Thursday, July 28, 2022

[USN-5535-1] Intel Microcode vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5535-1
July 28, 2022

Intel Microcode vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM

Summary:

Several security issues were fixed in Intel Microcode.

Software Description:
- intel-microcode: Processor microcode for Intel CPUs

Details:

Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)

Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)

It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service (system crash). (CVE-2021-0127)

It was discovered that some Intel processors did not completely perform
cleanup actions on multi-core shared buffers. A local attacker could
possibly use this to expose sensitive information. (CVE-2022-21123,
CVE-2022-21127)

It was discovered that some Intel processors did not completely perform
cleanup actions on microarchitectural fill buffers. A local attacker could
possibly use this to expose sensitive information. (CVE-2022-21125)

Alysa Milburn, Jason Brandt, Avishai Redelman and Nir Lavi discovered that
some Intel processors improperly optimised security-critical code. A local
attacker could possibly use this to expose sensitive
information. (CVE-2022-21151)

It was discovered that some Intel processors did not properly perform
cleanup during specific special register write operations. A local attacker
could possibly use this to expose sensitive information. (CVE-2022-21166)

It was discovered that some Intel processors did not properly restrict
access in some situations. A local attacker could use this to obtain
sensitive information. (CVE-2021-33117)

Brandon Miller discovered that some Intel processors did not properly
restrict access in some situations. A local attacker could use this to
obtain sensitive information or a remote attacker could use this to
cause a denial of service (system crash). (CVE-2021-33120)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
intel-microcode 3.20220510.0ubuntu0.16.04.1+esm1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5535-1
CVE-2021-0127
, CVE-2021-0145, CVE-2021-0146, CVE-2021-33117,
CVE-2021-33120, CVE-2022-21123, CVE-2022-21125, CVE-2022-21127,
CVE-2022-21151, CVE-2022-21166

Tuesday, July 26, 2022

[USN-5531-1] protobuf-c vulnerability

==========================================================================
Ubuntu Security Notice USN-5531-1
July 26, 2022

protobuf-c vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in protobuf-c.

Software Description:
- protobuf-c: Protocol Buffers C static library and headers (protobuf-c)

Details:

Pietro Borrello discovered that protobuf-c contained an invalid
arithmetic shift. This vulnerability allowed attackers to cause a
denial of service (system crash) via unspecified vectors
(CVE-2022-33070).

It was discovered that protobuf-c contained an unsigned integer
overflow. This vulnerability allowed attackers to cause a denial of
service (system crash) via unspecified vectors.

Todd Miller discovered that protobuf-c contained a possible NULL
dereference. This could cause a vulnerability that allowed attackers to
cause a denial of service (system crash) via unspecified vectors.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
protobuf-c-compiler 1.3.3-1ubuntu2.1

Ubuntu 20.04 LTS:
protobuf-c-compiler 1.3.3-1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5531-1
CVE-2022-33070


Package Information:
https://launchpad.net/ubuntu/+source/protobuf-c/1.3.3-1ubuntu2.1
https://launchpad.net/ubuntu/+source/protobuf-c/1.3.3-1ubuntu0.1

[USN-5534-1] ImageMagick vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5534-1
July 26, 2022

imagemagick vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM

Summary:

Several security issues were fixed in ImageMagick.

Software Description:
- imagemagick: Image manipulation programs and library

Details:

It was discovered that ImageMagick incorrectly handled certain values.
If a user were tricked into processing a specially crafted image file,
an attacker could possibly exploit this issue to cause a denial of
service or other unspecified impact. (CVE-2022-32545, CVE-2022-32546)

It was discovered that ImageMagick incorrectly handled memory under
certain circumstances. If a user were tricked into processing a
specially crafted image file, an attacker could possibly exploit this
issue to cause a denial of service or other unspecified impact.
(CVE-2022-32547)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
imagemagick 8:6.8.9.9-7ubuntu5.16+esm4
imagemagick-6.q16 8:6.8.9.9-7ubuntu5.16+esm4
libimage-magick-q16-perl 8:6.8.9.9-7ubuntu5.16+esm4
libmagick++-6.q16-5v5 8:6.8.9.9-7ubuntu5.16+esm4
libmagickcore-6-headers 8:6.8.9.9-7ubuntu5.16+esm4
libmagickcore-6.q16-2 8:6.8.9.9-7ubuntu5.16+esm4
libmagickcore-6.q16-2-extra 8:6.8.9.9-7ubuntu5.16+esm4
libmagickwand-6.q16-2 8:6.8.9.9-7ubuntu5.16+esm4

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5534-1
CVE-2022-32545, CVE-2022-32546, CVE-2022-32547

[USN-5533-1] Vim vulnerability

==========================================================================
Ubuntu Security Notice USN-5533-1
July 26, 2022

vim vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM

Summary:

Vim could be made to crash, among other things, if it
opened a specially crafted file.

