Fedora has issued an advisory on September 7: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FHOIRL6XH5NYR3LYI3KP5DE4SDSQWR7W/ Mageia 8 and 9 are also affected.
Source RPM: (none) => erofs-utils-1.5-1.mga9.src.rpmWhiteboard: (none) => MGA9TOO, MGA8TOOCC: (none) => nicolas.salguero
Version : 1.6.3 "- Backport patches for CVE-2023-33551 and CVE-2023-33552." Thierry is the clear committer for this pkg, so assigning to you.
Status comment: (none) => Fixed in v1.6.3Assignee: bugsquad => thierry.vignaud
Removing Mageia 8 from whiteboard due to EOL!
Whiteboard: MGA9TOO, MGA8TOO => MGA9TOOCC: (none) => geiger.david68210
Done for both mga9 and Cauldron! Packages in9/Core/Updates_testing: ====================== erofs-fuse-1.7.1-1.mga9 erofs-utils-1.7.1-1.mga9 From SRPMS: erofs-utils-1.7.1-1.mga9.src.rpm
Assignee: thierry.vignaud => qa-bugsWhiteboard: MGA9TOO => (none)Version: Cauldron => 9
CVE: (none) => CVE-2023-33551, CVE-2023-33552
Keywords: (none) => advisory
M9: I'm only seeing v 1.5. What repository is it in?
CC: (none) => tablackwell
NOt appeared in core updates testing yet?
changed my mirror to Princeton. Installed 1.7.1 erofsfuse runs, but I don't have a Huawei phone or other erofs filesystem to test it on
From googling I get the idea that you don't need a phone to run the commands, but I cann't get my head around what the commands expact as source or destination. I find no simple example to follow.
CC: (none) => herman.viaene
RH mageia 9 x86_64 LC_ALL=C urpmi erofs-fuse erofs-utils https://mirror.math.princeton.edu/pub/mageia/distrib/9/x86_64/media/core/release/erofs-utils-1.5-1.mga9.x86_64.rpm https://mirror.math.princeton.edu/pub/mageia/distrib/9/x86_64/media/core/release/erofs-fuse-1.5-1.mga9.x86_64.rpm installing erofs-utils-1.5-1.mga9.x86_64.rpm erofs-fuse-1.5-1.mga9.x86_64.rpm from /var/cache/urpmi/rpms Preparing... ################################################################################################## 1/2: erofs-fuse ################################################################################################## 2/2: erofs-utils ################################################################################################## LC_ALL=C urpmi --auto --auto-update medium "QA Testing (32-bit)" is up-to-date medium "QA Testing (64-bit)" is up-to-date medium "Core Release (distrib1)" is up-to-date medium "Core Updates (distrib3)" is up-to-date medium "Nonfree Release (distrib11)" is up-to-date medium "Nonfree Updates (distrib13)" is up-to-date medium "Tainted Release (distrib21)" is up-to-date medium "Tainted Updates (distrib23)" is up-to-date medium "Core 32bit Release (distrib31)" is up-to-date medium "Core 32bit Updates (distrib32)" is up-to-date medium "Nonfree 32bit Release (distrib36)" is up-to-date medium "Tainted 32bit Release (distrib41)" is up-to-date medium "Tainted 32bit Updates (distrib42)" is up-to-date installing erofs-fuse-1.7.1-1.mga9.x86_64.rpm erofs-utils-1.7.1-1.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64 Preparing... ################################################################################################## 1/2: erofs-utils ################################################################################################## 2/2: erofs-fuse ################################################################################################## 1/2: removing erofs-utils-1.5-1.mga9.x86_64 ################################################################################################## 2/2: removing erofs-fuse-1.5-1.mga9.x86_64 ################################################################################################## Give OK in base a clean install LC_ALL=C urpme erofs-fuse erofs-utils removing erofs-fuse-1.7.1-1.mga9.x86_64 erofs-utils-1.7.1-1.mga9.x86_64 removing package erofs-fuse-1.7.1-1.mga9.x86_64 1/2: removing erofs-fuse-1.7.1-1.mga9.x86_64 ################################################################################################## removing package erofs-utils-1.7.1-1.mga9.x86_64 2/2: removing erofs-utils-1.7.1-1.mga9.x86_64 ################################################################################################## And uninstall
Whiteboard: (none) => MGA9-64-OKCC: (none) => andrewsfarm
Validating.
CC: (none) => sysadmin-bugsKeywords: (none) => validated_update
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0241.html
Status: NEW => RESOLVEDResolution: (none) => FIXED