GNU bug report logs

#47257 mariadb is vulnerable to CVE-2021-27928 (RCE)

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Full log

Message #46 received at 47257@debbugs.gnu.org (full text, mbox, reply):

Received: (at 47257) by debbugs.gnu.org; 25 Mar 2021 12:48:50 +0000
From debbugs-submit-bounces@debbugs.gnu.org Thu Mar 25 08:48:50 2021
Received: from localhost ([127.0.0.1]:37427 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1lPPPu-0006Cn-57
	for submit@debbugs.gnu.org; Thu, 25 Mar 2021 08:48:50 -0400
Received: from mail.zaclys.net ([178.33.93.72]:37657)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <lle-bout@zaclys.net>) id 1lPPPs-0006Ca-8u
 for 47257@debbugs.gnu.org; Thu, 25 Mar 2021 08:48:49 -0400
Received: from guix-xps.local (82-64-145-38.subs.proxad.net [82.64.145.38])
 (authenticated bits=0)
 by mail.zaclys.net (8.14.7/8.14.7) with ESMTP id 12PCmg48044062
 (version=TLSv1/SSLv3 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO)
 for <47257@debbugs.gnu.org>; Thu, 25 Mar 2021 13:48:42 +0100
DMARC-Filter: OpenDMARC Filter v1.3.2 mail.zaclys.net 12PCmg48044062
Authentication-Results: mail.zaclys.net;
 dmarc=fail (p=reject dis=none) header.from=zaclys.net
Authentication-Results: mail.zaclys.net;
 spf=fail smtp.mailfrom=lle-bout@zaclys.net
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=zaclys.net;
 s=default; t=1616676522;
 bh=G7xlpV2/nFE/A80WPwBOAgHS/KqbSvwGwt3l+Fjmv7Y=;
 h=Subject:From:To:Date:In-Reply-To:References:From;
 b=q6xwiMbR5gc3X1y6Nmw2RMPULA9+FvDEI4y2I+PEIktscHfYHk/JcmfqjAqZEERwD
 3OSj6uQ0EiRY/SmLteH/DNfJSEMXAS7R/m555/JNfo9i/RNlQBetvwhVF0V1ROQELh
 J1x1BxdNCjKVxsL9ij0i0C4URUTwNd+6D04FG0yA=
Message-ID: <ebca408b79b4b828de3aca8f55a63977c6d44a42.camel@zaclys.net>
Subject: Re: [PATCH v3] gnu: mariadb: Fix CVE-2021-27928.
From: Léo Le Bouter <lle-bout@zaclys.net>
To: 47257@debbugs.gnu.org
Date: Thu, 25 Mar 2021 13:48:41 +0100
In-Reply-To: <20210325123921.9800-1-lle-bout@zaclys.net>
References: <20210325123921.9800-1-lle-bout@zaclys.net>
Content-Type: multipart/signed; micalg="pgp-sha512";
 protocol="application/pgp-signature"; boundary="=-DfBZWGvOjOtodEGw8CSk"
User-Agent: Evolution 3.34.2 
MIME-Version: 1.0
X-Spam-Score: 0.0 (/)
X-Debbugs-Envelope-To: 47257
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -1.0 (-)
[Message part 1 (text/plain, inline)]
v3 tested and builds fine:

$ ./pre-inst-env guix build mariadb
/gnu/store/f70jymwyfcnsghy4jg8caibci59p8rgq-mariadb-10.5.8-dev
/gnu/store/cj3qym1x1jjh02m2g23cqpbhchrbmn6c-mariadb-10.5.8-lib
/gnu/store/mpb5bdf1vkwazqfmmwcvskdm50g191bg-mariadb-10.5.8

Since we don't have PoC, I can't verify the rebased patch actually
fixes the security issue but it should. That's what we get when
manually rebasing stuff to earlier versions. Test suite passes but not
sure it actually tests this security issue being fixed.

Please review, then I will push, it's been 7 days so, let's get this
in.
[signature.asc (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sun Dec 22 01:03:09 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.