression => (none)
Source RPM: zlib-1.2.12-2.mga9.src.rpm => zlib-1.2.12-1.1.mga8.src.rpm
Status: NEW => ASSIGNED

Comment 8 David Walser 2022-09-02 18:43:43 CEST
Fedora has issued an advisory for this today (September 2):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/JWN4VE3JQR4O2SOUS5TXNLANRPMHWV4I/
Comment 9 Thomas Andrews 2022-09-13 14:12:00 CEST
MGA8-64 Plasma. No installation issues.

Repeated the test from https://bugs.mageia.org/show_bug.cgi?id=30204#c7 except with different object files, with the same results.

Validating. Advisory in Comment 7.

Keywords: (none) => validated_update
Whiteboard: (none) => MGA8-64-OK
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2022-09-16 19:54:21 CEST

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 10 Mageia Robot 2022-09-16 21:41:30 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0328.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.