openSUSE has issued an advisory on April 1: https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/4FBRFLGSEHNFULMPARVADU2TACHDQM4L/ Upstream fix: https://github.com/upx/upx/commit/e0b6ff192412f5bb5364c1948f4f6b27a0cd5ea2
CVE: (none) => CVE-2025-2849Status comment: (none) => Patch available from upstream and openSUSEWhiteboard: (none) => MGA9TOOSource RPM: (none) => upx-5.0.0-2.mga10.src.rpm, upx-4.2.3-1.mga9.src.rpm
Suggested advisory: ======================== The updated package fixes a security vulnerability: UPX p_lx_elf.cpp un_DT_INIT heap-based overflow. (CVE-2025-2849) References: https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/4FBRFLGSEHNFULMPARVADU2TACHDQM4L/ ======================== Updated package in core/updates_testing: ======================== upx-4.2.3-1.1.mga9 from SRPM: upx-4.2.3-1.1.mga9.src.rpm
Whiteboard: MGA9TOO => (none)Version: Cauldron => 9Assignee: bugsquad => qa-bugsStatus comment: Patch available from upstream and openSUSE => (none)Status: NEW => ASSIGNEDSource RPM: upx-5.0.0-2.mga10.src.rpm, upx-4.2.3-1.mga9.src.rpm => upx-4.2.3-1.mga9.src.rpm
Keywords: (none) => advisory
RH x86_64 installing upx-4.2.3-1.1.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64 Preparing... ################################################################################################## 1/1: upx Reference bug#33069 comment#3 cp /bin/filezilla ./ ll -h filezilla -rwxr-xr-x 1 root root 4.1M abr 2 11:50 filezilla* upx -k -9 -o filezilla2 filezilla Ultimate Packer for eXecutables Copyright (C) 1996 - 2024 UPX 4.2.3 Markus Oberhumer, Laszlo Molnar & John Reiser Mar 27th 2024 File size Ratio Format Name -------------------- ------ ----------- ----------- 4212136 -> 1323860 31.43% linux/amd64 filezilla2 Packed 1 file. ll -h filezilla* -rwxr-xr-x 1 root root 4.1M abr 2 11:50 filezilla* -rwxr-xr-x 1 root root 1.3M abr 2 11:50 filezilla2* ./filezilla2 works as the regular file
Whiteboard: (none) => MGA9-64-OKCC: (none) => andrewsfarm
Validating.
CC: (none) => sysadmin-bugsKeywords: (none) => validated_update
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2025-0122.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED