Bug 33167 - freeglut new security issues CVE-2024-2425[89]
Summary: freeglut new security issues CVE-2024-2425[89]
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK, MGA9-32-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2024-05-02 09:17 CEST by Nicolas Salguero
Modified: 2024-05-09 04:41 CEST (History)
3 users (show)

See Also:
Source RPM: freeglut-3.4.0-1.mga9.src.rpm
CVE: CVE-2024-24258, CVE-2024-24259
Status comment:


Attachments

Description Nicolas Salguero 2024-05-02 09:17:54 CEST
RedHat has issued an advisory on April 30:
https://lwn.net/Articles/971670/

The fix is: https://github.com/freeglut/freeglut/commit/9ad320c1ad1a25558998ddfe47674511567fec57

Mageia 9 is also affected.
Nicolas Salguero 2024-05-02 09:18:11 CEST

CVE: (none) => CVE-2024-24258, CVE-2024-24259
Source RPM: (none) => freeglut-3.4.0-1.mga9.src.rpm
Whiteboard: (none) => MGA9TOO

Comment 1 Nicolas Salguero 2024-05-02 14:48:39 CEST
Suggested advisory:
========================

The updated packages fix security vulnerabilities:

freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function. (CVE-2024-24258)

freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function. (CVE-2024-24259)

References:
https://lwn.net/Articles/971670/
========================

Updated packages in core/updates_testing:
========================
lib(64)freeglut3-3.4.0-1.1.mga9
lib(64)freeglut-devel-3.4.0-1.1.mga9

from SRPM:
freeglut-3.4.0-1.1.mga9.src.rpm

Status: NEW => ASSIGNED
Version: Cauldron => 9
Whiteboard: MGA9TOO => (none)
Assignee: bugsquad => qa-bugs

PC LX 2024-05-02 18:01:47 CEST

CC: (none) => mageia

katnatek 2024-05-02 19:44:37 CEST

Keywords: (none) => advisory

Comment 2 katnatek 2024-05-04 05:39:10 CEST
RH mageia 9 x86_64

LC_ALL=C urpmi --auto --auto-update
medium "QA Testing (32-bit)" is up-to-date
medium "QA Testing (64-bit)" is up-to-date
medium "Core Release (distrib1)" is up-to-date
medium "Core Updates (distrib3)" is up-to-date
medium "Nonfree Release (distrib11)" is up-to-date
medium "Nonfree Updates (distrib13)" is up-to-date
medium "Tainted Release (distrib21)" is up-to-date
medium "Tainted Updates (distrib23)" is up-to-date
medium "Core 32bit Release (distrib31)" is up-to-date
medium "Core 32bit Updates (distrib32)" is up-to-date
medium "Nonfree 32bit Release (distrib36)" is up-to-date
medium "Tainted 32bit Release (distrib41)" is up-to-date
medium "Tainted 32bit Updates (distrib42)" is up-to-date


installing lib64freeglut3-3.4.0-1.1.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ##################################################################################################
      1/1: lib64freeglut3        ##################################################################################################
      1/1: removing lib64freeglut3-3.4.0-1.mga9.x86_64
                                 ##################################################################################################


urpmq --whatrequires-recursive lib64freeglut3 provides lots of files

Can't find evidence the lib is loaded using strace in glxinfo or smplayer
katnatek 2024-05-04 23:59:03 CEST

CC: (none) => andrewsfarm

katnatek 2024-05-04 23:59:32 CEST

Whiteboard: (none) => MGA9-64-OK, MGA9-32-OK

Comment 3 katnatek 2024-05-05 00:03:19 CEST
RH mageia 9 i586

Updated without issues
Of the applications reported to require libfreeglut3 all what I test works

smplayer
vlc
glxinfo 

As in 64bit test the library not gives evidence in strace

Nothing more to test by my part, feel free of remove the OK if necessary
Comment 4 Thomas Andrews 2024-05-05 02:21:23 CEST
I tried a couple of applications, and couldn't find a trace, either. 

Letting it go on a clean install that doesn't seem to break anything.

Validating.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 5 Mageia Robot 2024-05-09 04:41:50 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0165.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.