GNU bug report logs

#47563 curl is vulnerable to CVE-2021-22890 and CVE-2021-22876

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Full log

Message #16 received at submit@debbugs.gnu.org (full text, mbox, reply):

Received: (at submit) by debbugs.gnu.org; 2 Apr 2021 18:22:15 +0000
From debbugs-submit-bounces@debbugs.gnu.org Fri Apr 02 14:22:15 2021
Received: from localhost ([127.0.0.1]:32831 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1lSOQx-0008IE-1f
	for submit@debbugs.gnu.org; Fri, 02 Apr 2021 14:22:15 -0400
Received: from lists.gnu.org ([209.51.188.17]:53714)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <leo@famulari.name>) id 1lSOQw-0008I7-2a
 for submit@debbugs.gnu.org; Fri, 02 Apr 2021 14:22:14 -0400
Received: from eggs.gnu.org ([2001:470:142:3::10]:57640)
 by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <leo@famulari.name>) id 1lSOQv-00056Z-T1
 for bug-guix@gnu.org; Fri, 02 Apr 2021 14:22:13 -0400
Received: from wout4-smtp.messagingengine.com ([64.147.123.20]:35967)
 by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <leo@famulari.name>) id 1lSOQt-0002JJ-Hs
 for bug-guix@gnu.org; Fri, 02 Apr 2021 14:22:13 -0400
Received: from compute3.internal (compute3.nyi.internal [10.202.2.43])
 by mailout.west.internal (Postfix) with ESMTP id 603DF140F;
 Fri,  2 Apr 2021 14:22:09 -0400 (EDT)
Received: from mailfrontend2 ([10.202.2.163])
 by compute3.internal (MEProxy); Fri, 02 Apr 2021 14:22:09 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name;
 h=date:from:to:cc:subject:message-id:references:mime-version
 :content-type:content-transfer-encoding:in-reply-to; s=mesmtp;
 bh=WN7333Uihk+Dcj7iUGeSry1XF50ie7TW5H6Mh5Q2uis=; b=c0nDoXjYC3OZ
 rcTBOVlpMc0aqFB/7tDy+JDYGd2a/U66FTcVWWoeEzYo3xQtrQXwESxtsuVOap+D
 F49E0ZphWI1fi/z3r+R0QVDh2VGemqvpjMHa8GAjqDq29F8vJV3ckzdd9q0AL1yj
 R6yVYiybvxwTSNNy5i/HAakpp5jjQp4=
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=
 messagingengine.com; h=cc:content-transfer-encoding:content-type
 :date:from:in-reply-to:message-id:mime-version:references
 :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender
 :x-sasl-enc; s=fm2; bh=WN7333Uihk+Dcj7iUGeSry1XF50ie7TW5H6Mh5Q2u
 is=; b=CSvo0b2cj9i1K30MSPmbcEF27rnFrckku3xdv0n4225cze58BbzC/kI9v
 b4cX5QrK+VA4vwefpVTTmnZsGPmcsPwgDElcurE29uWH7xuZ2d1aAx8Dd2OydwSJ
 3f8TPN27Q1VVXwOKjWLX01seaOfLN+iRtxOFzI5SoH2K5y8fcnjiijUseGXqJrAg
 QBlS+PgSMQrFF8o0XG0XclttnrpzQXTOKrDr31DUry6U2P3i70wPedTF0X5nI9Oc
 zHdEmFmkuU816NsMsXZ48wVvod+QiHNyhYZVfSgcvC+qWioivjf0aVITEjqJrUJO
 nPipQwQHmtIQkzp+pSRHdKnvaujUQ==
X-ME-Sender: <xms:0GBnYAMhr1H0-wQSZCmJhBXnCstSFYLIsZjrO6NN__Ckj4JaAlb18Q>
 <xme:0GBnYG_c82_6aPoQRUTZthyBaTUCuq202sBAbaJAmOOsncJSaQyPPjG5zhppZY29l
 P0P9FHPfA4c9T-nsA>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduledrudeiiedguddvudcutefuodetggdotefrod
 ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfgh
 necuuegrihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnthhsucdlqddutddtmd
 enucfjughrpeffhffvuffkfhggtggugfgjsehtkeertddttddunecuhfhrohhmpefnvgho
 ucfhrghmuhhlrghrihcuoehlvghosehfrghmuhhlrghrihdrnhgrmhgvqeenucggtffrrg
 htthgvrhhnpeejgfeileekhefgjeduteffhfefveffjeefheelfeduteevfeeujeevleff
 jeejjeenucffohhmrghinhepghhnuhdrohhrghdptghurhhlrdhsvgenucfkphepieelrd
 duvddtrdelvddrvddtkeenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgr
 ihhlfhhrohhmpehlvghosehfrghmuhhlrghrihdrnhgrmhgv
X-ME-Proxy: <xmx:0GBnYHTtlDLd_USuNYSB9iVTc-QOGjx2jUcEbeFDY-dTtAwUSQJJ5w>
 <xmx:0GBnYIu-kho3ggOx8oWH47Tu_Jy11sPhq8lnz0iZOJEMrMjXyHa4ZA>
 <xmx:0GBnYIfHE5YLbPTGNoqZxgtb2hf-_yWJa5qYW_Uuvzq2baxCSG4Ktg>
 <xmx:0WBnYAnFvootLn59r-iQvIjYepafHt559J2xUQnajoEU4AWc5k3hxg>
Received: from localhost (ool-45785cd0.dyn.optonline.net [69.120.92.208])
 by mail.messagingengine.com (Postfix) with ESMTPA id 4B0C91080057;
 Fri,  2 Apr 2021 14:22:08 -0400 (EDT)
Date: Fri, 2 Apr 2021 14:22:06 -0400
From: Leo Famulari <leo@famulari.name>
To: Léo Le Bouter via Bug reports for GNU Guix
 <bug-guix@gnu.org>
Subject: Re: bug#47563: [PATCH 0/1] gnu: curl: Fix CVE-2021-22876 and
 CVE-2021-22890.
Message-ID: <YGdgzne+guUD0JCT@jasmine.lan>
References: <3f93f64c692d9e0604aa406a735d81084443b692.camel@zaclys.net>
 <20210402140940.28300-1-lle-bout@zaclys.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
In-Reply-To: <20210402140940.28300-1-lle-bout@zaclys.net>
Received-SPF: pass client-ip=64.147.123.20; envelope-from=leo@famulari.name;
 helo=wout4-smtp.messagingengine.com
X-Spam_score_int: -27
X-Spam_score: -2.8
X-Spam_bar: --
X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1,
 DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1,
 RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001,
 SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no
X-Spam_action: no action
X-Spam-Score: -1.4 (-)
X-Debbugs-Envelope-To: submit
Cc: 47563@debbugs.gnu.org,
 Léo Le Bouter <lle-bout@zaclys.net>
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -2.4 (--)
On Fri, Apr 02, 2021 at 04:09:39PM +0200, Léo Le Bouter via Bug reports for GNU Guix wrote:
> curl-CVE-2021-22876.patch was rebased onto 7.74.0, but curl-CVE-2021-22890.patch
> does not apply and please I need help rebasing it, it looks quite complex.
> 
> I pushed an upgrade of curl to 7.76.0 which has been much much easier to
> core-updates already as
> https://git.savannah.gnu.org/cgit/guix.git/commit/?h=core-updates&id=2e0b1b62e94b926041ca9af70537dd9b3ab64edf
> but unfortunately since curl requires so many rebuilds it seems we can't use
> such commit on master for now.

Can we try grafting an "upgrade" to 7.76.0? In my experience, most curl
upgrades are graftable.

Curl's developers are very careful with their ABI and even maintain
their own page on the subject: <https://curl.se/libcurl/abi.html>




Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sat Dec 21 18:32:27 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.