Software Description:
- vim: Vi IMproved - enhanced vi editor

Details:

It was discovered that Vim incorrectly handled memory access. If a
user were tricked into opening a specially crafted file, an attacker
could possibly use this issue to cause the corruption of sensitive
information, a crash, or arbitrary code execution.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
vim 2:7.4.1689-3ubuntu1.5+esm12

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5533-1
CVE-2022-2129

List of long term FTBFS packages to be retired in August

Dear maintainers.

Based on the current fail to build from source policy, the following packages
will be retired from Fedora 37 approximately one week before branching (August
2022).

Policy:
https://docs.fedoraproject.org/en-US/fesco/Fails_to_build_from_source_Fails_to_install/

The packages in rawhide were not successfully built at least since Fedora 35.

This report is based on dist tags.

Packages collected via:
https://github.com/hroncok/fedora-report-ftbfs-retirements/blob/master/ftbfs-retirements.ipynb

If you see a package that was built, please let me know.
If you see a package that should be exempted from the process, please let me
know and we can work together to get a FESCo approval for that.

If you see a package that can be rebuilt, please do so.

Package (co)maintainers
=========================================================================
golang-grpc-go4 eclipseo, go-sig, jchaloup
lancer willb
php-aws-sdk3 lcts
php-pimple lcts
recorder ddd
rubygem-coffee-rails jaruga, ruby-packagers-sig, vondruch
rubygem-minitest-reporters pvalena
rubygem-sprockets-rails jaruga, pvalena, ruby-packagers-sig
tinygo go-sig, qulogic
uom-parent lberk, mgoodwin, nathans
xs petersen


The following packages require above mentioned packages:
Depending on: golang-grpc-go4 (1)
golang-x-build (maintained by: eclipseo, go-sig, jchaloup)
golang-x-build-0-0.19.20201229git0a4bf69.fc35.src requires
golang(grpc.go4.org) = 0-0.9.20180421git11d0a25.fc34,
golang(grpc.go4.org/codes) = 0-0.9.20180421git11d0a25.fc34
golang-x-build-devel-0-0.19.20201229git0a4bf69.fc35.noarch requires
golang(grpc.go4.org) = 0-0.9.20180421git11d0a25.fc34,
golang(grpc.go4.org/codes) = 0-0.9.20180421git11d0a25.fc34

Depending on: rubygem-sprockets-rails (22)
rubygem-actionmailbox (maintained by: pvalena)
rubygem-actionmailbox-7.0.2.3-2.fc37.src requires rubygem(sprockets-rails) =
3.2.2

rubygem-activestorage (maintained by: ruby-packagers-sig, vondruch)
rubygem-activestorage-7.0.2.3-1.fc37.src requires rubygem(sprockets-rails) =
3.2.2

rubygem-railties (maintained by: mmorsi, pvalena, tdawson, vondruch)
rubygem-railties-7.0.2.3-2.fc37.src requires rubygem(sprockets-rails) = 3.2.2

rubygem-sassc-rails (maintained by: pvalena)
rubygem-sassc-rails-2.1.2-4.fc36.noarch requires rubygem(sprockets-rails) = 3.2.2
rubygem-sassc-rails-2.1.2-4.fc36.src requires rubygem(sprockets-rails) = 3.2.2

rubygem-rails (maintained by: jstribny, kanarip, mmorsi, mtasaka, pvalena,
ruby-packagers-sig, sseago, tdawson, vondruch)
rubygem-rails-1:7.0.2.3-2.fc37.noarch requires rubygem(actionmailbox) = 7.0.2.3

rubygem-rspec-rails (maintained by: clalance, vondruch)
rubygem-rspec-rails-5.1.1-2.fc37.src requires rubygem(actionmailbox) = 7.0.2.3

rubygem-actiontext (maintained by: pvalena)
rubygem-actiontext-7.0.2.3-2.fc37.noarch requires rubygem(activestorage) =
7.0.2.3
rubygem-actiontext-7.0.2.3-2.fc37.src requires rubygem(activestorage) = 7.0.2.3

