Bug 30907 - rust new security issues CVE-2022-3611[34] and CVE-2022-46176
Summary: rust new security issues CVE-2022-3611[34] and CVE-2022-46176
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: High major
Target Milestone: ---
Assignee: Rémi Verschelde
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
: 31393 (view as bug list)
Depends on:
Blocks: 32394
  Show dependency treegraph
 
Reported: 2022-09-28 19:53 CEST by David Walser
Modified: 2024-01-12 10:27 CET (History)
2 users (show)

See Also:
Source RPM: rust-1.60.0-1.mga8
CVE:
Status comment: Fixed upstream in 1.66.1


Attachments

Description David Walser 2022-09-28 19:53:27 CEST
SUSE has issued an advisory today (September 28):
https://lists.suse.com/pipermail/sle-security-updates/2022-September/012440.html

The issues are fixed upstream in 1.64.0:
https://github.com/rust-lang/cargo/security/advisories/GHSA-2hvr-h6gw-qrxp
https://github.com/rust-lang/cargo/security/advisories/GHSA-rfj2-q3h3-hm5j

Mageia 8 is also affected.
David Walser 2022-09-28 19:53:36 CEST

Status comment: (none) => Fixed upstream in 1.64.0
Whiteboard: (none) => MGA8TOO

Comment 2 Rémi Verschelde 2022-09-28 21:49:12 CEST
Cauldron already has 1.64.0.

Version: Cauldron => 8
Source RPM: rust-1.63.0-1.mga9.src.rpm => rust-1.60.0-1.mga8
Whiteboard: MGA8TOO => (none)

Comment 3 David Walser 2023-01-18 00:31:48 CET
Fedora has issued an advisory on January 13:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/FVEI4CC7IBADIPB4HSLIYEX2LBAP5TC3/

The issue is fixed upstream in 1.66.1:
https://github.com/rust-lang/cargo/security/advisories/GHSA-r5w3-xm58-jv6j

Mageia 8 is also affected.

Whiteboard: (none) => MGA8TOO
Version: 8 => Cauldron
Status comment: Fixed upstream in 1.64.0 => Fixed upstream in 1.66.1
Severity: normal => major

David Walser 2023-01-18 00:32:32 CET

Summary: rust new security issues CVE-2022-3611[34] => rust new security issues CVE-2022-3611[34] and CVE-2022-46176

Comment 4 David Walser 2023-01-18 01:03:06 CET
*** Bug 31393 has been marked as a duplicate of this bug. ***

CC: (none) => nicolas.salguero

Comment 5 David Walser 2023-01-18 01:03:32 CET
(In reply to David Walser from comment #3)
> Fedora has issued an advisory on January 13:
> https://lists.fedoraproject.org/archives/list/package-announce@lists.
> fedoraproject.org/thread/FVEI4CC7IBADIPB4HSLIYEX2LBAP5TC3/
> 
> The issue is fixed upstream in 1.66.1:
> https://github.com/rust-lang/cargo/security/advisories/GHSA-r5w3-xm58-jv6j
> 
> Mageia 8 is also affected.

Another reference:
https://www.openwall.com/lists/oss-security/2023/01/10/3
Comment 6 Rémi Verschelde 2023-01-18 10:32:15 CET
Pushed rust-1.66.1-mga9 to Cauldron.

Now for Mageia 8, it's a bit trickier. We currently have rust 1.60.0 there.

CVE-2022-3611[34] seem fairly trivial to backport, but CVE-2022-46176 is much more complex and requires updating a bunch of vendored crates. I don't trust it would apply _at all_ on anything else than 1.66.0.

Patches in https://github.com/rust-lang/wg-security-response/tree/main/patches

So either we leave it unfixed (seems to be the Debian strategy), or we have to do the full update to 1.66.1 in Mageia 8 (which means building successively 1.61, 1.62, 1.63, 1.64, 1.65 and then 1.66.1, hoping that it plays well with the packages we have in Mageia 8... it's a lot of work).

Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8

Comment 7 David Walser 2023-01-25 16:43:00 CET
SUSE fixed CVE-2022-46176 for rust 1.65.  I don't know if that helps:
https://lists.suse.com/pipermail/sle-security-updates/2023-January/013517.html
Comment 8 David Walser 2023-05-19 21:05:29 CEST
If we update rust, we need to rebuild cargo-c with the updated rust:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/OLQEJPETSSBCHSDHX4JDMLCD2MMBG5SR/
Morgan Leijström 2023-11-11 01:01:12 CET

Blocks: (none) => 32394

Comment 9 Morgan Leijström 2023-11-11 01:05:25 CET
Badly needed for Firefox, which is EOL, security risk!
 Bug 32394 - Backport Firefox 115 for Mageia 8

If we decide to not fix this, that also means not updating Firefox,
which mean we do have to tell users officially to get new Firefox from upstream or as Flatpak.

(Unless there is another way to get mga8 package Firefox updated)

CC: (none) => fri
Priority: Normal => High

Comment 10 Rémi Verschelde 2023-11-11 02:08:35 CET
I don't have time to work on it, updating rust in Mageia 8 all the way to 1.66.0 would take a lot of time and effort, and backporting the patches would similarly be difficult.

Mageia 8 EOL can't arrive soon enough...
Comment 11 Nicolas Salguero 2024-01-12 10:27:37 CET
Mageia 8 EOL

Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.