Hi, CVE-2022-33065 was announced here: https://lwn.net/Articles/949598/ Mageia 8 and 9 are also affected. Best regards, Nico.
Whiteboard: (none) => MGA9TOO, MGA8TOOCC: (none) => nicolas.salgueroStatus comment: (none) => Patches available from openSUSESource RPM: (none) => libsndfile-1.2.0-2.mga9.src.rpm
Attention: This bug was raised quoting: libsndfile-1.2.0-2.mga9.src.rpm but I see it has recently been updated to v.1.2.2 (so I updated the SRPM field). The new version might already incorporate the openSUSE patch cited. This may help, from https://bugzilla.suse.com/show_bug.cgi?id=1213451: "The fix provided in the upstream commit https://github.com/libsndfile/libsndfile/commit/0754562e13d2e63a248a1c82f90b30bc0ffe307c I backported to TW (together with the version update to 1.2.2)" Assigning to DavidG who did our version update.
Source RPM: libsndfile-1.2.0-2.mga9.src.rpm => libsndfile-1.2.2-1.mga9.src.rpmAssignee: bugsquad => geiger.david68210
Assigning to QA, Packages in 9/Core/Updates_testing: ====================== libsndfile-devel-1.2.0-3.1.mga9 lib64sndfile-devel-1.2.0-3.1.mga9 libsndfile-progs-1.2.0-3.1.mga9 libsndfile1-1.2.0-3.1.mga9 lib64sndfile1-1.2.0-3.1.mga9 Packages in 8/Core/Updates_testing: ====================== libsndfile-progs-1.0.31-1.3.mga8 libsndfile-devel-1.0.31-1.3.mga8 lib64sndfile-devel-1.0.31-1.3.mga8 libsndfile1-1.0.31-1.3.mga8 lib64sndfile1-1.0.31-1.3.mga8 From SRPMS: libsndfile-1.2.0-3.1.mga9.src.rpm libsndfile-1.0.31-1.3.mga8.src.rpm
Version: Cauldron => 9Assignee: geiger.david68210 => qa-bugsWhiteboard: MGA9TOO, MGA8TOO => MGA8TOO
CC: (none) => mageia
(In reply to Lewis Smith from comment #1) > Attention: This bug was raised quoting: > libsndfile-1.2.0-2.mga9.src.rpm > but I see it has recently been updated to v.1.2.2 (so I updated the SRPM > field). That was only in cauldron, Mageia 9 did not get v. 1.2.2
CC: (none) => marja11Source RPM: libsndfile-1.2.2-1.mga9.src.rpm => libsndfile-1.2.0-2.mga9
Advisory based on comment 2 and the changelog mail added to SVN. Please remove the "advisory" keyword if it needs to be changed. It also helps when obsolete advisories are tagged as "obsolete"
Keywords: (none) => advisory
mga8 x86_64 Pre-update: could not find a usable PoC. Updated the three packages: lib64sndfile-devel-1.0.31-1.3.mga8.x86_64.rpm lib64sndfile1-1.0.31-1.3.mga8.x86_64.rpm libsndfile-progs-1.0.31-1.3.mga8.x86_64.rpm Exercised the libraries by using $ sndfile-info Semiramis.wav======================================== File : Semiramis.wav Length : 82362380 RIFF : 82362372 WAVE fmt : 16 Format : 0x1 => WAVE_FORMAT_PCM Channels : 2 Sample Rate : 44100 Block Align : 4 Bit Width : 16 Bytes/sec : 176400 data : 82362336 End ---------------------------------------- Sample Rate : 44100 Frames : 20590584 Channels : 2 Format : 0x00010002 Sections : 1 Seekable : TRUE Duration : 00:07:46.907 Signal Max : 22236 (-3.37 dB) $ sndfile-play Semiramis.wav Playing Semiramis.wav using PulseAudioVolumeControl.
CC: (none) => tarazed25Whiteboard: MGA8TOO => MGA8TOO MGA8-64-OK
Mageia9, x86_64 Starting with version 1.2.0-2, which works. $ sndfile-info Non_più_andrai.mp4 Error : Not able to open input file Non_più_andrai.mp4. File : Non_più_andrai.mp4 Length : 18419514 $ sndfile-info 'Long as I Can See the Light.wav' ======================================== File : Long as I Can See the Light.wav Length : 18419604 RIFF : 18419596 ............. $ sndfile-play 'Long as I Can See the Light.wav' Playing Long as I Can See the Light.wav $ sndfile-play MatthewLocke.flac Playing MatthewLocke.flac Updated the packages. $ sndfile-info IGotYouBabe_ChrissieHynde.ogg ======================================== File : IGotYouBabe_ChrissieHynde.ogg Length : 4039295 Ogg stream data : Vorbis Stream serialno : 1632469135 Vorbis library version : Xiph.Org libVorbis 1.3.7 Bitstream is 2 channel, 44100 Hz Encoded by : Xiph.Org libVorbis I 20070622 PCM offset : 0 PCM end : 8382528 Metadata : Title : I Got You Babe (feat. Chrissie Hynde) Artist : UB40 ................. $ sndfile-play MatthewLocke.flac Playing MatthewLocke.flac $ sndfile-play LaDansereye-TielmanSusato.wav Playing LaDansereye-TielmanSusato.wav Looks OK.
Whiteboard: MGA8TOO MGA8-64-OK => MGA8TOO MGA8-64-OK MGA9-64-OK
Validating.
Keywords: (none) => validated_updateCC: (none) => andrewsfarm, sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2023-0310.html
Resolution: (none) => FIXEDStatus: NEW => RESOLVED