rubygem-actionpack (maintained by: jaruga, jstribny, kanarip, mmorsi, pvalena,
ruby-packagers-sig, sseago, vondruch)
rubygem-actionpack-1:7.0.2.3-1.fc37.src requires rubygem(railties) = 7.0.2.3

rubygem-actionview (maintained by: jaruga, pvalena, ruby-packagers-sig)
rubygem-actionview-7.0.2.3-1.fc37.src requires rubygem(railties) = 7.0.2.3

rubygem-activemodel (maintained by: jstribny, mmorsi, pvalena, tdawson, vondruch)
rubygem-activemodel-7.0.2.3-2.fc37.src requires rubygem(railties) = 7.0.2.3

rubygem-ammeter (maintained by: jstribny, ruby-packagers-sig, vondruch)
rubygem-ammeter-1.1.5-3.fc37.noarch requires rubygem(railties) = 7.0.2.3
rubygem-ammeter-1.1.5-3.fc37.src requires rubygem(railties) = 7.0.2.3

rubygem-font-awesome-rails (maintained by: abradshaw, ckyriakidou, evgeni,
fale, snecker)
rubygem-font-awesome-rails-4.7.0.8-2.fc37.noarch requires rubygem(railties) =
7.0.2.3
rubygem-font-awesome-rails-4.7.0.8-2.fc37.src requires rubygem(railties) =
7.0.2.3

rubygem-generator_spec (maintained by: ilgrad)
rubygem-generator_spec-0.9.4-12.fc37.noarch requires rubygem(railties) = 7.0.2.3
rubygem-generator_spec-0.9.4-12.fc37.src requires rubygem(railties) = 7.0.2.3

rubygem-globalid (maintained by: jaruga, pvalena, ruby-packagers-sig)
rubygem-globalid-1.0.0-3.fc37.src requires rubygem(railties) = 7.0.2.3

rubygem-haml (maintained by: kanarip, pvalena)
rubygem-haml-5.2.2-3.fc37.src requires rubygem(railties) = 7.0.2.3

rubygem-importmap-rails (maintained by: pvalena)
rubygem-importmap-rails-1.0.3-2.fc37.noarch requires rubygem(railties) = 7.0.2.3

rubygem-jbuilder (maintained by: pvalena, vondruch)
rubygem-jbuilder-2.11.5-2.fc37.src requires rubygem(railties) = 7.0.2.3

rubygem-jquery-rails (maintained by: jstribny, tdawson, vondruch)
rubygem-jquery-rails-4.4.0-3.fc37.noarch requires rubygem(railties) = 7.0.2.3

rubygem-rails-controller-testing (maintained by: valtri)
rubygem-rails-controller-testing-1.0.5-6.fc37.src requires rubygem(railties)
= 7.0.2.3

rubygem-sass-twitter-bootstrap (maintained by: tdawson)
rubygem-sass-twitter-bootstrap-2.3.0-16.fc37.noarch requires
rubygem(railties) = 7.0.2.3

rubygem-slim (maintained by: vondruch)
rubygem-slim-4.1.0-6.fc37.src requires rubygem(railties) = 7.0.2.3

rubygem-web-console (maintained by: jaruga, ruby-packagers-sig, vondruch)
rubygem-web-console-4.1.0-4.fc36.noarch requires rubygem(railties) = 7.0.2.3
rubygem-web-console-4.1.0-4.fc36.src requires rubygem(railties) = 7.0.2.3

Too many dependencies for rubygem-sprockets-rails, not all listed here


Affected (co)maintainers (directly and indirectly):
abradshaw: rubygem-sprockets-rails
ckyriakidou: rubygem-sprockets-rails
clalance: rubygem-sprockets-rails
ddd: recorder
eclipseo: golang-grpc-go4
evgeni: rubygem-sprockets-rails
fale: rubygem-sprockets-rails
go-sig: golang-grpc-go4, tinygo
ilgrad: rubygem-sprockets-rails
jaruga: rubygem-sprockets-rails, rubygem-coffee-rails
jchaloup: golang-grpc-go4
jstribny: rubygem-sprockets-rails
kanarip: rubygem-sprockets-rails
lberk: uom-parent
lcts: php-aws-sdk3, php-pimple
mgoodwin: uom-parent
mmorsi: rubygem-sprockets-rails
mtasaka: rubygem-sprockets-rails
nathans: uom-parent
petersen: xs
pvalena: rubygem-sprockets-rails, rubygem-minitest-reporters
qulogic: tinygo
ruby-packagers-sig: rubygem-sprockets-rails, rubygem-coffee-rails
snecker: rubygem-sprockets-rails
sseago: rubygem-sprockets-rails
tdawson: rubygem-sprockets-rails
valtri: rubygem-sprockets-rails
vondruch: rubygem-sprockets-rails, rubygem-coffee-rails
willb: lancer

--
Miro HronĨok
--
Phone: +420777974800
IRC: mhroncok
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

[USN-5532-1] Bottle vulnerability

==========================================================================
Ubuntu Security Notice USN-5532-1
July 26, 2022

python-bottle vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Bottle could be made to leak sensitive information if it received a specially
crafted request.

