The following Fedora EPEL 9 Security updates need testing:
Age URL
2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-a0fcd69d86 chromium-120.0.6099.71-1.el9
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-7a05e8decc rdiff-backup-2.2.6-3.el9
The following builds have been pushed to Fedora EPEL 9 updates-testing
composer-2.6.6-1.el9
datovka-4.23.1-1.el9
php-nikic-php-parser4-4.18.0-1.el9
python-damo-2.1.0-1.el9
python-opensearch-py-2.4.2-2.el9
python-pathspec-0.12.1-1.el9
rpkg-1.66-14.el9
tmt-1.30.0-1.el9
Details about builds:
================================================================================
composer-2.6.6-1.el9 (FEDORA-EPEL-2023-2a9d3dbbda)
Dependency Manager for PHP
--------------------------------------------------------------------------------
Update Information:
**Version 2.6.6** - 2023-12-08 * Fixed symfony/console requirement to
exclude 7.x as Composer 2.6 is not compatible, 2.7 will be (#11741) * Fixed
libpq parsing to use the global constant if available (#11684) * Fixed error
output when updating with a temporary constraint fails (#11692)
--------------------------------------------------------------------------------
ChangeLog:
* Sat Dec 9 2023 Remi Collet <remi(a)remirepo.net> - 2.6.6-1
- update to 2.6.6
--------------------------------------------------------------------------------
================================================================================
datovka-4.23.1-1.el9 (FEDORA-EPEL-2023-d18666b6dd)
A free graphical interface for Czech Databox (Datov�� schr��nky)
--------------------------------------------------------------------------------
Update Information:
This is new version of datovka.
--------------------------------------------------------------------------------
ChangeLog:
* Mon Dec 11 2023 Jaroslav ��karvada <jskarvad(a)redhat.com> - 4.23.1-1
- New version
Resolves: rhbz#2253431
* Mon Dec 4 2023 Jaroslav ��karvada <jskarvad(a)redhat.com> - 4.23.0-1
- New version
Resolves: rhbz#2251951
* Thu Nov 9 2023 Jaroslav ��karvada <jskarvad(a)redhat.com> - 4.22.1-5
- Rebuilt for new datovka
* Tue Nov 7 2023 Jaroslav ��karvada <jskarvad(a)redhat.com> - 4.22.1-4
- Rebuild for new libdatovka
* Tue Sep 5 2023 Jaroslav ��karvada <jskarvad(a)redhat.com> - 4.22.1-3
- Rebuild for new libdatovka
* Wed Jul 19 2023 Fedora Release Engineering <releng(a)fedoraproject.org> - 4.22.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Wed Apr 26 2023 Jaroslav ��karvada <jskarvad(a)redhat.com> - 4.22.1-1
- New version
Resolves: rhbz#2188035
* Thu Feb 23 2023 Jaroslav ��karvada <jskarvad(a)redhat.com> - 4.22.0-1
- New version
Resolves: rhbz#2170063
* Thu Jan 19 2023 Fedora Release Engineering <releng(a)fedoraproject.org> - 4.21.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Tue Nov 22 2022 Jaroslav ��karvada <jskarvad(a)redhat.com> - 4.21.1-1
- New version
Resolves: rhbz#2144857
* Thu Sep 29 2022 Jaroslav ��karvada <jskarvad(a)redhat.com> - 4.21.0-1
- New version
Resolves: rhbz#2130187
* Thu Jul 21 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 4.20.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Thu Mar 17 2022 Jaroslav ��karvada <jskarvad(a)redhat.com> - 4.20.0-1
- New version
Resolves: rhbz#2064316
* Thu Jan 20 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 4.19.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2253431 - datovka-4.23.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2253431
--------------------------------------------------------------------------------
================================================================================
php-nikic-php-parser4-4.18.0-1.el9 (FEDORA-EPEL-2023-316e73fc47)
A PHP parser written in PHP - version 4
--------------------------------------------------------------------------------
Update Information:
**Version 4.18.0** (2023-12-10) Added * Added methods
`ParserFactory::createForNewestSupportedVersion()` and
`ParserFactory::createForHostVersion()` for forward-compatibility with PHP-
Parser 5.0. Fixed * Fixed missing name resolution of class constant types. *
Fixed class members being dropped if an error is encountered while parsing a
later class member (when error recovery is enabeld).
--------------------------------------------------------------------------------
ChangeLog:
* Mon Dec 11 2023 Remi Collet <remi(a)remirepo.net> - 4.18.0-1
- update to 4.18.0
--------------------------------------------------------------------------------
================================================================================
python-damo-2.1.0-1.el9 (FEDORA-EPEL-2023-d2d929502c)
Data Access Monitoring Operator
--------------------------------------------------------------------------------
Update Information:
v2.1.0 - Remove 'damo translate_damos' - Internal code cleanup - Make 'damo
show' fail faster for some cases v2.0.9 - Internal code cleanup v2.0.8 -
Support DAMOS quota goals (not mainlined DAMON feature) v2.0.7 - 'damo
status': Add an option for only entered inputs without updating sysfs - 'damo
fmt_json': Drop non-input fields
--------------------------------------------------------------------------------
ChangeLog:
* Mon Dec 11 2023 Michel Lind <salimma(a)fedoraproject.org> - 2.1.0-1
- Update to 2.1.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2249857 - python-damo-2.1.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2249857
--------------------------------------------------------------------------------
================================================================================
python-opensearch-py-2.4.2-2.el9 (FEDORA-EPEL-2023-1358c369a2)
Python low-level client for OpenSearch
--------------------------------------------------------------------------------
Update Information:
* Update to 2.4.2 * Convert spec to %autochangelog macro
--------------------------------------------------------------------------------
ChangeLog:
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2253963 - Release opensearch-py 2.4.2 for EL 7/8/9
https://bugzilla.redhat.com/show_bug.cgi?id=2253963
--------------------------------------------------------------------------------
================================================================================
python-pathspec-0.12.1-1.el9 (FEDORA-EPEL-2023-7f4bdc6e2c)
Utility library for gitignore style pattern matching of file paths
--------------------------------------------------------------------------------
Update Information:
Update to version 0.12.1
--------------------------------------------------------------------------------
ChangeLog:
* Mon Dec 11 2023 Adrien Verg�� <adrienverge(a)gmail.com> - 0.12.1-1
- Update to latest upstream version
--------------------------------------------------------------------------------
================================================================================
rpkg-1.66-14.el9 (FEDORA-EPEL-2023-3d61283ef4)
Python library for interacting with rpm+git
--------------------------------------------------------------------------------
Update Information:
Actually, added the patches that were missed in the last update. Patches for
"undo rpmautospec processing" - during `import`, specfile is searched and
rpmautospec records are removed. * Patch: *pkg import: Don't delete changelog
generated by `rpmautospec convert` * Patch: *pkg import: Undo rpmautospec
processing * Patch: Unittests for "Undo rpmautospec processing"
--------------------------------------------------------------------------------
ChangeLog:
* Mon Dec 11 2023 Miro Hron��ok <mhroncok(a)redhat.com> - 1.66-14
- Actually add the patches:
- Patch: *pkg import: Don't delete changelog generated by `rpmautospec convert`
- Patch: *pkg import: Undo rpmautospec processing
- Patch: Unittests for "Undo rpmautospec processing"
--------------------------------------------------------------------------------
================================================================================
tmt-1.30.0-1.el9 (FEDORA-EPEL-2023-5f4d760a59)
Test Management Tool
--------------------------------------------------------------------------------
Update Information:
Automatic update for tmt-1.30.0-1.el9. ##### **Changelog for tmt** ``` * Fri
Dec 08 2023 Petr ��pl��chal <psplicha(a)redhat.com> - 1.30.0 - Make `arch` field
unsupported in the spec - Introduce `tty` test attribute to control terminal
environment - Ensure the imported plan's `enabled` key is respected - Add
support for user defined templates (#2519) - Update the common schema for the
`check` key - Create a `checks` directory to store avc/dmesg checks - Correctly
update environment from importing plan - Implement `tmt try` for interactive
sessions - Use a shorter time for `podman stop` (#2480) - Add the `redis` server
as a multihost sync example - Improve documentation of test checks - Adjust the
format of Polarion test run title - Run all available tests only upon a user
request - Rename `name` to `how` in test check specification (#2527) - Link
`inheritance` and `elasticity` from the guide - Add the `fips` field for the
`polarion` report - Cover `tmt.cli` with `pyright` (#2520) - Custom soft/hard
reboot commands for the connect provision plugin - Add `--feeling-safe` for
allowing possibly dangerous actions - Update docs for the `polarion` report
plugin - Move test-requested reboot handling into test invocation class - Add
`-i` to select an image in beaker and artemis - Document how to use `yaml`
anchors and aliases - Simplify log decolorizers to support pickleable trees -
Add description field to polarion report plugin - Make check plugin class
generic over check class (#2502) - Increase verbosity of Artemis provisioning
errors - Add more distros to the `mrack` config - Move the `contact` key to the
`Core` class - Bump tmt in lint pre-commit check to 1.29.0 - Add Python 3.12 to
the test matrix - Move `mrack` configs into `tmt+provision-beaker` - Allow
running upgrade from the current repository - Fix remote nested library fetch
and add test - Cover tmt.options with pyright - Cover tmt.checks, tmt.frameworks
and tmt.log with pyright - Cover tmt.result with pyright checks - Store fmf
`context` in results for each test - Add networks to the podman provision plugin
(#2419) - Add a dedicated exit code when all tests reported `skip` result - Move
invocation-related fields out of `Test` class - Remove expected fail from
`/tests/pip/install/full` - Convert test execution internals to use "invocation"
bundle (#2469) - Introduce a separate page `Code` for code docs - Add code
documentation generated from docstrings - Fix possible unbound variable after
import-under-try - Add `pyright` as a `pre-commit` check - Add a helper for
nonconflicting, multihost-safe filenames - Add the `whiteboard` option for
`beaker` provision - Support timestamped logging even on the terminal - Enable
pyupgrade `UP` ruff rule - Fix `UP035` deprecated-import violations - Fix
`UP034` extraneous-parentheses violation - Fix `UP033` lru-cache-with-maxsize-
none violations - Fix `UP032` f-string violations - Fix `UP013` convert-typed-
dict-functional-to-class - Fix `UP009` utf8-encoding-declaration violations -
Fix `UP006` non-pep585-annotation violations - Try several times to build the
`become` container (#2467) - Add .py file extension to docs scripts (#2476) -
Add a link to the Testing Farm documentation - Use `renku` as the default theme
for building docs - Properly normalize the test `path` key - Add an `adjust`
example for enabling custom repo - Drop special normalization methods - Disable
`dist-git-init` in the `distgit` test (#2463) ```
--------------------------------------------------------------------------------
ChangeLog:
* Fri Dec 8 2023 Petr ��pl��chal <psplicha(a)redhat.com> - 1.30.0
- Make `arch` field unsupported in the spec
- Introduce `tty` test attribute to control terminal environment
- Ensure the imported plan's `enabled` key is respected
- Add support for user defined templates (#2519)
- Update the common schema for the `check` key
- Create a `checks` directory to store avc/dmesg checks
- Correctly update environment from importing plan
- Implement `tmt try` for interactive sessions
- Use a shorter time for `podman stop` (#2480)
- Add the `redis` server as a multihost sync example
- Improve documentation of test checks
- Adjust the format of Polarion test run title
- Run all available tests only upon a user request
- Rename `name` to `how` in test check specification (#2527)
- Link `inheritance` and `elasticity` from the guide
- Add the `fips` field for the `polarion` report
- Cover `tmt.cli` with `pyright` (#2520)
- Custom soft/hard reboot commands for the connect provision plugin
- Add `--feeling-safe` for allowing possibly dangerous actions
- Update docs for the `polarion` report plugin
- Move test-requested reboot handling into test invocation class
- Add `-i` to select an image in beaker and artemis
- Document how to use `yaml` anchors and aliases
- Simplify log decolorizers to support pickleable trees
- Add description field to polarion report plugin
- Make check plugin class generic over check class (#2502)
- Increase verbosity of Artemis provisioning errors
- Add more distros to the `mrack` config
- Move the `contact` key to the `Core` class
- Bump tmt in lint pre-commit check to 1.29.0
- Add Python 3.12 to the test matrix
- Move `mrack` configs into `tmt+provision-beaker`
- Allow running upgrade from the current repository
- Fix remote nested library fetch and add test
- Cover tmt.options with pyright
- Cover tmt.checks, tmt.frameworks and tmt.log with pyright
- Cover tmt.result with pyright checks
- Store fmf `context` in results for each test
- Add networks to the podman provision plugin (#2419)
- Add a dedicated exit code when all tests reported `skip` result
- Move invocation-related fields out of `Test` class
- Remove expected fail from `/tests/pip/install/full`
- Convert test execution internals to use "invocation" bundle (#2469)
- Introduce a separate page `Code` for code docs
- Add code documentation generated from docstrings
- Fix possible unbound variable after import-under-try
- Add `pyright` as a `pre-commit` check
- Add a helper for nonconflicting, multihost-safe filenames
- Add the `whiteboard` option for `beaker` provision
- Support timestamped logging even on the terminal
- Enable pyupgrade `UP` ruff rule
- Fix `UP035` deprecated-import violations
- Fix `UP034` extraneous-parentheses violation
- Fix `UP033` lru-cache-with-maxsize-none violations
- Fix `UP032` f-string violations
- Fix `UP013` convert-typed-dict-functional-to-class
- Fix `UP009` utf8-encoding-declaration violations
- Fix `UP006` non-pep585-annotation violations
- Try several times to build the `become` container (#2467)
- Add .py file extension to docs scripts (#2476)
- Add a link to the Testing Farm documentation
- Use `renku` as the default theme for building docs
- Properly normalize the test `path` key
- Add an `adjust` example for enabling custom repo
- Drop special normalization methods
- Disable `dist-git-init` in the `distgit` test (#2463)
--------------------------------------------------------------------------------
While updating to EL8.9 I noticed that cloud-utils-growpart is in EPEL
and RHEL8?
cloud-utils-growpart noarch 0.33-0.el8 rhel-8-for-x86_64-appstream-rpms
cloud-utils-growpart noarch 0.33-3.el8 epel
Subpackage conflict?
--
Leon
The following Fedora EPEL 7 Security updates need testing:
Age URL
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-fd36857b5e seamonkey-2.53.18-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
chromium-120.0.6099.71-1.el7
guacamole-server-1.5.4-1.el7
unrealircd-6.1.3-1.el7
Details about builds:
================================================================================
chromium-120.0.6099.71-1.el7 (FEDORA-EPEL-2023-3782f9a3bf)
A WebKit (Blink) powered web browser that Google doesn't want you to use
--------------------------------------------------------------------------------
Update Information:
Update to 120.0.6099.71 ---- Update to 120.0.6099.62, upstream release fixes
follow security issues: * High CVE-2023-6508: Use after free in Media Stream *
High CVE-2023-6509: Use after free in Side Panel Search * Medium CVE-2023-6510:
Use after free in Media Capture * Low CVE-2023-6511: Inappropriate
implementation in Autofill * Low CVE-2023-6512: Inappropriate implementation in
Web Browser UI ---- update to 119.0.6045.199, upstream security release *
High CVE-2023-6348: Type Confusion in Spellcheck * High CVE-2023-6347: Use after
free in Mojo * High CVE-2023-6346: Use after free in WebAudio * High
CVE-2023-6350: Out of bounds memory access in libavif * High CVE-2023-6351: Use
after free in libavif * High CVE-2023-6345: Integer overflow in Skia
--------------------------------------------------------------------------------
ChangeLog:
* Fri Dec 8 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.71-1
- update to 120.0.6099.71
* Wed Dec 6 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.62-2
- drop unsupported ldflag which caused build failure
* Tue Dec 5 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.62-1
- update to 120.0.6099.62
- fixed bz#2252874, built with control flow integrity (CFI) support
* Sat Dec 2 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.56-1
- update to 120.0.6099.56
- enable qt6 UI backend
* Sat Dec 2 2023 Than Ngo <than(a)redhat.com> - 119.0.6045.199-2
- fixed bz#2242271, built with bundleminizip in fedora > 39
- fixed bz#2251884, built with fstack-protector-strong for improved security
* Wed Nov 29 2023 Than Ngo <than(a)redhat.com> - 119.0.6045.199-1
- update to 119.0.6045.199
* Sun Nov 19 2023 Than Ngo <than(a)redhat.com> - 119.0.6045.159-2
- fix ffmpeg conflicts
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2252009 - CVE-2023-6346 CVE-2023-6347 CVE-2023-6350 CVE-2023-6351 chromium: various flaws [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252009
[ 2 ] Bug #2252188 - CVE-2023-6345 chromium: chromium-browser: Integer overflow [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252188
[ 3 ] Bug #2252191 - CVE-2023-6348 chromium: chromium-browser: Type Confusion in Spellcheck [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252191
[ 4 ] Bug #2253151 - CVE-2023-6508 chromium: Use after free in Media Stream [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253151
[ 5 ] Bug #2253154 - CVE-2023-6509 chromium: Use after free in Side Panel Search [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253154
[ 6 ] Bug #2253157 - CVE-2023-6510 chromium: Use after free in Media Capture [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253157
[ 7 ] Bug #2253161 - CVE-2023-6511 chromium: Inappropriate implementation in Autofill [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253161
[ 8 ] Bug #2253164 - CVE-2023-6512 chromium: Inappropriate implementation in Web Browser UI [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253164
--------------------------------------------------------------------------------
================================================================================
guacamole-server-1.5.4-1.el7 (FEDORA-EPEL-2023-e5cd593804)
Server-side native components that form the Guacamole proxy
--------------------------------------------------------------------------------
Update Information:
# Apache Guacamole 1.5.4 ## User interface / platform - History Recording
Player should show controls when mouse is moved (GUACAMOLE-1872) - Bug:
Control bar doesn���t auto-hide on history recording player (GUACAMOLE-1873) ##
Authentication, integration, and storage - Bug: Regression in JSON module
causes loading to fail (GUACAMOLE-1851) - Bug: Permission check for creating
user groups is incorrect (GUACAMOLE-1856) ## Protocol support / guacd - Bug:
Race condition can cause the first user for a connection to miss updates
(GUACAMOLE-1846) - Bug: Parser reparses same instructions multiple times in
some cases (GUACAMOLE-1849) - Bug: `guac_common_cursor_dup()` may segfault if
cursor is being modified (GUACAMOLE-1850) - Add libguac convenience functions
for memory management (GUACAMOLE-1867) ## Internationalization - Updates and
corrections to Catalan translation (GUACAMOLE-1880) ## Documentation - TOTP
Authentication - Add documentation relating to usage with docker
(GUACAMOLE-1878) ## General housekeeping and cleanup - Update webapp
dependencies to latest stable and compatible versions (GUACAMOLE-1859) - Bump
version numbers to 1.5.4 (GUACAMOLE-1886)
--------------------------------------------------------------------------------
ChangeLog:
* Sat Dec 9 2023 Robert Scheck <robert(a)fedoraproject.org> - 1:1.5.4-1
- Update to 1.5.4 (#2223510)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2223510 - guacamole-server-1.5.4 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2223510
--------------------------------------------------------------------------------
================================================================================
unrealircd-6.1.3-1.el7 (FEDORA-EPEL-2023-991fb571f9)
Open Source IRC server
--------------------------------------------------------------------------------
Update Information:
# UnrealIRCd 6.1.3 The main focus of this release is adding countermeasures
against large scale spam/drones. Upstream does this by offering a central API
which can be used for accessing Central Blocklist, Central Spamreport and
Central Spamfilter. ## Enhancements * Central anti-spam services: * The
services from below require a central-api key, which you can [request
here](https://www.unrealircd.org/central-api/). * [Central
Blocklist](https://www.unrealircd.org/docs/Central_Blocklist) is an attempt to
detect and block spammers. It works similar to DNS Blacklists but the central
blocklist receives many more details about the user that is trying to connect
and therefore can make a better decision on whether a user is likely a spammer.
* [Central Spamreport](https://www.unrealircd.org/docs/Central_spamreport)
allows you to send spam reports (user details, last sent lines) via the
`SPAMREPORT` command. This information may then be used to improve [Central
Blocklist](https://www.unrealircd.org/docs/Central_Blocklist) and/or [Central
Spamfilter](https://www.unrealircd.org/docs/Central_Spamfilter). * The
[Central Spamfilter](https://www.unrealircd.org/docs/Central_Spamfilter), which
provides `spamfilter { }` blocks that are centrally managed, is now fetched from
a different URL if you have an Central API key set. This way, upstream can later
provide `spamfilter { }` blocks that build on central blocklist scoring
functionality, and also so upstream doesn't have to reveal all the central
spamfilter blocks to the world. * New option `auto` for [set::hide-ban-
reason](https://www.unrealircd.org/docs/Set_block#set::hide-ban-reason), which
is now the default. This will hide the \*LINE reason to other users if the
\*LINE reason contains the IP of the user, for example when it contains a
DroneBL URL which has `lookup?ip=XXX`. This to protect the privacy of the user.
Other possible settings are `no` (never hide, the previous default) and `yes` to
always hide the \*LINE reason. In all cases the user affected by the server ban
can still see the reason and IRCOps too. * Make [Deny
channel](https://www.unrealircd.org/docs/Deny_channel_block) support escaped
sequences like `channel "#xyz\*";` so you can match a literal `*` or `?` via
`\*` and `\?`. * New option [listen::options::websocket::allow-
origin](https://www.unrealircd.org/docs/Listen_block#options_block_(optiona…:
this allows to restrict websocket connections to a list of websites (the sites
hosting the HTML/JS page that makes the websocket connection). It doesn't
*securely* restrict it though, non-browsers will bypass this restriction, but it
can still be useful to restrict regular webchat users. * The [Proxy
block](https://www.unrealircd.org/docs/Proxy_block) already had support for
reverse proxying with the `Forwarded` header. Now it also properly supports
`X-Forwarded-For`. If you previously used a proxy block with type `web`, then
you now need to choose one of the new types explicitly. Note that using a
reverse proxy for IRC traffic is rare (see the proxy block docs for details),
but upstream offers the option. ## Changes * Reserve more file descriptors
for internal use. For example, when there are 10,000 fd's are available upstream
now reserves 250, and when 2048 are available upstream reserves 32. This so
upstream has more fds available to handle things like log files, do HTTPS
callbacks to blacklists, etc. * Make `$client.details` in logs follow the
ident rules for users in the handshake too, so use the `~` prefix if ident
lookups are enabled and identd fails etc. * More validation for operclass
names (`a-zA-Z0-9_-`) * Hits for central-blocklist are now broadcasted
globally instead of staying on the same server. ## Fixes * When using a
trusted reverse proxy with the [Proxy
block](https://www.unrealircd.org/docs/Proxy_block), under some circumstances it
was possible for end-users to spoof IPs. * Crash issue when a module is
reloaded (not unloaded) and that module no longer provides a particular moddata
object, e.g. because it was renamed or no longer needed. This is rare, but did
happen for one third party module recently. * Fix memory leak when unloading a
module for good and that module provided ModData objects for "unknown users"
(users still in the handshake). * Don't ask to generate TLS certificate if one
already exists (issue introduced in 6.1.2). ## Developers and protocol * New
hooks: `HOOKTYPE_WATCH_ADD`, `HOOKTYPE_WATCH_DEL`,
`HOOKTYPE_MONITOR_NOTIFICATION`. * The hook `HOOKTYPE_IS_HANDSHAKE_FINISHED`
is now properly called at all places. * A new [URL
API](https://www.unrealircd.org/docs/Dev:URL_API) to easily fetch URLs from
modules.
