Bug 32558 - libqb new security issue CVE-2023-39976
Summary: libqb new security issue CVE-2023-39976
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-11-24 12:30 CET by Nicolas Salguero
Modified: 2023-12-04 22:38 CET (History)
3 users (show)

See Also:
Source RPM: libqb-2.0.6-1.mga9.src.rpm
CVE: CVE-2023-39976
Status comment: Fixed upstream in 2.0.8


Attachments

Description Nicolas Salguero 2023-11-24 12:30:33 CET
Redhat has issued an advisory for that CVE:
https://lwn.net/Articles/952259/

The problem is fixed in version 2.0.8 so Cauldron is not affected and Mageia 8 is not affected too because the vulnerable code was introduced later.
Nicolas Salguero 2023-11-24 12:31:29 CET

Source RPM: (none) => libqb-2.0.6-1.mga9.src.rpm
Status comment: (none) => Fixed upstream in 2.0.8

Comment 1 Lewis Smith 2023-11-24 21:21:00 CET
The main pkg is lib64qb100.
Cauldron already has v2.0.8
This was put up by DavidG, so can we ask you to the M9 bit? (+ advisory).

Assignee: bugsquad => geiger.david68210

Comment 2 David GEIGER 2023-12-02 16:50:59 CET
Assigning to QA,


Package in 9/Core/Updates_testing:
=====================
libqb-devel-2.0.8-1.mga9
lib64qb-devel-2.0.8-1.mga9
doxygen2man-2.0.8-1.mga9
libqb100-2.0.8-1.mga9
lib64qb100-2.0.8-1.mga9


From SRPMS:
libqb-2.0.8-1.mga9.src.rpm

Assignee: geiger.david68210 => qa-bugs

Comment 3 Marja Van Waes 2023-12-02 18:04:42 CET
Advisory with the SRPM from comment 2 added to SVN. Please remove the "advisory" keyword if it needs to be changed. It also helps when obsolete advisories are tagged as "obsolete"

CC: (none) => marja11
Keywords: (none) => advisory
CVE: (none) => CVE-2023-39976

Comment 4 Thomas Andrews 2023-12-04 01:39:53 CET
MGA9-64 Plasma in VirtualBox: No installation issues over the old packages.

No previous updates for doxygen2man. One for libqb, bug 25751, which, apparently after some discussion at a QA meeting, was validated on a clean install. Looking on the Web at doxygen2man, it appears that application is also in developer territory, beyond the scope of QA. So...

Giving this an OK and validating, based on the clean install.

Keywords: (none) => validated_update
Whiteboard: (none) => MGA9-64-OK
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 5 Mageia Robot 2023-12-04 22:38:56 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0339.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.