Software Description:
- python-bottle: fast and simple WSGI-framework for Python

Details:

It was discovered that Bottle incorrectly handled errors during early request
binding. An attacker could possibly use this issue to disclose sensitve
information. (CVE-2022-31799)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
python3-bottle 0.12.19-1+deb11u1build0.22.04.1

Ubuntu 20.04 LTS:
python3-bottle 0.12.15-2.1ubuntu0.2

Ubuntu 18.04 LTS:
python-bottle 0.12.13-1ubuntu0.2
python3-bottle 0.12.13-1ubuntu0.2

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5532-1
CVE-2022-31799

Package Information:
https://launchpad.net/ubuntu/+source/python-bottle/0.12.19-1+deb11u1build0.22.04.1
https://launchpad.net/ubuntu/+source/python-bottle/0.12.15-2.1ubuntu0.2
https://launchpad.net/ubuntu/+source/python-bottle/0.12.13-1ubuntu0.2

Automated reports redirected into a new mailing list: test-reports

Hello testers and developers,

please note that we've set up a new mailing list called test-reports [1] and we've redirected all automated compose/updates/test/etc reports into it. These reports were previously sent to the test list and devel list and created a lot of visual noise among regular conversations (especially in the test list). You can see test-reports archives [1] to see which emails I'm talking about. The only exception is the main rawhide compose report, which still goes to the devel list (as well as test-reports), because it was deemed useful enough to be kept there.

If you're interested in receiving these reports, please subscribe to the new list. The default reply is set to go to the test list, where we can have conversations about any suspicious changes/outcomes, but you can of course start your discussion in the devel list, if you prefer.

Cheers,
Kamil
Fedora QA


Monday, July 25, 2022

Fedora 37 mass rebuild complete

Hi all,

Per the Fedora 37 schedule[1] we started a mass rebuild for Fedora
37 on 2022/07/20. We did a mass rebuild for Fedora 37 for:

https://pagure.io/releng/issues?status=Open&tags=mass+rebuild

The mass rebuild was done in a side tag (f37-rebuild) and moved over to
f37. Failures can be seen
https://kojipkgs.fedoraproject.org/mass-rebuild/f37-failures.html Things
still needing rebuilding
https://kojipkgs.fedoraproject.org/mass-rebuild/f37-need-rebuild.html

21713 builds have been tagged into f37, there is currently 1144 failed
builds that need to be addressed by the package maintainers. FTBFS bugs
will be filed shortly. Please be sure to let releng know if you see any
bugs in the reporting. You can contact releng in #fedora-releng on
libera.chat, by dropping an email to our list[2], joining
#releng:fedoraproject.org on Matrix, or filing an issue in pagure[3]

Regards,
Fedora Release Engineering

[1] https://fedorapeople.org/groups/schedule/f-N/f-N-key-tasks.html
[2] https://lists.fedoraproject.org/admin/lists/rel-eng.lists.fedoraproject.org/
[3] https://pagure.io/releng/

[USN-5530-1] PHP vulnerability

==========================================================================
Ubuntu Security Notice USN-5530-1
July 25, 2022

php8.1 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS

Summary:

PHP could be made to crash or run programs if it processed specially
crafted data.

Software Description:
- php8.1: HTML-embedded scripting language interpreter

Details:

It was discovered that PHP incorrectly handled certain memory operations
when obtaining file information. A remote attacker could use this issue to
cause PHP to crash, resulting in a denial of service, or possibly execute
arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
libapache2-mod-php8.1 8.1.2-1ubuntu2.2
php8.1-cgi 8.1.2-1ubuntu2.2
php8.1-cli 8.1.2-1ubuntu2.2
php8.1-fpm 8.1.2-1ubuntu2.2
php8.1-mysql 8.1.2-1ubuntu2.2
php8.1-pgsql 8.1.2-1ubuntu2.2

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5530-1
CVE-2022-31627

Package Information:
https://launchpad.net/ubuntu/+source/php8.1/8.1.2-1ubuntu2.2

Sunday, July 24, 2022

OpenBSD Errata: July 24, 2022 (xserver cron)

Errata patches for X11 server and cron daemon have been released
for OpenBSD 7.0 and 7.1.

