--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2018-915602df63
2018-08-31 20:02:40.219592
--------------------------------------------------------------------------------
Name : xen
Product : Fedora 27
Version : 4.9.2
Release : 7.fc27
URL : http://xen.org/
Summary : Xen is a virtual machine monitor
Description :
This package contains the XenD daemon and xm command line
tools, needed to manage virtual machines running under the
Xen hypervisor
--------------------------------------------------------------------------------
Update Information:
L1 Terminal Fault speculative side channel patch bundle [XSA-273, CVE-2018-3620,
CVE-2018-3646] drop patches also in the bundle, which also includes Use of v2
grant tables may cause crash on ARM [XSA-268] (#1616081) x86: Incorrect
MSR_DEBUGCTL handling lets guests enable BTS [XSA-269] (#1616077) oxenstored
does not apply quota-maxentity [XSA-272] (#1616080)
--------------------------------------------------------------------------------
ChangeLog:
* Wed Aug 15 2018 Michael Young <m.a.young(a)durham.ac.uk> - 4.9.2-7
- L1 Terminal Fault speculative side channel patch bundle [XSA-273,
CVE-2018-3620, CVE-2018-3646]
drop patches also in the bundle, which also includes
Use of v2 grant tables may cause crash on ARM [XSA-268] (#1616081)
x86: Incorrect MSR_DEBUGCTL handling lets guests enable BTS [XSA-269]
(#1616077)
oxenstored does not apply quota-maxentity [XSA-272] (#1616080)
* Wed Jun 27 2018 Michael Young <m.a.young(a)durham.ac.uk> - 4.9.2-6
- preemption checks bypassed in x86 PV MM handling [XSA-264, CVE-2018-12891]
(#1595959)
- x86: #DB exception safety check can be triggered by a guest [XSA-265,
CVE-2018-12893] (#1595958)
- libxl fails to honour readonly flag on HVM emulated SCSI disks [XSA-266,
CVE-2018-12892] (#1595957)
* Sat Jun 16 2018 Michael Young <m.a.young(a)durham.ac.uk> - 4.9.2-5
- Speculative register leakage from lazy FPU context switching
[XSA-267, CVE-2018-3665]
- fix for change in iasl output
* Tue May 22 2018 Michael Young <m.a.young(a)durham.ac.uk> - 4.9.2-4
- Speculative Store Bypass [XSA-263, CVE-2018-3639]
(with extra patches so it applies cleanly)
* Wed May 9 2018 Michael Young <m.a.young(a)durham.ac.uk> - 4.9.2-3
- x86: mishandling of debug exceptions [XSA-260, CVE-2018-8897]
(with extra patch so it applies cleanly)
- x86 vHPET interrupt injection errors [XSA-261, CVE-2018-10982] (#1576089)
- qemu may drive Xen into unbounded loop [XSA-262, CVE-2018-10981] (#1576680)
* Wed Apr 25 2018 Michael Young <m.a.young(a)durham.ac.uk> - 4.9.2-2
- Information leak via crafted user-supplied CDROM [XSA-258] (#1571867)
- x86: PV guest may crash Xen with XPTI [XSA-259] (#1571878)
* Wed Apr 4 2018 Michael Young <m.a.young(a)durham.ac.uk> - 4.9.2-1
- update to 4.9.2
adjust xen.use.fedora.ipxe.patch
remove patches for issues now fixed upstream
* Tue Feb 27 2018 Michael Young <m.a.young(a)durham.ac.uk> - 4.9.1-5
- add Xen page-table isolation (XPTI) mitigation
and Branch Target Injection (BTI) mitigation for XSA-254
- DoS via non-preemptable L3/L4 pagetable freeing [XSA-252, CVE-2018-7540]
(#1549568)
- grant table v2 -> v1 transition may crash Xen [XSA-255, CVE-2018-7541]
(#1549570)
- x86 PVH guest without LAPIC may DoS the host [XSA-256, CVE-2018-7542]
(#1549572)
* Tue Dec 12 2017 Michael Young <m.a.young(a)durham.ac.uk> - 4.9.1-4
- another patch related to the [XSA-240, CVE-2017-15595] issue
- xen: various flaws (#1525018)
x86 PV guests may gain access to internally used page
[XSA-248, CVE-2017-17566]
broken x86 shadow mode refcount overflow check [XSA-249, CVE-2017-17563]
improper x86 shadow mode refcount error handling [XSA-250, CVE-2017-17564]
improper bug check in x86 log-dirty handling [XSA-251, CVE-2017-17565]
* Sat Dec 2 2017 Richard W.M. Jones <rjones(a)redhat.com> - 4.9.1-3
- OCaml 4.06.0 rebuild.
* Tue Nov 28 2017 Michael Young <m.a.young(a)durham.ac.uk> - 4.9.1-2
- xen: various flaws (#1518214)
x86: infinite loop due to missing PoD error checking [XSA-246, CVE-2017-17044]
Missing p2m error checking in PoD code [XSA-247, CVE-2017-17045]
* Thu Nov 23 2017 Michael Young <m.a.young(a)durham.ac.uk> - 4.9.1-1
- update to 4.9.1 (#1515818)
adjust xen.use.fedora.ipxe.patch
and qemu.git-fec5e8c92becad223df9d972770522f64aafdb72.patch
remove patches for issues now fixed upstream and parts of xen.gcc7.fix.patch
update xen.hypervisor.config
- update Source0 location
* Wed Nov 15 2017 Michael Young <m.a.young(a)durham.ac.uk> - 4.9.0-14
- fix an issue in patch for [XSA-240, CVE-2017-15595] that might be a
security issue
- fix for [XSA-243, CVE-2017-15592] could cause hypervisor crash (DOS)
* Thu Oct 26 2017 Michael Young <m.a.young(a)durham.ac.uk> - 4.9.0-13
- pin count / page reference race in grant table code [XSA-236, CVE-2017-15597]
(#1506693)
* Thu Oct 12 2017 Michael Young <m.a.young(a)durham.ac.uk> - 4.9.0-12
- xen: various flaws (#1501391)
multiple MSI mapping issues on x86 [XSA-237, CVE-2017-15590]
DMOP map/unmap missing argument checks [XSA-238, CVE-2017-15591]
hypervisor stack leak in x86 I/O intercept code [XSA-239, CVE-2017-15589]
Unlimited recursion in linear pagetable de-typing [XSA-240, CVE-2017-15595]
Stale TLB entry due to page type release race [XSA-241, CVE-2017-15588]
page type reference leak on x86 [XSA-242, CVE-2017-15593]
x86: Incorrect handling of self-linear shadow mappings with translated
guests [XSA-243, CVE-2017-15592]
x86: Incorrect handling of IST settings during CPU hotplug [XSA-244,
CVE-2017-15594]
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1610543 - CVE-2018-15469 xen: Use of v2 grant tables may cause crash on ARM (XSA-268)
https://bugzilla.redhat.com/show_bug.cgi?id=1610543
[ 2 ] Bug #1610548 - CVE-2018-15468 xen: x86 Incorrect MSR_DEBUGCTL handling lets guests enable BTS (XSA-269)
https://bugzilla.redhat.com/show_bug.cgi?id=1610548
[ 3 ] Bug #1610552 - CVE-2018-15470 xen: oxenstored does not apply quota-maxentity (XSA-272)
https://bugzilla.redhat.com/show_bug.cgi?id=1610552
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-915602df63' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2018-4dfc6b0eca
2018-08-31 13:31:35.381910
--------------------------------------------------------------------------------
Name : lorax
Product : Fedora 29
Version : 29.12
Release : 1.fc29
URL : https://github.com/weldr/lorax
Summary : Tool for creating the anaconda install images
Description :
Lorax is a tool for creating the anaconda install images.
It also includes livemedia-creator which is used to create bootable livemedia,
including live isos and disk images. It can use libvirtd for the install, or
Anaconda's image install feature.
--------------------------------------------------------------------------------
Update Information:
- Minor package fixes for aarch64/ARMv7 (pbrobinson)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1615332 - import-state.service / initscripts missing in installer image
https://bugzilla.redhat.com/show_bug.cgi?id=1615332
[ 2 ] Bug #1623272 - composes fail with lorax 29.11 due to incorrect armhfp/aarch64 package install directives
https://bugzilla.redhat.com/show_bug.cgi?id=1623272
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-4dfc6b0eca' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2018-b7b99fe852
2018-08-30 19:03:39.343496
--------------------------------------------------------------------------------
Name : golang-github-xlab-handysort
Product : Fedora 28
Version : 0
Release : 0.1.20180827gitfb3537e.fc28
URL : https://github.com/xlab/handysort
Summary : Alphanumeric string sorting algorithm implementation in Go
Description :
This is a Go package implementing a correct comparison function to
compare alphanumeric strings with respect to their integer parts.
--------------------------------------------------------------------------------
Update Information:
First package for Fedora
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-b7b99fe852' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2018-2b9849579c
2018-08-30 19:03:39.343482
--------------------------------------------------------------------------------
Name : golang-github-tg-gosortmap
Product : Fedora 28
Version : 0
Release : 0.1.20180827git2901ada.fc28
URL : https://github.com/tg/gosortmap
Summary : Sort maps in Go
Description :
Sort maps in Go by keys or values. Works with most built-in types;
own comparator can be provided to support custom types and ordering.
--------------------------------------------------------------------------------
Update Information:
First package for Fedora
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-2b9849579c' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2018-5074fb1adc
2018-08-30 19:03:39.343468
--------------------------------------------------------------------------------
Name : golang-github-fatih-set
Product : Fedora 28
Version : 0.2.1
Release : 1.fc28
URL : https://github.com/fatih/set
Summary : Set data structure for Go
Description :
Set is a basic and simple, hash-based, Set data structure implementation in Go
(Golang).
--------------------------------------------------------------------------------
Update Information:
First package for Fedora
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-5074fb1adc' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2018-42056955de
2018-08-30 19:03:39.343455
--------------------------------------------------------------------------------
Name : libunibreak
Product : Fedora 28
Version : 4.0
Release : 2.fc28
URL : http://vimgadgets.sourceforge.net/libunibreak/
Summary : A Unicode line-breaking library
Description :
Libunibreak is an implementation of the line breaking and word
breaking algorithms as described in Unicode Standard Annex 14 and
Unicode Standard Annex 29. It is designed to be used in a generic text
renderer.
--------------------------------------------------------------------------------
Update Information:
Initial release of libunibreak, replacing liblinebreak
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1342724 - Review Request: libunibreak - A Unicode line-breaking library
https://bugzilla.redhat.com/show_bug.cgi?id=1342724
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-42056955de' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2018-99112fc1a0
2018-08-30 19:03:39.343441
--------------------------------------------------------------------------------
Name : python-beautifulsoup4
Product : Fedora 28
Version : 4.6.3
Release : 1.fc28
URL : http://www.crummy.com/software/BeautifulSoup/
Summary : HTML/XML parser for quick-turnaround applications like screen-scraping
Description :
Beautiful Soup is a Python HTML/XML parser designed for quick
turnaround projects like screen-scraping. Three features make it
powerful:
Beautiful Soup wont choke if you give it bad markup.
Beautiful Soup provides a few simple methods and Pythonic idioms for
navigating, searching, and modifying a parse tree.
Beautiful Soup automatically converts incoming documents to Unicode
and outgoing documents to UTF-8.
Beautiful Soup parses anything you give it.
Valuable data that was once locked up in poorly-designed websites is
now within your reach. Projects that would have taken hours take only
minutes with Beautiful Soup.
--------------------------------------------------------------------------------
Update Information:
Update to latest upstream release beautifulsoup 4.6.3.
--------------------------------------------------------------------------------
ChangeLog:
* Mon Aug 27 2018 Terje Rosten <terje.rosten(a)ntnu.no> - 4.6.3-1
- 4.6.3
* Mon Jul 30 2018 Terje Rosten <terje.rosten(a)ntnu.no> - 4.6.1-1
- 4.6.1
* Fri Jul 13 2018 Fedora Release Engineering <releng(a)fedoraproject.org> - 4.6.0-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Sun Jun 17 2018 Miro Hron��ok <mhroncok(a)redhat.com> - 4.6.0-7
- Rebuilt for Python 3.7
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1615177 - python-beautifulsoup4-4.6.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1615177
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-99112fc1a0' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2018-93b269fa36
2018-08-30 19:03:39.343427
--------------------------------------------------------------------------------
Name : glusterfs
Product : Fedora 28
Version : 4.1.3
Release : 1.fc28
URL : http://docs.gluster.org/
Summary : Distributed File System
Description :
GlusterFS is a distributed file-system capable of scaling to several
petabytes. It aggregates various storage bricks over Infiniband RDMA
or TCP/IP interconnect into one large parallel network file
system. GlusterFS is one of the most sophisticated file systems in
terms of features and extensibility. It borrows a powerful concept
called Translators from GNU Hurd kernel. Much of the code in GlusterFS
is in user space and easily manageable.
This package includes the glusterfs binary, the glusterfsd daemon and the
libglusterfs and glusterfs translator modules common to both GlusterFS server
and client framework.
--------------------------------------------------------------------------------
Update Information:
4.1.3 GA
--------------------------------------------------------------------------------
ChangeLog:
* Mon Aug 27 2018 Kaleb S. KEITHLEY <kkeithle[at]redhat.com> - 4.1.3-1
- 4.1.3 GA
* Wed Jul 25 2018 Kaleb S. KEITHLEY <kkeithle[at]redhat.com> - 4.1.2-2
- 4.1.2, again
* Tue Jul 24 2018 Kaleb S. KEITHLEY <kkeithle[at]redhat.com> - 4.1.2-1
- 4.1.2 GA (includes gsyncd.conf)
* Fri Jul 13 2018 Fedora Release Engineering <releng(a)fedoraproject.org> - 4.1.1-2.1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Wed Jul 11 2018 Kaleb S. KEITHLEY <kkeithle[at]redhat.com> - 4.1.1-2
- missed python->python2 in shebang
* Tue Jun 26 2018 Kaleb S. KEITHLEY <kkeithle[at]redhat.com> - 4.1.1-1
- 4.1.1 GA
* Tue Jun 12 2018 Kaleb S. KEITHLEY <kkeithle[at]redhat.com> - 4.1.0-1
- 4.1.0 GA
* Fri Jun 1 2018 Kaleb S. KEITHLEY <kkeithle[at]redhat.com> - 4.1.0rc0
- 4.1.0 RC0
* Tue Apr 24 2018 Niels de Vos <ndevos(a)redhat.com> - 4.0.2-1
- 4.0.2 GA
* Thu Apr 19 2018 Kaleb S. KEITHLEY <kkeithle[at]redhat.com> - 4.0.1-3
- 4.0.1, restore python->python2 -prettytable
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-93b269fa36' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2018-02eaa71884
2018-08-30 19:03:39.343399
--------------------------------------------------------------------------------
Name : copr-cli
Product : Fedora 28
Version : 1.73
Release : 1.fc28
URL : https://pagure.io/copr/copr
Summary : Command line interface for COPR
Description :
COPR is lightweight build system. It allows you to create new project in WebUI,
and submit new builds and COPR will create yum repository from latests builds.
This package contains command line interface.
--------------------------------------------------------------------------------
Update Information:
- pg#370 copr-cli new-webhook-secret fails - fix input under python2 ---- -
generate new webhook secret functionality in copr-cli - packaging: Python 2/3,
RHEL/Fedora fixes
--------------------------------------------------------------------------------
ChangeLog:
* Fri Aug 24 2018 clime <clime(a)redhat.com> 1.73-1
- pg#370 copr-cli new-webhook-secret fails
- fix input under python2
* Thu Aug 23 2018 clime <clime(a)redhat.com> 1.72-1
- generate new webhook secret functionality in copr-cli
- packaging: Python 2/3, RHEL/Fedora fixes
* Mon Aug 6 2018 clime <clime(a)redhat.com> 1.71-1
- %{python_sitelib} ��� %{python2_sitelib}
* Fri May 18 2018 clime <clime(a)redhat.com> 1.70-1
- deprecate mock-config command
* Mon Apr 30 2018 Dominik Turecek <dturecek(a)redhat.com> 1.69-1
fix non-passing unittests under f28+
* Thu Apr 26 2018 Dominik Turecek <dturecek(a)redhat.com> 1.68-1
- simplify bar.finish logic
- rpkg deployment into COPR - containers + releng continuation
- #280 cli upload to nonexisting project makes terminal cursor disappear
- #220 copr-cli doesn't display build progress in non-interactive terminal
- add download-build --dest description to man page
- add `copr delete-build` build into man pages
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-02eaa71884' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------