--------------------------------------------------------------------------------
ChangeLog:
* Sat Dec 9 2023 Robert Scheck <robert(a)fedoraproject.org> 6.1.3-1
- Upgrade to 6.1.3 (#2252372)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2252372 - unrealircd-6.1.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2252372
--------------------------------------------------------------------------------
The following builds have been pushed to Fedora EPEL 9 updates-testing
chromium-120.0.6099.71-1.el9
expected-1.1.0-1.el9
guacamole-server-1.5.4-1.el9
unrealircd-6.1.3-1.el9
Details about builds:
================================================================================
chromium-120.0.6099.71-1.el9 (FEDORA-EPEL-2023-a0fcd69d86)
A WebKit (Blink) powered web browser that Google doesn't want you to use
--------------------------------------------------------------------------------
Update Information:
Update to 120.0.6099.71 ---- Update to 120.0.6099.62, upstream release fixes
follow security issues: * High CVE-2023-6508: Use after free in Media Stream *
High CVE-2023-6509: Use after free in Side Panel Search * Medium CVE-2023-6510:
Use after free in Media Capture * Low CVE-2023-6511: Inappropriate
implementation in Autofill * Low CVE-2023-6512: Inappropriate implementation in
Web Browser UI ---- update to 119.0.6045.199, upstream security release *
High CVE-2023-6348: Type Confusion in Spellcheck * High CVE-2023-6347: Use after
free in Mojo * High CVE-2023-6346: Use after free in WebAudio * High
CVE-2023-6350: Out of bounds memory access in libavif * High CVE-2023-6351: Use
after free in libavif * High CVE-2023-6345: Integer overflow in Skia
--------------------------------------------------------------------------------
ChangeLog:
* Fri Dec 8 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.71-1
- update to 120.0.6099.71
* Wed Dec 6 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.62-2
- drop unsupported ldflag which caused build failure
* Tue Dec 5 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.62-1
- update to 120.0.6099.62
- fixed bz#2252874, built with control flow integrity (CFI) support
* Sat Dec 2 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.56-1
- update to 120.0.6099.56
- enable qt6 UI backend
* Sat Dec 2 2023 Than Ngo <than(a)redhat.com> - 119.0.6045.199-2
- fixed bz#2242271, built with bundleminizip in fedora > 39
- fixed bz#2251884, built with fstack-protector-strong for improved security
* Wed Nov 29 2023 Than Ngo <than(a)redhat.com> - 119.0.6045.199-1
- update to 119.0.6045.199
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2252009 - CVE-2023-6346 CVE-2023-6347 CVE-2023-6350 CVE-2023-6351 chromium: various flaws [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252009
[ 2 ] Bug #2252188 - CVE-2023-6345 chromium: chromium-browser: Integer overflow [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252188
[ 3 ] Bug #2252191 - CVE-2023-6348 chromium: chromium-browser: Type Confusion in Spellcheck [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252191
[ 4 ] Bug #2253151 - CVE-2023-6508 chromium: Use after free in Media Stream [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253151
[ 5 ] Bug #2253154 - CVE-2023-6509 chromium: Use after free in Side Panel Search [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253154
[ 6 ] Bug #2253157 - CVE-2023-6510 chromium: Use after free in Media Capture [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253157
[ 7 ] Bug #2253161 - CVE-2023-6511 chromium: Inappropriate implementation in Autofill [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253161
[ 8 ] Bug #2253164 - CVE-2023-6512 chromium: Inappropriate implementation in Web Browser UI [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253164
--------------------------------------------------------------------------------
================================================================================
expected-1.1.0-1.el9 (FEDORA-EPEL-2023-ee66f94881)
C++11/14/17 std::expected with functional-style extensions
--------------------------------------------------------------------------------
Update Information:
Build for EPEL8/9
--------------------------------------------------------------------------------
ChangeLog:
* Thu Mar 16 2023 Vitaly Zaitsev <vitaly(a)easycoding.org> - 1.1.0-1
- Updated to version 1.1.0.
* Thu Jan 19 2023 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.0.0-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Thu Jul 21 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.0.0-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Thu Jan 20 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.0.0-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Wed Jul 21 2021 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.0.0-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2252323 - Please branch and build expected for EPEL8 and EPEL9
https://bugzilla.redhat.com/show_bug.cgi?id=2252323
--------------------------------------------------------------------------------
================================================================================
guacamole-server-1.5.4-1.el9 (FEDORA-EPEL-2023-f1d8823b4b)
Server-side native components that form the Guacamole proxy
--------------------------------------------------------------------------------
Update Information:
# Apache Guacamole 1.5.4 ## User interface / platform - History Recording
Player should show controls when mouse is moved (GUACAMOLE-1872) - Bug:
Control bar doesn���t auto-hide on history recording player (GUACAMOLE-1873) ##
Authentication, integration, and storage - Bug: Regression in JSON module
causes loading to fail (GUACAMOLE-1851) - Bug: Permission check for creating
user groups is incorrect (GUACAMOLE-1856) ## Protocol support / guacd - Bug:
Race condition can cause the first user for a connection to miss updates
(GUACAMOLE-1846) - Bug: Parser reparses same instructions multiple times in
some cases (GUACAMOLE-1849) - Bug: `guac_common_cursor_dup()` may segfault if
cursor is being modified (GUACAMOLE-1850) - Add libguac convenience functions
for memory management (GUACAMOLE-1867) ## Internationalization - Updates and
corrections to Catalan translation (GUACAMOLE-1880) ## Documentation - TOTP
Authentication - Add documentation relating to usage with docker
(GUACAMOLE-1878) ## General housekeeping and cleanup - Update webapp
dependencies to latest stable and compatible versions (GUACAMOLE-1859) - Bump
version numbers to 1.5.4 (GUACAMOLE-1886)
--------------------------------------------------------------------------------
ChangeLog:
* Sat Dec 9 2023 Robert Scheck <robert(a)fedoraproject.org> - 1.5.4-1
- Update to 1.5.4 (#2223510)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2223510 - guacamole-server-1.5.4 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2223510
--------------------------------------------------------------------------------
================================================================================
unrealircd-6.1.3-1.el9 (FEDORA-EPEL-2023-2ac3f6abae)
Open Source IRC server
--------------------------------------------------------------------------------
Update Information:
# UnrealIRCd 6.1.3 The main focus of this release is adding countermeasures
against large scale spam/drones. Upstream does this by offering a central API
which can be used for accessing Central Blocklist, Central Spamreport and
Central Spamfilter. ## Enhancements * Central anti-spam services: * The
services from below require a central-api key, which you can [request
here](https://www.unrealircd.org/central-api/). * [Central
Blocklist](https://www.unrealircd.org/docs/Central_Blocklist) is an attempt to
detect and block spammers. It works similar to DNS Blacklists but the central
blocklist receives many more details about the user that is trying to connect
and therefore can make a better decision on whether a user is likely a spammer.
* [Central Spamreport](https://www.unrealircd.org/docs/Central_spamreport)
allows you to send spam reports (user details, last sent lines) via the
`SPAMREPORT` command. This information may then be used to improve [Central
Blocklist](https://www.unrealircd.org/docs/Central_Blocklist) and/or [Central
Spamfilter](https://www.unrealircd.org/docs/Central_Spamfilter). * The
[Central Spamfilter](https://www.unrealircd.org/docs/Central_Spamfilter), which
provides `spamfilter { }` blocks that are centrally managed, is now fetched from
a different URL if you have an Central API key set. This way, upstream can later
provide `spamfilter { }` blocks that build on central blocklist scoring
functionality, and also so upstream doesn't have to reveal all the central
spamfilter blocks to the world. * New option `auto` for [set::hide-ban-
reason](https://www.unrealircd.org/docs/Set_block#set::hide-ban-reason), which
is now the default. This will hide the \*LINE reason to other users if the
\*LINE reason contains the IP of the user, for example when it contains a
DroneBL URL which has `lookup?ip=XXX`. This to protect the privacy of the user.
Other possible settings are `no` (never hide, the previous default) and `yes` to
always hide the \*LINE reason. In all cases the user affected by the server ban
can still see the reason and IRCOps too. * Make [Deny
channel](https://www.unrealircd.org/docs/Deny_channel_block) support escaped
sequences like `channel "#xyz\*";` so you can match a literal `*` or `?` via
`\*` and `\?`. * New option [listen::options::websocket::allow-
origin](https://www.unrealircd.org/docs/Listen_block#options_block_(optiona…:
this allows to restrict websocket connections to a list of websites (the sites
hosting the HTML/JS page that makes the websocket connection). It doesn't
*securely* restrict it though, non-browsers will bypass this restriction, but it
can still be useful to restrict regular webchat users. * The [Proxy
block](https://www.unrealircd.org/docs/Proxy_block) already had support for
reverse proxying with the `Forwarded` header. Now it also properly supports
`X-Forwarded-For`. If you previously used a proxy block with type `web`, then
you now need to choose one of the new types explicitly. Note that using a
reverse proxy for IRC traffic is rare (see the proxy block docs for details),
but upstream offers the option. ## Changes * Reserve more file descriptors
for internal use. For example, when there are 10,000 fd's are available upstream
now reserves 250, and when 2048 are available upstream reserves 32. This so
upstream has more fds available to handle things like log files, do HTTPS
callbacks to blacklists, etc. * Make `$client.details` in logs follow the
ident rules for users in the handshake too, so use the `~` prefix if ident
lookups are enabled and identd fails etc. * More validation for operclass
names (`a-zA-Z0-9_-`) * Hits for central-blocklist are now broadcasted
globally instead of staying on the same server. ## Fixes * When using a
trusted reverse proxy with the [Proxy
block](https://www.unrealircd.org/docs/Proxy_block), under some circumstances it
was possible for end-users to spoof IPs. * Crash issue when a module is
reloaded (not unloaded) and that module no longer provides a particular moddata
object, e.g. because it was renamed or no longer needed. This is rare, but did
happen for one third party module recently. * Fix memory leak when unloading a
module for good and that module provided ModData objects for "unknown users"
(users still in the handshake). * Don't ask to generate TLS certificate if one
already exists (issue introduced in 6.1.2). ## Developers and protocol * New
hooks: `HOOKTYPE_WATCH_ADD`, `HOOKTYPE_WATCH_DEL`,
`HOOKTYPE_MONITOR_NOTIFICATION`. * The hook `HOOKTYPE_IS_HANDSHAKE_FINISHED`
is now properly called at all places. * A new [URL
API](https://www.unrealircd.org/docs/Dev:URL_API) to easily fetch URLs from
modules.
--------------------------------------------------------------------------------
ChangeLog:
* Sat Dec 9 2023 Robert Scheck <robert(a)fedoraproject.org> 6.1.3-1
- Upgrade to 6.1.3 (#2252372)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2252372 - unrealircd-6.1.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2252372
--------------------------------------------------------------------------------
The following Fedora EPEL 8 Security updates need testing:
Age URL
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-76db503610 seamonkey-2.53.18-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
chromium-120.0.6099.71-1.el8
expected-1.1.0-1.el8
guacamole-server-1.5.4-1.el8
unrealircd-6.1.3-1.el8
Details about builds:
================================================================================
chromium-120.0.6099.71-1.el8 (FEDORA-EPEL-2023-d1b0df83e0)
A WebKit (Blink) powered web browser that Google doesn't want you to use
--------------------------------------------------------------------------------
Update Information:
Update to 120.0.6099.71 ---- Update to 120.0.6099.62, upstream release fixes
follow security issues: * High CVE-2023-6508: Use after free in Media Stream *
High CVE-2023-6509: Use after free in Side Panel Search * Medium CVE-2023-6510:
Use after free in Media Capture * Low CVE-2023-6511: Inappropriate
implementation in Autofill * Low CVE-2023-6512: Inappropriate implementation in
Web Browser UI ---- update to 119.0.6045.199, upstream security release *
High CVE-2023-6348: Type Confusion in Spellcheck * High CVE-2023-6347: Use after
free in Mojo * High CVE-2023-6346: Use after free in WebAudio * High
CVE-2023-6350: Out of bounds memory access in libavif * High CVE-2023-6351: Use
after free in libavif * High CVE-2023-6345: Integer overflow in Skia
--------------------------------------------------------------------------------
ChangeLog:
* Fri Dec 8 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.71-1
- update to 120.0.6099.71
* Wed Dec 6 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.62-2
- drop unsupported ldflag which caused build failure
* Tue Dec 5 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.62-1
- update to 120.0.6099.62
- fixed bz#2252874, built with control flow integrity (CFI) support
* Sat Dec 2 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.56-1
- update to 120.0.6099.56
- enable qt6 UI backend
* Sat Dec 2 2023 Than Ngo <than(a)redhat.com> - 119.0.6045.199-2
- fixed bz#2242271, built with bundleminizip in fedora > 39
- fixed bz#2251884, built with fstack-protector-strong for improved security
* Wed Nov 29 2023 Than Ngo <than(a)redhat.com> - 119.0.6045.199-1
- update to 119.0.6045.199
* Sun Nov 19 2023 Than Ngo <than(a)redhat.com> - 119.0.6045.159-2
- fix ffmpeg conflicts
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2252009 - CVE-2023-6346 CVE-2023-6347 CVE-2023-6350 CVE-2023-6351 chromium: various flaws [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252009
[ 2 ] Bug #2252188 - CVE-2023-6345 chromium: chromium-browser: Integer overflow [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252188
[ 3 ] Bug #2252191 - CVE-2023-6348 chromium: chromium-browser: Type Confusion in Spellcheck [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252191
[ 4 ] Bug #2253151 - CVE-2023-6508 chromium: Use after free in Media Stream [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253151
[ 5 ] Bug #2253154 - CVE-2023-6509 chromium: Use after free in Side Panel Search [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253154
[ 6 ] Bug #2253157 - CVE-2023-6510 chromium: Use after free in Media Capture [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253157
[ 7 ] Bug #2253161 - CVE-2023-6511 chromium: Inappropriate implementation in Autofill [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253161
[ 8 ] Bug #2253164 - CVE-2023-6512 chromium: Inappropriate implementation in Web Browser UI [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253164
--------------------------------------------------------------------------------
================================================================================
expected-1.1.0-1.el8 (FEDORA-EPEL-2023-ddda2b79e7)
C++11/14/17 std::expected with functional-style extensions
--------------------------------------------------------------------------------
Update Information:
Build for EPEL8/9
--------------------------------------------------------------------------------
ChangeLog:
* Thu Mar 16 2023 Vitaly Zaitsev <vitaly(a)easycoding.org> - 1.1.0-1
- Updated to version 1.1.0.
* Thu Jan 19 2023 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.0.0-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Thu Jul 21 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.0.0-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Thu Jan 20 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.0.0-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Wed Jul 21 2021 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.0.0-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Tue Jan 26 2021 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.0.0-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Mon Jul 27 2020 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.0.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Tue Jan 28 2020 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.0.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
* Mon Jan 6 2020 Vitaly Zaitsev <vitaly(a)easycoding.org> - 1.0.0-1
- Initial SPEC release.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2252323 - Please branch and build expected for EPEL8 and EPEL9
https://bugzilla.redhat.com/show_bug.cgi?id=2252323
--------------------------------------------------------------------------------
================================================================================
guacamole-server-1.5.4-1.el8 (FEDORA-EPEL-2023-eb17d13fbd)
Server-side native components that form the Guacamole proxy
--------------------------------------------------------------------------------
Update Information:
# Apache Guacamole 1.5.4 ## User interface / platform - History Recording
Player should show controls when mouse is moved (GUACAMOLE-1872) - Bug:
Control bar doesn���t auto-hide on history recording player (GUACAMOLE-1873) ##
Authentication, integration, and storage - Bug: Regression in JSON module
causes loading to fail (GUACAMOLE-1851) - Bug: Permission check for creating
user groups is incorrect (GUACAMOLE-1856) ## Protocol support / guacd - Bug:
Race condition can cause the first user for a connection to miss updates
(GUACAMOLE-1846) - Bug: Parser reparses same instructions multiple times in
some cases (GUACAMOLE-1849) - Bug: `guac_common_cursor_dup()` may segfault if
cursor is being modified (GUACAMOLE-1850) - Add libguac convenience functions
for memory management (GUACAMOLE-1867) ## Internationalization - Updates and
corrections to Catalan translation (GUACAMOLE-1880) ## Documentation - TOTP
Authentication - Add documentation relating to usage with docker
(GUACAMOLE-1878) ## General housekeeping and cleanup - Update webapp
dependencies to latest stable and compatible versions (GUACAMOLE-1859) - Bump
version numbers to 1.5.4 (GUACAMOLE-1886)
--------------------------------------------------------------------------------
ChangeLog:
* Sat Dec 9 2023 Robert Scheck <robert(a)fedoraproject.org> - 1.5.4-1
- Update to 1.5.4 (#2223510)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2223510 - guacamole-server-1.5.4 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2223510
--------------------------------------------------------------------------------
================================================================================
unrealircd-6.1.3-1.el8 (FEDORA-EPEL-2023-a1267e32b9)
Open Source IRC server
--------------------------------------------------------------------------------
Update Information:
# UnrealIRCd 6.1.3 The main focus of this release is adding countermeasures
against large scale spam/drones. Upstream does this by offering a central API
which can be used for accessing Central Blocklist, Central Spamreport and
Central Spamfilter. ## Enhancements * Central anti-spam services: * The
services from below require a central-api key, which you can [request
here](https://www.unrealircd.org/central-api/). * [Central
Blocklist](https://www.unrealircd.org/docs/Central_Blocklist) is an attempt to
detect and block spammers. It works similar to DNS Blacklists but the central
blocklist receives many more details about the user that is trying to connect
and therefore can make a better decision on whether a user is likely a spammer.
* [Central Spamreport](https://www.unrealircd.org/docs/Central_spamreport)
allows you to send spam reports (user details, last sent lines) via the
`SPAMREPORT` command. This information may then be used to improve [Central
Blocklist](https://www.unrealircd.org/docs/Central_Blocklist) and/or [Central
Spamfilter](https://www.unrealircd.org/docs/Central_Spamfilter). * The
[Central Spamfilter](https://www.unrealircd.org/docs/Central_Spamfilter), which
provides `spamfilter { }` blocks that are centrally managed, is now fetched from
a different URL if you have an Central API key set. This way, upstream can later
provide `spamfilter { }` blocks that build on central blocklist scoring
functionality, and also so upstream doesn't have to reveal all the central
spamfilter blocks to the world. * New option `auto` for [set::hide-ban-
reason](https://www.unrealircd.org/docs/Set_block#set::hide-ban-reason), which
is now the default. This will hide the \*LINE reason to other users if the
\*LINE reason contains the IP of the user, for example when it contains a
DroneBL URL which has `lookup?ip=XXX`. This to protect the privacy of the user.
Other possible settings are `no` (never hide, the previous default) and `yes` to
always hide the \*LINE reason. In all cases the user affected by the server ban
can still see the reason and IRCOps too. * Make [Deny
channel](https://www.unrealircd.org/docs/Deny_channel_block) support escaped
sequences like `channel "#xyz\*";` so you can match a literal `*` or `?` via
`\*` and `\?`. * New option [listen::options::websocket::allow-
origin](https://www.unrealircd.org/docs/Listen_block#options_block_(optiona…:
this allows to restrict websocket connections to a list of websites (the sites
hosting the HTML/JS page that makes the websocket connection). It doesn't
*securely* restrict it though, non-browsers will bypass this restriction, but it
can still be useful to restrict regular webchat users. * The [Proxy
block](https://www.unrealircd.org/docs/Proxy_block) already had support for
reverse proxying with the `Forwarded` header. Now it also properly supports
`X-Forwarded-For`. If you previously used a proxy block with type `web`, then
you now need to choose one of the new types explicitly. Note that using a
reverse proxy for IRC traffic is rare (see the proxy block docs for details),
but upstream offers the option. ## Changes * Reserve more file descriptors
for internal use. For example, when there are 10,000 fd's are available upstream
now reserves 250, and when 2048 are available upstream reserves 32. This so
upstream has more fds available to handle things like log files, do HTTPS
callbacks to blacklists, etc. * Make `$client.details` in logs follow the
ident rules for users in the handshake too, so use the `~` prefix if ident
lookups are enabled and identd fails etc. * More validation for operclass
names (`a-zA-Z0-9_-`) * Hits for central-blocklist are now broadcasted
globally instead of staying on the same server. ## Fixes * When using a
trusted reverse proxy with the [Proxy
block](https://www.unrealircd.org/docs/Proxy_block), under some circumstances it
was possible for end-users to spoof IPs. * Crash issue when a module is
reloaded (not unloaded) and that module no longer provides a particular moddata
object, e.g. because it was renamed or no longer needed. This is rare, but did
happen for one third party module recently. * Fix memory leak when unloading a
module for good and that module provided ModData objects for "unknown users"
(users still in the handshake). * Don't ask to generate TLS certificate if one
already exists (issue introduced in 6.1.2). ## Developers and protocol * New
hooks: `HOOKTYPE_WATCH_ADD`, `HOOKTYPE_WATCH_DEL`,
`HOOKTYPE_MONITOR_NOTIFICATION`. * The hook `HOOKTYPE_IS_HANDSHAKE_FINISHED`
is now properly called at all places. * A new [URL
API](https://www.unrealircd.org/docs/Dev:URL_API) to easily fetch URLs from
modules.
--------------------------------------------------------------------------------
ChangeLog:
* Sat Dec 9 2023 Robert Scheck <robert(a)fedoraproject.org> 6.1.3-1
- Upgrade to 6.1.3 (#2252372)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2252372 - unrealircd-6.1.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2252372
--------------------------------------------------------------------------------
The following Fedora EPEL 7 Security updates need testing:
Age URL
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-259055935d chromium-120.0.6099.62-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
nodejs-16.20.2-1.el7
seamonkey-2.53.18-1.el7
Details about builds:
================================================================================
nodejs-16.20.2-1.el7 (FEDORA-EPEL-2023-8ea1dafefe)
JavaScript runtime
--------------------------------------------------------------------------------
Update Information:
Update to final 16.20.2 release
--------------------------------------------------------------------------------
ChangeLog:
* Fri Dec 8 2023 Stephen Gallagher <sgallagh(a)redhat.com> - 1:16.20.2-1
- Update to 16.20.2
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2253524 - Upgrade to last supported NodeJS 16 version
https://bugzilla.redhat.com/show_bug.cgi?id=2253524
--------------------------------------------------------------------------------
================================================================================
seamonkey-2.53.18-1.el7 (FEDORA-EPEL-2023-fd36857b5e)
Web browser, e-mail, news, IRC client, HTML editor
--------------------------------------------------------------------------------
Update Information:
Update to 2.53.18
--------------------------------------------------------------------------------
ChangeLog:
* Fri Dec 8 2023 Dmitry Butskoy <Dmitry(a)Butskoy.name> 2.53.18-1
- update to 2.53.18
- add patch for binutils >= 2.36
--------------------------------------------------------------------------------
The following builds have been pushed to Fedora EPEL 7 updates-testing
chromium-120.0.6099.62-1.el7
netdata-1.44.0-1.el7
Details about builds:
================================================================================
chromium-120.0.6099.62-1.el7 (FEDORA-EPEL-2023-259055935d)
A WebKit (Blink) powered web browser that Google doesn't want you to use
--------------------------------------------------------------------------------
Update Information:
Update to 120.0.6099.62, upstream release fixes follow security issues: * High
CVE-2023-6508: Use after free in Media Stream * High CVE-2023-6509: Use after
free in Side Panel Search * Medium CVE-2023-6510: Use after free in Media
Capture * Low CVE-2023-6511: Inappropriate implementation in Autofill * Low
CVE-2023-6512: Inappropriate implementation in Web Browser UI ---- update to
119.0.6045.199, upstream security release * High CVE-2023-6348: Type Confusion
in Spellcheck * High CVE-2023-6347: Use after free in Mojo * High CVE-2023-6346:
Use after free in WebAudio * High CVE-2023-6350: Out of bounds memory access in
libavif * High CVE-2023-6351: Use after free in libavif * High CVE-2023-6345:
Integer overflow in Skia
--------------------------------------------------------------------------------
ChangeLog:
* Tue Dec 5 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.62-1
- update to 120.0.6099.62
- fixed bz#2252874, built with control flow integrity (CFI) support
* Sat Dec 2 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.56-1
- update to 120.0.6099.56
- enable qt6 UI backend
* Sat Dec 2 2023 Than Ngo <than(a)redhat.com> - 119.0.6045.199-2
- fixed bz#2242271, built with bundleminizip in fedora > 39
- fixed bz#2251884, built with fstack-protector-strong for improved security
* Wed Nov 29 2023 Than Ngo <than(a)redhat.com> - 119.0.6045.199-1
- update to 119.0.6045.199
* Sun Nov 19 2023 Than Ngo <than(a)redhat.com> - 119.0.6045.159-2
- fix ffmpeg conflicts
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2252009 - CVE-2023-6346 CVE-2023-6347 CVE-2023-6350 CVE-2023-6351 chromium: various flaws [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252009
[ 2 ] Bug #2252188 - CVE-2023-6345 chromium: chromium-browser: Integer overflow [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252188
[ 3 ] Bug #2252191 - CVE-2023-6348 chromium: chromium-browser: Type Confusion in Spellcheck [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252191
[ 4 ] Bug #2253151 - CVE-2023-6508 chromium: Use after free in Media Stream [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253151
[ 5 ] Bug #2253154 - CVE-2023-6509 chromium: Use after free in Side Panel Search [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253154
[ 6 ] Bug #2253157 - CVE-2023-6510 chromium: Use after free in Media Capture [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253157
[ 7 ] Bug #2253161 - CVE-2023-6511 chromium: Inappropriate implementation in Autofill [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253161
[ 8 ] Bug #2253164 - CVE-2023-6512 chromium: Inappropriate implementation in Web Browser UI [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253164
--------------------------------------------------------------------------------
================================================================================
netdata-1.44.0-1.el7 (FEDORA-EPEL-2023-e21ee694ce)
Real-time performance monitoring
--------------------------------------------------------------------------------
Update Information:
Update from upstream
--------------------------------------------------------------------------------
ChangeLog:
* Thu Dec 7 2023 Didier Fabert <didier.fabert(a)gmail.com> 1.44.0-1
- Update from upstream
--------------------------------------------------------------------------------
The following builds have been pushed to Fedora EPEL 8 updates-testing
chromium-120.0.6099.62-2.el8
java-latest-openjdk-21.0.1.0.12-1.rolling.el8
netdata-1.44.0-1.el8
Details about builds:
================================================================================
chromium-120.0.6099.62-2.el8 (FEDORA-EPEL-2023-d0b9bcb64f)
A WebKit (Blink) powered web browser that Google doesn't want you to use
--------------------------------------------------------------------------------
Update Information:
Update to 120.0.6099.62, upstream release fixes follow security issues: * High
CVE-2023-6508: Use after free in Media Stream * High CVE-2023-6509: Use after
free in Side Panel Search * Medium CVE-2023-6510: Use after free in Media
Capture * Low CVE-2023-6511: Inappropriate implementation in Autofill * Low
CVE-2023-6512: Inappropriate implementation in Web Browser UI ---- update to
119.0.6045.199, upstream security release * High CVE-2023-6348: Type Confusion
in Spellcheck * High CVE-2023-6347: Use after free in Mojo * High CVE-2023-6346:
Use after free in WebAudio * High CVE-2023-6350: Out of bounds memory access in
libavif * High CVE-2023-6351: Use after free in libavif * High CVE-2023-6345:
Integer overflow in Skia
--------------------------------------------------------------------------------
ChangeLog:
* Wed Dec 6 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.62-2
- drop unsupported ldflag which caused build failure
* Tue Dec 5 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.62-1
- update to 120.0.6099.62
- fixed bz#2252874, built with control flow integrity (CFI) support
* Sat Dec 2 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.56-1
- update to 120.0.6099.56
- enable qt6 UI backend
* Sat Dec 2 2023 Than Ngo <than(a)redhat.com> - 119.0.6045.199-2
- fixed bz#2242271, built with bundleminizip in fedora > 39
- fixed bz#2251884, built with fstack-protector-strong for improved security
* Wed Nov 29 2023 Than Ngo <than(a)redhat.com> - 119.0.6045.199-1
- update to 119.0.6045.199
* Sun Nov 19 2023 Than Ngo <than(a)redhat.com> - 119.0.6045.159-2
- fix ffmpeg conflicts
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2252009 - CVE-2023-6346 CVE-2023-6347 CVE-2023-6350 CVE-2023-6351 chromium: various flaws [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252009
[ 2 ] Bug #2252188 - CVE-2023-6345 chromium: chromium-browser: Integer overflow [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252188
[ 3 ] Bug #2252191 - CVE-2023-6348 chromium: chromium-browser: Type Confusion in Spellcheck [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252191
[ 4 ] Bug #2253151 - CVE-2023-6508 chromium: Use after free in Media Stream [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253151
[ 5 ] Bug #2253154 - CVE-2023-6509 chromium: Use after free in Side Panel Search [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253154
[ 6 ] Bug #2253157 - CVE-2023-6510 chromium: Use after free in Media Capture [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253157
[ 7 ] Bug #2253161 - CVE-2023-6511 chromium: Inappropriate implementation in Autofill [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253161
[ 8 ] Bug #2253164 - CVE-2023-6512 chromium: Inappropriate implementation in Web Browser UI [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253164
--------------------------------------------------------------------------------
================================================================================
java-latest-openjdk-21.0.1.0.12-1.rolling.el8 (FEDORA-EPEL-2023-1cee9af347)
OpenJDK 21 Runtime Environment
--------------------------------------------------------------------------------
Update Information:
updated to octrober cpu
--------------------------------------------------------------------------------
ChangeLog:
* Wed Nov 22 2023 Jiri Vanek <jvanek(a)redhat.com> - 1:21.0.1.0.12-1.rolling
- updated to OpenJDK 21.0.1 (2023-10-17)
* Fri Sep 29 2023 Yaakov Selkowitz <yselkowi(a)redhat.com> - 1:21.0.0.0.35-3.rolling
- Fix flatpak build by handling different installation prefixes of package dependencies
* Tue Sep 19 2023 Jiri Vanek <jvanek(a)redhat.com> - 1:21.0.0.0.35-2.rolling
- adapted to new path in sources
- repacked alt-java from misc subpkg
- adapted alt-java to grep correctly prctl
- removed no longer prepared nss.cfg
* Tue Aug 29 2023 Jiri Vanek <jvanek(a)redhat.com> - 1:21.0.0.0.35-1.rolling
- updated to jdk 21
--------------------------------------------------------------------------------
================================================================================
netdata-1.44.0-1.el8 (FEDORA-EPEL-2023-39976b127c)
Real-time performance monitoring
--------------------------------------------------------------------------------
Update Information:
Update from upstream
--------------------------------------------------------------------------------
ChangeLog:
* Thu Dec 7 2023 Didier Fabert <didier.fabert(a)gmail.com> 1.44.0-1
- Update from upstream
--------------------------------------------------------------------------------
The following Fedora EPEL 9 Security updates need testing:
Age URL
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-3d9a822df5 rust-pore-0.1.8-5.el9
The following builds have been pushed to Fedora EPEL 9 updates-testing
chromium-120.0.6099.62-2.el9
initoverlayfs-0.98-1.el9
java-latest-openjdk-21.0.1.0.12-1.rolling.el9
libssh2-1.11.0-1.el9
netdata-1.44.0-1.el9
python-awscrt-0.19.19-2.el9
qt-creator-8.0.2-2.el9
rust-once_cell-1.19.0-1.el9
wordpress-6.4.2-1.el9
Details about builds:
================================================================================
chromium-120.0.6099.62-2.el9 (FEDORA-EPEL-2023-8d617060ef)
A WebKit (Blink) powered web browser that Google doesn't want you to use
--------------------------------------------------------------------------------
Update Information:
Update to 120.0.6099.62, upstream release fixes follow security issues: * High
CVE-2023-6508: Use after free in Media Stream * High CVE-2023-6509: Use after
free in Side Panel Search * Medium CVE-2023-6510: Use after free in Media
Capture * Low CVE-2023-6511: Inappropriate implementation in Autofill * Low
CVE-2023-6512: Inappropriate implementation in Web Browser UI ---- update to
119.0.6045.199, upstream security release * High CVE-2023-6348: Type Confusion
in Spellcheck * High CVE-2023-6347: Use after free in Mojo * High CVE-2023-6346:
Use after free in WebAudio * High CVE-2023-6350: Out of bounds memory access in
libavif * High CVE-2023-6351: Use after free in libavif * High CVE-2023-6345:
Integer overflow in Skia
--------------------------------------------------------------------------------
ChangeLog:
* Wed Dec 6 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.62-2
- drop unsupported ldflag which caused build failure
* Tue Dec 5 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.62-1
- update to 120.0.6099.62
- fixed bz#2252874, built with control flow integrity (CFI) support
* Sat Dec 2 2023 Than Ngo <than(a)redhat.com> - 120.0.6099.56-1
- update to 120.0.6099.56
- enable qt6 UI backend
* Sat Dec 2 2023 Than Ngo <than(a)redhat.com> - 119.0.6045.199-2
- fixed bz#2242271, built with bundleminizip in fedora > 39
- fixed bz#2251884, built with fstack-protector-strong for improved security
* Wed Nov 29 2023 Than Ngo <than(a)redhat.com> - 119.0.6045.199-1
- update to 119.0.6045.199
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2252009 - CVE-2023-6346 CVE-2023-6347 CVE-2023-6350 CVE-2023-6351 chromium: various flaws [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252009
[ 2 ] Bug #2252188 - CVE-2023-6345 chromium: chromium-browser: Integer overflow [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252188
[ 3 ] Bug #2252191 - CVE-2023-6348 chromium: chromium-browser: Type Confusion in Spellcheck [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2252191
[ 4 ] Bug #2253151 - CVE-2023-6508 chromium: Use after free in Media Stream [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253151
[ 5 ] Bug #2253154 - CVE-2023-6509 chromium: Use after free in Side Panel Search [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253154
[ 6 ] Bug #2253157 - CVE-2023-6510 chromium: Use after free in Media Capture [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253157
[ 7 ] Bug #2253161 - CVE-2023-6511 chromium: Inappropriate implementation in Autofill [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253161
[ 8 ] Bug #2253164 - CVE-2023-6512 chromium: Inappropriate implementation in Web Browser UI [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2253164
--------------------------------------------------------------------------------
================================================================================
initoverlayfs-0.98-1.el9 (FEDORA-EPEL-2023-6765518a30)
An initial scalable filesystem for Linux operating systems
--------------------------------------------------------------------------------
Update Information:
Release 0.98
--------------------------------------------------------------------------------
ChangeLog:
* Thu Dec 7 2023 Stephen Smoogen <ssmoogen(a)redhat.com> - 0.98-1
- Release 0.98
- Improve documentation (PR31 and ecurtin)
- Only wait for bootfs storage device if it is configured (PR32)
* Fri Nov 17 2023 Eric Curtin <ecurtin(a)redhat.com> - 0.97-1
- Raspberry Pi 4 enablement.
--------------------------------------------------------------------------------
================================================================================
java-latest-openjdk-21.0.1.0.12-1.rolling.el9 (FEDORA-EPEL-2023-f623b9081e)
OpenJDK 21 Runtime Environment
--------------------------------------------------------------------------------
Update Information:
updated to octrober cpu
--------------------------------------------------------------------------------
ChangeLog:
* Wed Nov 22 2023 Jiri Vanek <jvanek(a)redhat.com> - 1:21.0.1.0.12-1.rolling
- updated to OpenJDK 21.0.1 (2023-10-17)
* Fri Sep 29 2023 Yaakov Selkowitz <yselkowi(a)redhat.com> - 1:21.0.0.0.35-3.rolling
- Fix flatpak build by handling different installation prefixes of package dependencies
* Tue Sep 19 2023 Jiri Vanek <jvanek(a)redhat.com> - 1:21.0.0.0.35-2.rolling
- adapted to new path in sources
- repacked alt-java from misc subpkg
- adapted alt-java to grep correctly prctl
- removed no longer prepared nss.cfg
* Tue Aug 29 2023 Jiri Vanek <jvanek(a)redhat.com> - 1:21.0.0.0.35-1.rolling
- updated to jdk 21
--------------------------------------------------------------------------------
================================================================================
libssh2-1.11.0-1.el9 (FEDORA-EPEL-2023-1b67b5f664)
A library implementing the SSH2 protocol
--------------------------------------------------------------------------------
Update Information:
This is an update to the current upstream release version, with a number of
enhancements including Ed25519, ETM-MAC and AES-GCM support.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jun 1 2023 Paul Howarth <paul(a)city-fan.org> - 1.11.0-1
- Update to 1.11.0 (rhbz#2211200)
- Adds support for encrypt-then-mac (ETM) MACs
- Adds support for AES-GCM crypto protocols
- Adds support for sk-ecdsa-sha2-nistp256 and sk-ssh-ed25519 keys
- Adds support for RSA certificate authentication
- Adds FIDO support with *_sk() functions
- Adds RSA-SHA2 key upgrading to OpenSSL, WinCNG, mbedTLS, OS400 backends
- Adds Agent Forwarding and libssh2_agent_sign()
- Adds support for Channel Signal message libssh2_channel_signal_ex()
- Adds support to get the user auth banner message libssh2_userauth_banner()
- Adds LIBSSH2_NO_{MD5, HMAC_RIPEMD, DSA, RSA, RSA_SHA1, ECDSA, ED25519,
AES_CBC, AES_CTR, BLOWFISH, RC4, CAST, 3DES} options
- Adds direct stream UNIX sockets with libssh2_channel_direct_streamlocal_ex()
- Adds wolfSSL support to CMake file
- Adds mbedTLS 3.x support
- Adds LibreSSL 3.5 support
- Adds support for CMake "unity" builds
- Adds CMake support for building shared and static libs in a single pass
- Adds symbol hiding support to CMake
- Adds support for libssh2.rc for all build tools
- Adds .zip, .tar.xz and .tar.bz2 release tarballs
- Enables ed25519 key support for LibreSSL 3.7.0 or higher
- Improves OpenSSL 1.1 and 3 compatibility
- Now requires OpenSSL 1.0.2 or newer
- Now requires CMake 3.1 or newer
- SFTP: Adds libssh2_sftp_open_ex_r() and libssh2_sftp_open_r() extended APIs
- SFTP: No longer has a packet limit when reading a directory
- SFTP: Now parses attribute extensions if they exist
- SFTP: No longer will busy loop if SFTP fails to initialize
- SFTP: Now clear various errors as expected
- SFTP: No longer skips files if the line buffer is too small
- SCP: Add option to not quote paths
- SCP: Enables 64-bit offset support unconditionally
- Now skips leading \r and \n characters in banner_receive()
- Enables secure memory zeroing with all build tools on all platforms
- No longer logs SSH_MSG_REQUEST_FAILURE packets from keepalive
- Speed up base64 encoding by 7x
- Assert if there is an attempt to write a value that is too large
- WinCNG: fix memory leak in _libssh2_dh_secret()
- Added protection against possible null pointer dereferences
- Agent now handles overly large comment lengths
- Now ensure KEX replies don't include extra bytes
- Fixed possible buffer overflow when receiving SSH_MSG_USERAUTH_BANNER
- Fixed possible buffer overflow in keyboard interactive code path
- Fixed overlapping memcpy()
- Fixed Windows UWP builds
- Fixed DLL import name
- Renamed local RANDOM_PADDING macro to avoid unexpected define on Windows
- Support for building with gcc versions older than 8
- Improvements to CMake, Makefile, NMakefile, GNUmakefile, autoreconf files
- Restores ANSI C89 compliance
- Enabled new compiler warnings and fixed/silenced them
- Improved error messages
- Now uses CIFuzz
- Numerous minor code improvements
- Improvements to CI builds
- Improvements to unit tests
- Improvements to doc files
- Improvements to example files
- Removed "old gex" build option
- Removed no-encryption/no-mac builds
- Removed support for NetWare and Watcom wmake build files
- Avoid use of deprecated patch syntax
- Build static library but don't package it since it's required for the
test suite (https://github.com/libssh2/libssh2/issues/1056)
- Remove redundant references to %{_libdir} from pkgconfig file
- Add patch to work around strict permissions issues for sshd tests
* Thu Jan 19 2023 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.10.0-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Fri Oct 28 2022 Todd Zullinger <tmz(a)pobox.com> - 1.10.0-6
- Verify upstream release signatures
* Thu Jul 21 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.10.0-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Sun Jan 23 2022 Paul Howarth <paul(a)city-fan.org> - 1.10.0-4
- In 8.8 OpenSSH disabled sha1 rsa-sha keys out of the box,
so we need to re-enable them as a workaround for the test
suite until upstream updates the tests
See: https://github.com/libssh2/libssh2/issues/630
- Drop other test workarounds, none of them being needed any longer
* Thu Jan 20 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.10.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Tue Sep 14 2021 Sahana Prasad <sahana(a)redhat.com> - 1.10.0-2
- Rebuilt with OpenSSL 3.0.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2253412 - Please rebase libssh2 in EPEL 9 to 1.11.0
https://bugzilla.redhat.com/show_bug.cgi?id=2253412
--------------------------------------------------------------------------------
================================================================================
netdata-1.44.0-1.el9 (FEDORA-EPEL-2023-c76dcf8d1f)
Real-time performance monitoring
--------------------------------------------------------------------------------
Update Information:
Update from upstream
--------------------------------------------------------------------------------
ChangeLog:
* Thu Dec 7 2023 Didier Fabert <didier.fabert(a)gmail.com> 1.44.0-1
- Update from upstream
--------------------------------------------------------------------------------
================================================================================
python-awscrt-0.19.19-2.el9 (FEDORA-EPEL-2023-910ad77450)
Python bindings for the AWS Common Runtime
--------------------------------------------------------------------------------
Update Information:
Update for python-awscrt-0.19.19-2.el9. ##### **Changelog for python-awscrt**
``` * Wed Dec 06 2023 Nikola Forr�� <nforro(a)redhat.com> - 0.19.19-2 - Add Packit
config * Thu Nov 30 2023 Packit <hello(a)packit.dev> - 0.19.19-1 - [packit]
0.19.19 upstream release - Resolves rhbz#2250726 * Fri Nov 17 2023 Packit
<hello(a)packit.dev> - 0.19.13-1 - [packit] 0.19.13 upstream release - Resolves
rhbz#2247105 * Wed Oct 25 2023 Packit <hello(a)packit.dev> - 0.19.6-1 - [packit]
0.19.6 upstream release - Resolves rhbz#2211521 Upstream tag: v0.19.6 Upstream
commit: b83949d0 * Mon Oct 16 2023 Packit <hello(a)packit.dev> - 0.19.3-1 -
[packit] 0.19.3 upstream release * Mon Oct 02 2023 Packit <hello(a)packit.dev> -
0.19.2-1 - [packit] 0.19.2 upstream release ```
--------------------------------------------------------------------------------
ChangeLog:
* Wed Dec 6 2023 Nikola Forr�� <nforro(a)redhat.com> - 0.19.19-2
- Add Packit config
* Thu Nov 30 2023 Packit <hello(a)packit.dev> - 0.19.19-1
- [packit] 0.19.19 upstream release
- Resolves rhbz#2250726
* Fri Nov 17 2023 Packit <hello(a)packit.dev> - 0.19.13-1
- [packit] 0.19.13 upstream release
- Resolves rhbz#2247105
* Wed Oct 25 2023 Packit <hello(a)packit.dev> - 0.19.6-1
- [packit] 0.19.6 upstream release
- Resolves rhbz#2211521 Upstream tag: v0.19.6 Upstream commit: b83949d0
* Mon Oct 16 2023 Packit <hello(a)packit.dev> - 0.19.3-1
- [packit] 0.19.3 upstream release
* Mon Oct 2 2023 Packit <hello(a)packit.dev> - 0.19.2-1
- [packit] 0.19.2 upstream release
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2250726 - python-awscrt-0.19.19 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2250726
--------------------------------------------------------------------------------
================================================================================
qt-creator-8.0.2-2.el9 (FEDORA-EPEL-2023-4f4cc2f9b2)
Cross-platform IDE for Qt
--------------------------------------------------------------------------------
Update Information:
Update to version 8.0.2
--------------------------------------------------------------------------------
ChangeLog:
* Thu Dec 7 2023 Thomas Zimmermann <thomas.zimmermann(a)voestalpine.com> - 8.0.2-1
- Update to Version 8.0.2
- Unbundle clang
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2102604 - qt-creator requires rebuild due to clang-libs update 14.0.5
https://bugzilla.redhat.com/show_bug.cgi?id=2102604
[ 2 ] Bug #2253404 - Request to rebuild qt-creator for RHEL 9.3
https://bugzilla.redhat.com/show_bug.cgi?id=2253404
--------------------------------------------------------------------------------
================================================================================
rust-once_cell-1.19.0-1.el9 (FEDORA-EPEL-2023-cbc8151b4a)
Single assignment cells and lazy values
--------------------------------------------------------------------------------
Update Information:
Update to version 1.19.0.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Dec 7 2023 Jan Stan��k <jstanek(a)redhat.com> - 1.19.0-1
- Update to version 1.19.0 (rhbz#2253436)
--------------------------------------------------------------------------------
================================================================================
wordpress-6.4.2-1.el9 (FEDORA-EPEL-2023-af4a7bbba9)
Blog tool and publishing platform
--------------------------------------------------------------------------------
Update Information:
**WordPress 6.4.2 Maintenance & Security Release** Security updates included in
this release * A Remote Code Execution vulnerability that is not directly
exploitable in core, however the security team feels that there is a potential
for high severity when combined with some plugins, especially in multisite
installs. See [Upstream
announcement](https://wordpress.org/news/2023/12/wordpress-6-4-2-maintenanc…
security-release/)
--------------------------------------------------------------------------------
ChangeLog:
* Thu Dec 7 2023 Remi Collet <remi(a)remirepo.net> - 6.4.2-1
- WordPress 6.4.2 Maintenance & Security Release
--------------------------------------------------------------------------------
The following Fedora EPEL 7 Security updates need testing:
Age URL
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-46696cc30b chromium-119.0.6045.199-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
wsdd-0.7.1-1.el7
Details about builds:
================================================================================
wsdd-0.7.1-1.el7 (FEDORA-EPEL-2023-4e7c9d636e)
Web Services Dynamic Discovery host daemon
--------------------------------------------------------------------------------
Update Information:
Latest upstream release. Includes https://src.fedoraproject.org/rpms/wsdd/pull-
request/1 .
--------------------------------------------------------------------------------
ChangeLog:
* Fri Oct 6 2023 Ondrej Holy <oholy(a)redhat.com> - 0.7.1-1
- Update to 0.7.1.
* Sat Jul 22 2023 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.7.0-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Sat Jan 21 2023 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.7.0-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Sat Jul 23 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.7.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Sat Jan 22 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.7.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
--------------------------------------------------------------------------------
The following Fedora EPEL 8 Security updates need testing:
Age URL
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-d47bce8e4e chromium-119.0.6045.199-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
java-latest-openjdk-portable-21.0.1.0.12-2.rolling.el8
root-6.30.02-1.el8
wsdd-0.7.1-1.el8
Details about builds:
================================================================================
java-latest-openjdk-portable-21.0.1.0.12-2.rolling.el8 (FEDORA-EPEL-2023-8ce17c621c)
OpenJDK 21 Runtime Environment portable edition
--------------------------------------------------------------------------------
Update Information:
updated to october CPU
--------------------------------------------------------------------------------
ChangeLog:
* Wed Nov 22 2023 Jiri Vanek <jvanek(a)redhat.com> - 1:21.0.1.0.12-2.rolling
- updated to OpenJDK 21.0.1 (2023-10-17)
- adjsuted generate_source_tarball
- removed icedtea_sync
- dropped standalone licenses
- added usntripped subpkg
- added docs subpkg
- adjsuted versions of bundled libraries
- build refactored to several solid methods following gnu_andrew
- removed no longer needed jdk8296108-tzdata2022f.patch, jdk8296715-cldr2022f.patch, rh1648644-java_access_bridge_privileged_security.patch
- added jdk8311630-s390_ffmapi.patch to support virtual threads on s390x
- aligned fips-21u-75ffdc48eda.patch (gnu_andrew)
- fixed '--without release' build-ability by moving docs and misc to if-release only
* Wed Sep 20 2023 Jiri Vanek <jvanek(a)redhat.com> - 1:21.0.0.0.35-4.rolling
- removed %{1} from miscportablename
* Fri Sep 15 2023 Andrew Hughes <gnu.andrew(a)redhat.com> - 1:21.0.0.0.35-3.rolling
- Update documentation (README.md, add missing JEP to release notes)
- Replace alt-java patch with a binary separate from the JDK
- Drop stale patches that are of little use any more:
- * nss.cfg has been disabled since early PKCS11 work and long superseded by FIPS work
- * No accessibility subpackage to warrant RH1648242 patch any more
- * No use of system libjpeg turbo to warrant RH649512 patch any more
- Replace RH1684077 pcsc-lite-libs patch with better JDK-8009550 fix being upstreamed
- Update generate_tarball.sh to sync with upstream vanilla script
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Use upstream release URL for OpenJDK source
- Port misc tarball from RHEL to house alt-java outside the JDK tree
- Port improved tarball creation and checking from RHEL so tarballs are verified
* Thu Sep 14 2023 Andrew Hughes <gnu.andrew(a)redhat.com> - 1:21.0.0.0.35-2.rolling
- Bump buildjdkver now that java-21-openjdk is available in the buildroot
* Tue Aug 8 2023 Petra Alice Mikova <pmikova(a)redhat.com> 1:21.0.0.0.35-1.rolling
- updated to jdk-21+35, which is no longer EA
* Tue Aug 8 2023 Petra Alice Mikova <pmikova(a)redhat.com> 1:21.0.0.0.34-0.1.ea.rolling
- initial update to jdk21
- commented out fips patches
- updated to jdk21 ea
- updated patch 1001 - rh1648249-add_commented_out_nss_cfg_provider_to_java_security
- replace smoketests in staticlibs test, as the previous files used were removed by a patch in JDK
- require tzdata 2023c
- Update FIPS support to bring in latest changes
- * RH2048582: Support PKCS#12 keystores
- * RH2020290: Support TLS 1.3 in FIPS mode
- * Add nss.fips.cfg support to OpenJDK tree
- * RH2117972: Extend the support for NSS DBs (PKCS11) in FIPS mode
- * Remove forgotten dead code from RH2020290 and RH2104724
- * OJ1357: Fix issue on FIPS with a SecurityManager in place
- * RH2134669: Add missing attributes when registering services in FIPS mode.
- * test/jdk/sun/security/pkcs11/fips/VerifyMissingAttributes.java: fixed jtreg main class
- * RH1940064: Enable XML Signature provider in FIPS mode
- * Remove GCC minor versioning (JDK-8284772) to unbreak testing
- Drop local nss.fips.cfg.in handling now this is handled in the patched OpenJDK build
--------------------------------------------------------------------------------
================================================================================
root-6.30.02-1.el8 (FEDORA-EPEL-2023-5cf6b377b2)
Numerical data analysis framework
--------------------------------------------------------------------------------
Update Information:
ROOT 6.30.02
--------------------------------------------------------------------------------
ChangeLog:
* Sat Dec 2 2023 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 6.30.02-1
- Update to 6.30.02
--------------------------------------------------------------------------------
================================================================================
wsdd-0.7.1-1.el8 (FEDORA-EPEL-2023-e43ee1ef96)
Web Services Dynamic Discovery host daemon
--------------------------------------------------------------------------------
Update Information:
Latest upstream release. Includes https://src.fedoraproject.org/rpms/wsdd/pull-
request/1 .
--------------------------------------------------------------------------------
ChangeLog:
* Fri Oct 6 2023 Ondrej Holy <oholy(a)redhat.com> - 0.7.1-1
- Update to 0.7.1.
* Sat Jul 22 2023 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.7.0-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Sat Jan 21 2023 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.7.0-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Sat Jul 23 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.7.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Sat Jan 22 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.7.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
--------------------------------------------------------------------------------
The following Fedora EPEL 9 Security updates need testing:
Age URL
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-2537ccf8b5 chromium-119.0.6045.199-1.el9
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-3d9a822df5 rust-pore-0.1.8-5.el9
The following builds have been pushed to Fedora EPEL 9 updates-testing
bluechi-0.6.0-1.el9
java-latest-openjdk-portable-21.0.1.0.12-2.rolling.el9
nickle-2.96-1.el9
python-google-auth-2.25.1-1.el9
root-6.30.02-1.el9
snakeyaml-1.33-1.el9
wsdd-0.7.1-1.el9
Details about builds:
================================================================================
bluechi-0.6.0-1.el9 (FEDORA-EPEL-2023-73c4c9c7aa)
A systemd service controller for multi-nodes environments
--------------------------------------------------------------------------------
Update Information:
Version 0.6.0 includes the following changes and updates: - Renamed bluechi to
bluechi-controller for binary, rpm and documentation - Moved bluechi binaries
to /usr/libexec for auto-completion - Added properties and signals for
connection status and disconnected timestamp to Agent's public API - Removed
duplicate NodeConnectionStateChanged signal from bluechi-controller - CLI
option for the version (-v) prints version and git commit hash for non-release
builds - Extended BlueChi's public D-Bus API specification by inline-comments
- Added EmitsChangedSignal annotation to properties in BlueChi's public D-Bus
API specification - Enhanced typed python bindings generator to use inline-
comments from specification - Enhanced typed python bindings generator to
provide listener functions for property changed signals - Fixes in the D-Bus
API description - Improved error messages returned by D-Bus API - Added static
code analysis from gcc and fixed detected issues - Added a graceful node
shutdown in bluechi-controller - Fixed a few smaller memory leaks - Fixed bug
where configured manager address was overridden on connection failure - Fixed
bug where removing a subscription was not prevented - Fixed race condition
leading bluechi-proxy and bluechi-dep service to transition into failed state -
Aligned and added API examples for Python, Go and Rust - Changed the license
for python bindings to MIT-0
--------------------------------------------------------------------------------
ChangeLog:
* Wed Nov 29 2023 Michael Engel <mengel(a)redhat.com> - 0.6.0-1
- Update to 0.6.0
- Rename bluechi package to controller
--------------------------------------------------------------------------------
================================================================================
java-latest-openjdk-portable-21.0.1.0.12-2.rolling.el9 (FEDORA-EPEL-2023-a52c6ecf48)
OpenJDK 21 Runtime Environment portable edition
--------------------------------------------------------------------------------
Update Information:
updated to october CPU
--------------------------------------------------------------------------------
ChangeLog:
* Wed Nov 22 2023 Jiri Vanek <jvanek(a)redhat.com> - 1:21.0.1.0.12-2.rolling
- updated to OpenJDK 21.0.1 (2023-10-17)
- adjsuted generate_source_tarball
- removed icedtea_sync
- dropped standalone licenses
- added usntripped subpkg
- added docs subpkg
- adjsuted versions of bundled libraries
- build refactored to several solid methods following gnu_andrew
- removed no longer needed jdk8296108-tzdata2022f.patch, jdk8296715-cldr2022f.patch, rh1648644-java_access_bridge_privileged_security.patch
- added jdk8311630-s390_ffmapi.patch to support virtual threads on s390x
- aligned fips-21u-75ffdc48eda.patch (gnu_andrew)
- fixed '--without release' build-ability by moving docs and misc to if-release only
* Wed Sep 20 2023 Jiri Vanek <jvanek(a)redhat.com> - 1:21.0.0.0.35-4.rolling
- removed %{1} from miscportablename
* Fri Sep 15 2023 Andrew Hughes <gnu.andrew(a)redhat.com> - 1:21.0.0.0.35-3.rolling
- Update documentation (README.md, add missing JEP to release notes)
- Replace alt-java patch with a binary separate from the JDK
- Drop stale patches that are of little use any more:
- * nss.cfg has been disabled since early PKCS11 work and long superseded by FIPS work
- * No accessibility subpackage to warrant RH1648242 patch any more
- * No use of system libjpeg turbo to warrant RH649512 patch any more
- Replace RH1684077 pcsc-lite-libs patch with better JDK-8009550 fix being upstreamed
- Update generate_tarball.sh to sync with upstream vanilla script
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Use upstream release URL for OpenJDK source
- Port misc tarball from RHEL to house alt-java outside the JDK tree
- Port improved tarball creation and checking from RHEL so tarballs are verified
* Thu Sep 14 2023 Andrew Hughes <gnu.andrew(a)redhat.com> - 1:21.0.0.0.35-2.rolling
- Bump buildjdkver now that java-21-openjdk is available in the buildroot
* Tue Aug 8 2023 Petra Alice Mikova <pmikova(a)redhat.com> 1:21.0.0.0.35-1.rolling
- updated to jdk-21+35, which is no longer EA
* Tue Aug 8 2023 Petra Alice Mikova <pmikova(a)redhat.com> 1:21.0.0.0.34-0.1.ea.rolling
- initial update to jdk21
- commented out fips patches
- updated to jdk21 ea
- updated patch 1001 - rh1648249-add_commented_out_nss_cfg_provider_to_java_security
- replace smoketests in staticlibs test, as the previous files used were removed by a patch in JDK
- require tzdata 2023c
- Update FIPS support to bring in latest changes
- * RH2048582: Support PKCS#12 keystores
- * RH2020290: Support TLS 1.3 in FIPS mode
- * Add nss.fips.cfg support to OpenJDK tree
- * RH2117972: Extend the support for NSS DBs (PKCS11) in FIPS mode
- * Remove forgotten dead code from RH2020290 and RH2104724
- * OJ1357: Fix issue on FIPS with a SecurityManager in place
- * RH2134669: Add missing attributes when registering services in FIPS mode.
- * test/jdk/sun/security/pkcs11/fips/VerifyMissingAttributes.java: fixed jtreg main class
- * RH1940064: Enable XML Signature provider in FIPS mode
- * Remove GCC minor versioning (JDK-8284772) to unbreak testing
- Drop local nss.fips.cfg.in handling now this is handled in the patched OpenJDK build
--------------------------------------------------------------------------------
================================================================================
nickle-2.96-1.el9 (FEDORA-EPEL-2023-ce4a3d610e)
A programming language-based prototyping environment
--------------------------------------------------------------------------------
Update Information:
Update to latest `nickle` release nickle (2.96) unstable; urgency=medium *
Fix LDFLAGS in debian package. -- Keith Packard <keithp(a)keithp.com> Sat, 02
Dec 2023 22:21:27 -0800 nickle (2.95) unstable; urgency=medium * Handle
empty objects and arrays in JSON input * Initialize SymbolLocal code member in
allocator to prevent fault when GC runs before correct value is set. --
Keith Packard <keithp(a)keithp.com> Sat, 02 Dec 2023 12:52:05 -0800 nickle
(2.94) unstable; urgency=medium * Add true/false/null support to json.5c *
Add file input/output to json.5c -- Keith Packard <keithp(a)keithp.com> Thu, 30
Nov 2023 12:13:48 -0800
--------------------------------------------------------------------------------
ChangeLog:
* Tue Dec 5 2023 Michel Lind <salimma(a)fedoraproject.org> - 2.96-1
- Update to 2.96
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2252324 - nickle-2.96 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2252324
--------------------------------------------------------------------------------
================================================================================
python-google-auth-2.25.1-1.el9 (FEDORA-EPEL-2023-27d28fb954)
Google Auth Python Library
--------------------------------------------------------------------------------
Update Information:
Update python-google-auth to 2.25
--------------------------------------------------------------------------------
ChangeLog:
* Wed Dec 6 2023 Fedora Release Monitoring <release-monitoring(a)fedoraproject.org> - 1:2.25.1-1
- Update to 2.25.1 (#2252361)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2252361 - python-google-auth-2.25.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2252361
--------------------------------------------------------------------------------
================================================================================
root-6.30.02-1.el9 (FEDORA-EPEL-2023-b71d101c25)
Numerical data analysis framework
--------------------------------------------------------------------------------
Update Information:
ROOT 6.30.02
--------------------------------------------------------------------------------
ChangeLog:
* Sat Dec 2 2023 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 6.30.02-1
- Update to 6.30.02
--------------------------------------------------------------------------------
================================================================================
snakeyaml-1.33-1.el9 (FEDORA-EPEL-2023-a7a7801f83)
YAML parser and emitter for Java
--------------------------------------------------------------------------------
Update Information:
Updated to upstream 1.33 release.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Nov 23 2023 Stefan Bluhm <stefan.bluhm(a)clacee.eu> - 1.33-1
- Updated to upstream 1.33 release.
* Sat Jul 22 2023 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.32-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Sat Jan 21 2023 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.32-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
wsdd-0.7.1-1.el9 (FEDORA-EPEL-2023-c9101e8a4b)
Web Services Dynamic Discovery host daemon
--------------------------------------------------------------------------------
Update Information:
Latest upstream release. Includes https://src.fedoraproject.org/rpms/wsdd/pull-
request/1 .
--------------------------------------------------------------------------------
ChangeLog:
* Fri Oct 6 2023 Ondrej Holy <oholy(a)redhat.com> - 0.7.1-1
- Update to 0.7.1.
* Sat Jul 22 2023 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.7.0-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Sat Jan 21 2023 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.7.0-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
--------------------------------------------------------------------------------
This email proposes upgrading the llhttp package in EPEL9 from 6.0.10 to
8.1.1, which would break the ABI and bump the SONAME version, under the
EPEL Incompatible Upgrades Policy[1].
The llhttp package is a C library (transpiled from TypeScript) that
provides the low-level HTTP support for NodeJS and for python-aiohttp.
Currently, only python-aiohttp depends on the llhttp package in EPEL9.
Versions of llhttp prior to 8.1.1 are affected by CVE-2023-30589[2], an
HTTP request smuggling vulnerability rated 7.7 HIGH in CVSS v3 and rated
Moderate by Red Hat. The GitHub advisory for llhttp is
GHSA-cggh-pq45-6h9x[3]; the advisory for python-aiohttp is
GHSA-45c4-8wx5-qw6w[4]. Upstream for python-aiohttp fixed this by
updating llhttp (which they bundle, but we unbundle) in release 3.8.5.
I am not comfortable attempting to backport the fix to an older release
of llhttp. My preferred solution would be to update llhttp to 8.1.1[5]
and (in the same side tag) update python-aiohttp to 3.8.5[6]. The ABI
break in llhttp would only affect python-aiohttp; the python-aiohttp
update itself is compatible (by upstream intent, and verified in
COPR[7]); and a number of packages that depend on python-aiohttp would
benefit from the fix.
If this exception request is not approved, my fallback plan is to
propose rebuilding python-aiohttp in EPEL9 with AIOHTTP_NO_EXTENSIONS=1,
which would convert it to a pure-Python package. This is a documented
mitigation, but comes with potentially serious performance regressions,
again affecting a number of dependent packages. The llhttp package would
become a leaf package and would remain unpatched.
The same incompatible update was approved by FESCo for Fedora 37[8].
The purpose of this email is to document and explain the proposed
update, to begin the minimum one-week discussion period mandated by the
EPEL Incompatible Upgrades Policy, and to request that the update be
added to the agenda for an upcoming EPEL meeting.
[1]
https://docs.fedoraproject.org/en-US/epel/epel-policy-incompatible-upgrades…
[2] https://access.redhat.com/security/cve/CVE-2023-30589
[3] https://github.com/advisories/GHSA-cggh-pq45-6h9x
[4]
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-45c4-8wx5-qw6w
[5] https://src.fedoraproject.org/rpms/llhttp/pull-request/14
[6] https://src.fedoraproject.org/rpms/python-aiohttp/pull-request/26
[7] https://copr.fedorainfracloud.org/coprs/music/aiohttp-epel9/packages/
[8] https://pagure.io/fesco/issue/3049
The following Fedora EPEL 8 Security updates need testing:
Age URL
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-d47bce8e4e chromium-119.0.6045.199-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
R-qtl-1.66-1.el8
mold-2.4.0-1.el8
xrootd-5.6.3-3.el8
Details about builds:
================================================================================
R-qtl-1.66-1.el8 (FEDORA-EPEL-2023-08d01052dd)
Tools for analyzing QTL experiments
--------------------------------------------------------------------------------
Update Information:
R qtl 1.66
--------------------------------------------------------------------------------
ChangeLog:
* Tue Dec 5 2023 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 1.66-1
- Update to 1.66
--------------------------------------------------------------------------------
================================================================================
mold-2.4.0-1.el8 (FEDORA-EPEL-2023-d4e203f499)
A Modern Linker
--------------------------------------------------------------------------------
Update Information:
Bump version to 2.4.0 (rhbz#2252444)
--------------------------------------------------------------------------------
ChangeLog:
* Sun Dec 3 2023 Christoph Erhardt <fedora(a)sicherha.de> - 2.4.0-1
- Bump version to 2.4.0 (rhbz#2252444)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2252444 - mold-2.4.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2252444
--------------------------------------------------------------------------------
================================================================================
xrootd-5.6.3-3.el8 (FEDORA-EPEL-2023-13916936b1)
Extended ROOT file server
--------------------------------------------------------------------------------
Update Information:
Fix include path in XRootDConfig.cmake Support big endian in XrdZip
--------------------------------------------------------------------------------
ChangeLog:
* Tue Dec 5 2023 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 1:5.6.3-3
- Avoid /tmp when running some tests
- Fail gracefully in case of unsupported extended file attributes
- Avoid null bytes in error message strings
- Fix include path in XRootDConfig.cmake
- Avoid dereferencing unaligned pointers
- Support big endian in XrdZip
--------------------------------------------------------------------------------
The following Fedora EPEL 7 Security updates need testing:
Age URL
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-46696cc30b chromium-119.0.6045.199-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
R-qtl-1.66-1.el7
xrootd-5.6.3-3.el7
Details about builds:
================================================================================
R-qtl-1.66-1.el7 (FEDORA-EPEL-2023-d0bbb14250)
Tools for analyzing QTL experiments
--------------------------------------------------------------------------------
Update Information:
R qtl 1.66
--------------------------------------------------------------------------------
ChangeLog:
* Tue Dec 5 2023 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 1.66-1
- Update to 1.66
--------------------------------------------------------------------------------
================================================================================
xrootd-5.6.3-3.el7 (FEDORA-EPEL-2023-6d102dc0c0)
Extended ROOT file server
--------------------------------------------------------------------------------
Update Information:
Fix include path in XRootDConfig.cmake Support big endian in XrdZip
--------------------------------------------------------------------------------
ChangeLog:
* Tue Dec 5 2023 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 1:5.6.3-3
- Avoid /tmp when running some tests
- Fail gracefully in case of unsupported extended file attributes
- Avoid null bytes in error message strings
- Fix include path in XRootDConfig.cmake
- Avoid dereferencing unaligned pointers
- Support big endian in XrdZip
--------------------------------------------------------------------------------
The following Fedora EPEL 9 Security updates need testing:
Age URL
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-2537ccf8b5 chromium-119.0.6045.199-1.el9
4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-3d9a822df5 rust-pore-0.1.8-5.el9
The following builds have been pushed to Fedora EPEL 9 updates-testing
R-qtl-1.66-1.el9
mlmmj-1.3.0-17.el9
mold-2.4.0-1.el9
rust-cargo-c-0.9.27-2.el9
rust-rav1e-0.6.6-3.el9
rust-snap-1.1.1-1.el9
rust-szip-1.0.0-3.el9
vecgeom-1.2.6-1.el9
xrootd-5.6.3-3.el9
Details about builds:
================================================================================
R-qtl-1.66-1.el9 (FEDORA-EPEL-2023-d58ec8b56f)
Tools for analyzing QTL experiments
--------------------------------------------------------------------------------
Update Information:
R qtl 1.66
--------------------------------------------------------------------------------
ChangeLog:
* Tue Dec 5 2023 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 1.66-1
- Update to 1.66
--------------------------------------------------------------------------------
================================================================================
mlmmj-1.3.0-17.el9 (FEDORA-EPEL-2023-762cf6a987)
A simple and slim mailing list manager inspired by ezmlm
--------------------------------------------------------------------------------
Update Information:
Add user/group assignment and SELinux enforcement support
--------------------------------------------------------------------------------
ChangeLog:
* Mon Dec 4 2023 Denis Fateyev <denis(a)fateyev.com> - 1.3.0-17
- Add system user and group assignment
- Add initial SELinux support
* Thu Jul 20 2023 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.3.0-16
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Thu Jan 19 2023 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.3.0-15
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2238004 - SELinux policy does not exist for mlmmj: cannot run on any enforcing machine
https://bugzilla.redhat.com/show_bug.cgi?id=2238004
--------------------------------------------------------------------------------
================================================================================
mold-2.4.0-1.el9 (FEDORA-EPEL-2023-0fa02b2478)
A Modern Linker
--------------------------------------------------------------------------------
Update Information:
Bump version to 2.4.0 (rhbz#2252444)
--------------------------------------------------------------------------------
ChangeLog:
* Sun Dec 3 2023 Christoph Erhardt <fedora(a)sicherha.de> - 2.4.0-1
- Bump version to 2.4.0 (rhbz#2252444)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2252444 - mold-2.4.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2252444
--------------------------------------------------------------------------------
================================================================================
rust-cargo-c-0.9.27-2.el9 (FEDORA-EPEL-2023-f5fb6283e1)
Helper program to build and install c-like libraries
--------------------------------------------------------------------------------
Update Information:
- Backport an upstream change in cargo-c to support configuring library soname.
- Adapt rav1e to cargo-c v0.9.26+ by configuring the soname manually for
backwards compatibility.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Dec 5 2023 Fabio Valentini <decathorpe(a)gmail.com> - 0.9.27-2
- Backport upstream change to add the version_suffix_components setting
--------------------------------------------------------------------------------
================================================================================
rust-rav1e-0.6.6-3.el9 (FEDORA-EPEL-2023-f5fb6283e1)
Fastest and safest AV1 encoder
--------------------------------------------------------------------------------
Update Information:
- Backport an upstream change in cargo-c to support configuring library soname.
- Adapt rav1e to cargo-c v0.9.26+ by configuring the soname manually for
backwards compatibility.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Dec 5 2023 Fabio Valentini <decathorpe(a)gmail.com> - 0.6.6-3
- Compatibility fixes for cargo-c v0.9.26 and newer
* Tue Dec 5 2023 Fabio Valentini <decathorpe(a)gmail.com> - 0.6.6-2
- Migrate to new cargo_cbuild and cargo_cinstall macros
--------------------------------------------------------------------------------
================================================================================
rust-snap-1.1.1-1.el9 (FEDORA-EPEL-2023-5d30c9201a)
Pure Rust implementation of the Snappy compression algorithm
--------------------------------------------------------------------------------
Update Information:
Fixes a reborrow UB violation in the `snap` crate under the Tree Borrows model.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Dec 5 2023 Benjamin A. Beasley <code(a)musicinmybrain.net> - 1.1.1-1
- Update to 1.1.1 (close RHBZ#2252979)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2252979 - rust-snap-1.1.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2252979
--------------------------------------------------------------------------------
================================================================================
rust-szip-1.0.0-3.el9 (FEDORA-EPEL-2023-5d30c9201a)
Fast command line tool for snappy compression and decompression
--------------------------------------------------------------------------------
Update Information:
Fixes a reborrow UB violation in the `snap` crate under the Tree Borrows model.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Dec 5 2023 Benjamin A. Beasley <code(a)musicinmybrain.net> - 1.0.0-3
- Rebuilt for rust-snap 1.1.1
* Tue Dec 5 2023 Benjamin A. Beasley <code(a)musicinmybrain.net> - 1.0.0-2
- Rebuilt for rust-snap 1.1.1
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2252979 - rust-snap-1.1.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2252979
--------------------------------------------------------------------------------
================================================================================
vecgeom-1.2.6-1.el9 (FEDORA-EPEL-2023-a05060a2cc)
A vectorized geometry library for particle-detector simulation
--------------------------------------------------------------------------------
Update Information:
initial import
--------------------------------------------------------------------------------
ChangeLog:
* Mon Dec 4 2023 topazus <topazus(a)outlook.com> - 1.2.6-1
- initial import; rhbz#2225004
--------------------------------------------------------------------------------
================================================================================
xrootd-5.6.3-3.el9 (FEDORA-EPEL-2023-933f0a3c26)
Extended ROOT file server
--------------------------------------------------------------------------------
Update Information:
Fix include path in XRootDConfig.cmake Support big endian in XrdZip
--------------------------------------------------------------------------------
ChangeLog:
* Tue Dec 5 2023 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 1:5.6.3-3
- Avoid /tmp when running some tests
- Fail gracefully in case of unsupported extended file attributes
- Avoid null bytes in error message strings
- Fix include path in XRootDConfig.cmake
- Avoid dereferencing unaligned pointers
- Support big endian in XrdZip
--------------------------------------------------------------------------------
The following Fedora EPEL 8 Security updates need testing:
Age URL
4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-d47bce8e4e chromium-119.0.6045.199-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
calceph-3.5.4-1.el8
python-calcephpy-3.5.4-1.el8
Details about builds:
================================================================================
calceph-3.5.4-1.el8 (FEDORA-EPEL-2023-08078cf99d)
Astronomical library to access planetary ephemeris files
--------------------------------------------------------------------------------
Update Information:
Update to 3.5.4
--------------------------------------------------------------------------------
ChangeLog:
* Sun Dec 3 2023 Mattia Verga <mattia.verga(a)proton.me> - 3.5.4-1
- Update to 3.5.4 (fedora#2252402)
--------------------------------------------------------------------------------
================================================================================
python-calcephpy-3.5.4-1.el8 (FEDORA-EPEL-2023-08078cf99d)
Astronomical library to access planetary ephemeris files
--------------------------------------------------------------------------------
Update Information:
Update to 3.5.4
--------------------------------------------------------------------------------
ChangeLog:
* Sun Dec 3 2023 Mattia Verga <mattia.verga(a)protonm.me> - 3.5.4-1
- Update to 3.5.4 (fedora#2252667)
--------------------------------------------------------------------------------