• Bug#1066965: bookworm-pu: package newlib/3.3.0-2

    From Petter Reinholdtsen@21:1/5 to All on Sat Mar 16 09:10:01 2024
    XPost: linux.debian.devel.release

    Package: release.debian.org

    The <URL: https://tracker.debian.org/pkg/newlib > package got an open
    security problem with malloc and friends in stable and oldstable, see
    <URL: https://bugs.debian.org/984446 > for the CVE issue. The package
    is orphaned.

    I would like to fix the bug at least in stable, and propose the
    following upload. The change is already in the git repo on salsa in the debian/bookworm branch. The problem is already fixed in unstable and
    testing with a new version of the upstream code. The fix to stable is
    only the minimal patch to solve the issue.

    I propose to use the version number 3.3.0-2, but am open to better
    proposals. The version in testing is 4.4.0.20231231-2.

    Complete proposed patch is below:

    diff --git a/debian/changelog b/debian/changelog
    index b3e3ef851..1c8ddc5cb 100644
    --- a/debian/changelog
    +++ b/debian/changelog
    @@ -1,3 +1,12 @@
    +newlib (3.3.0-2) bookworm; urgency=medium
    +
    + * QA upload.
    + * Orphan package to reflect status in Unstable.
    + * Added mallocr-CVE-2021-3420.patch to solve incorrect overflow
    + check in malloc and friends.
    +
    + -- Petter Reinholdtsen <pere@debian.org> Sat, 16 Mar 2024 08:53:41 +0100
    +
    newlib (3.3.0-1.3) unstable; urgency=medium

    * Non-maintainer upload.
    diff --git a/debian/control b/debian/control
    index ff12d0bc5..4daa4e559 100644
    --- a/debian/control
    +++ b/debian/control
    @@ -1,7 +1,7 @@
    Source: newlib
    Section: devel
    Priority: optional
    -Maintainer: Agustin Henze <tin@debian.org>
    +Maintainer: Debian QA Group <packages@qa.debian.org>
    Build-Depends:
    debhelper (>= 9),
    texinfo,
    diff --git a/debian/gbp.conf b/debian/gbp.conf
    index f4a0824a9..04f21b160 100644
    --- a/debian/gbp.conf
    +++ b/debian/gbp.conf
    @@ -1,6 +1,7 @@
    [DEFAULT]
    pristine-tar = True
    merge = True
    +debian-branch = debian/bookworm
  • From Salvatore Bonaccorso@21:1/5 to Petter Reinholdtsen on Wed Mar 20 21:00:02 2024
    XPost: linux.debian.devel.release

    Hi

    [disclaimer, not an authoritative answer as not part of the stable
    release managers]

    On Sat, Mar 16, 2024 at 09:09:05AM +0100, Petter Reinholdtsen wrote:

    Package: release.debian.org

    The <URL: https://tracker.debian.org/pkg/newlib > package got an open security problem with malloc and friends in stable and oldstable, see
    <URL: https://bugs.debian.org/984446 > for the CVE issue. The package
    is orphaned.

    I would like to fix the bug at least in stable, and propose the
    following upload. The change is already in the git repo on salsa in the debian/bookworm branch. The problem is already fixed in unstable and
    testing with a new version of the upstream code. The fix to stable is
    only the minimal patch to solve the issue.

    I propose to use the version number 3.3.0-2, but am open to better
    proposals. The version in testing is 4.4.0.20231231-2.

    Usually you would choose for this update 3.3.0-1.3+deb12u1, but given
    3.3.0-2 was never present in unstable and the version later moved on,
    this is in theory possible.


    Complete proposed patch is below:

    diff --git a/debian/changelog b/debian/changelog
    index b3e3ef851..1c8ddc5cb 100644
    --- a/debian/changelog
    +++ b/debian/changelog
    @@ -1,3 +1,12 @@
    +newlib (3.3.0-2) bookworm; urgency=medium
    +
    + * QA upload.
    + * Orphan package to reflect status in Unstable.
    + * Added mallocr-CVE-2021-3420.patch to solve incorrect overflow
    + check in malloc and friends.

    I would add as well the bug closer for #984446.

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Petter Reinholdtsen@21:1/5 to All on Wed Mar 20 21:20:01 2024
    XPost: linux.debian.devel.release

    [Salvatore Bonaccorso]
    Usually you would choose for this update 3.3.0-1.3+deb12u1, but given
    3.3.0-2 was never present in unstable and the version later moved on,
    this is in theory possible.

    That reasoning is the same as mine. I also wanted to drop the NMU
    version number part, to make it more obvoius that this is not a NMU.

    I would add as well the bug closer for #984446.

    Good point. git updated.

    --
    Happy hacking
    Petter Reinholdtsen

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Petter Reinholdtsen@21:1/5 to All on Sat Apr 6 09:52:21 2024
    XPost: linux.debian.devel.release

    Btw, what is the timeline for approval or rejection for this security
    upload proposal?
    --
    Happy hacking
    Petter Reinholdtsen

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)