Bug 31418 - sdl2 new security issue CVE-2022-4743
Summary: sdl2 new security issue CVE-2022-4743
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-01-17 22:36 CET by David Walser
Modified: 2023-01-24 09:00 CET (History)
5 users (show)

See Also:
Source RPM: sdl2-2.0.14-1.1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2023-01-17 22:36:55 CET
openSUSE has issued an advisory on January 11:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XPXXPXNP65LT4SYPF33U23FQUNEGMGWW/

The issue is fixed upstream in 2.26.0.
David Walser 2023-01-17 22:37:08 CET

Status comment: (none) => Fixed upstream in 2.26.0

Comment 1 David GEIGER 2023-01-18 17:05:22 CET
Done for mga8!

CC: (none) => geiger.david68210

Comment 2 David Walser 2023-01-18 21:00:19 CET
libsdl2.0_0-2.0.14-1.2.mga8
libsdl2.0-devel-2.0.14-1.2.mga8
libsdl2.0-static-devel-2.0.14-1.2.mga8
sdl2-docs-2.0.14-1.2.mga8

from sdl2-2.0.14-1.2.mga8.src.rpm

Assignee: rverschelde => qa-bugs
Status comment: Fixed upstream in 2.26.0 => (none)

Comment 3 Herman Viaene 2023-01-21 11:04:54 CET
MGA8-64 MATE on Acer Aspire 5253
No installation issues.
Looking for something I can grasp in previous updates, Len had a test with loopwave.c but according bug 24497 Comment 12 this needed "some editing", so I gave up on that.
Then
# urpmq --whatrequires lib64sdl2.0_0
produced a loooooong list, I picked blobby, blobwars an dreamchess, installed and ran these under strace, and they all worked and showed access to the library.
So good enough for me.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA8-64-OK

Comment 4 Thomas Andrews 2023-01-21 14:02:35 CET
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2023-01-24 01:24:52 CET

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 5 Mageia Robot 2023-01-24 09:00:43 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0020.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.