Binary updates for the amd64, i386 and arm64 platform are available
via the syspatch utility. Source code patches can be found on the
respective errata page:

https://www.openbsd.org/errata71.html
https://www.openbsd.org/errata70.html

Wednesday, July 20, 2022

[USN-5529-1] Linux kernel (OEM) vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5529-1
July 21, 2022

linux-oem-5.17 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-oem-5.17: Linux kernel for OEM systems

Details:

It was discovered that the Atheros ath9k wireless device driver in the
Linux kernel did not properly handle some error conditions, leading to a
use-after-free vulnerability. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2022-1679)

Yongkang Jia discovered that the KVM hypervisor implementation in the Linux
kernel did not properly handle guest TLB mapping invalidation requests in
some situations. An attacker in a guest VM could use this to cause a denial
of service (system crash) in the host OS. (CVE-2022-1789)

Qiuhao Li, Gaoning Pan, and Yongkang Jia discovered that the KVM hypervisor
implementation in the Linux kernel did not properly handle an illegal
instruction in a guest, resulting in a null pointer dereference. An
attacker in a guest VM could use this to cause a denial of service (system
crash) in the host OS. (CVE-2022-1852)

Gerald Lee discovered that the NTFS file system implementation in the Linux
kernel did not properly handle certain error conditions, leading to a use-
after-free vulnerability. A local attacker could use this to cause a denial
of service (system crash) or possibly expose sensitive information.
(CVE-2022-1973)

It was discovered that the netfilter subsystem in the Linux kernel
contained a buffer overflow in certain situations. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2022-2078)

It was discovered that some Intel processors did not completely perform
cleanup actions on multi-core shared buffers. A local attacker could
possibly use this to expose sensitive information. (CVE-2022-21123)

It was discovered that some Intel processors did not completely perform
cleanup actions on microarchitectural fill buffers. A local attacker could
possibly use this to expose sensitive information. (CVE-2022-21125)

It was discovered that some Intel processors did not properly perform
cleanup during specific special register write operations. A local attacker
could possibly use this to expose sensitive information. (CVE-2022-21166)

It was discovered that the virtio RPMSG bus driver in the Linux kernel
contained a double-free vulnerability in certain error conditions. A local
attacker could possibly use this to cause a denial of service (system
crash). (CVE-2022-34494, CVE-2022-34495)

Minh Yuan discovered that the floppy disk driver in the Linux kernel
contained a race condition, leading to a use-after-free vulnerability. A
local attacker could possibly use this to cause a denial of service (system
crash) or execute arbitrary code. (CVE-2022-1652)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
linux-image-5.17.0-1013-oem 5.17.0-1013.14
linux-image-oem-22.04 5.17.0.1013.12
linux-image-oem-22.04a 5.17.0.1013.12

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-5529-1
CVE-2022-1652, CVE-2022-1679, CVE-2022-1789, CVE-2022-1852,
CVE-2022-1973, CVE-2022-2078, CVE-2022-21123, CVE-2022-21125,
CVE-2022-21166, CVE-2022-34494, CVE-2022-34495

Package Information:
https://launchpad.net/ubuntu/+source/linux-oem-5.17/5.17.0-1013.14

Some spins/labs to be dropped from F37

In accordance with FESCo's approved[1] keepalive policy, the following
Spins/Labs will be dropped from F37 unless new maintainers step up.

## Maintainer indicated they do not have time to maintain for this release
* Robotics Spin — https://fedoraproject.org/wiki/Robotics_Spin

## Maintainer did not respond to pings
* Games Spin — https://fedoraproject.org/wiki/Games_Spin
* Security Spin — https://fedoraproject.org/wiki/Security_Spin

If you'd like to become a maintainer of one of these, please comment
on the corresponding ticket in the schedule repo[2]. If you want to
know what goes into maintaining a Spin/Lab, see the Releases docs[3].


[1] https://pagure.io/fesco/issue/1972
[2] https://pagure.io/fedora-pgm/schedule/issues?tags=spins+keepalive
[3] https://docs.fedoraproject.org/en-US/releases/spins/maintaining/

--
Ben Cotton
He / Him / His
Fedora Program Manager
Red Hat
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure