-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmWcUUkACgkQZWnYVadE
vpP6sA//Q8jdGEeboBT6n747ePrb0+Z8YGjVMp8LWhUs3YeDzSAyjb8MP+s9rZmG
l9jP0XPgHFnjI7WdRd2veOaMDgydwumyBN3yRJ9KF0Xan2sMh+U02AJbhSViMUz3
rpHH1gJhI6WJXX0V2Yn5HwbZpWuQ2QjHftGVcxbb12AQe+JXQUgtWqxipXxoezjz
bzPDRg+1eb/VP9y2iLuo9Pd2jVg25VY0z1lu5ggVIsVZFHa55M3T4lYpHZ/55EfC
4yjBF2fozkWm9zbqcKKtukx8xNfWHcZ871BMXo6MB28QNoK4ddwQQlQy2QNu8nk6
DW0dF7O0k08T+d8BtFiZzVDC9TahvXe/aF5Oz5NpUYc/1bg2Vns7n77CBo+ubgD0
Es1uFVhliC6OPSOlRvt2VKjJ3LxY42faQ6pDfth933QOX1Xl4kt/Z03C4vUST7dH
7pj0lwEEIPMdiTqDKOFE0bOtEnyHSwTyc0ZyBdG+OImOhqE36X4PcvQTTavycQAN
qmpQq81PpJhT0aU1Fv/LwWV37mrkJYN9PbJJTnYND3/skdTGFjGlCPqMlBaSRdXc
s55FnBxTUk3Z79rXRrOTAXoNEBEqVtMeHyzFoQVbd0IZZrn7ShbecaMEFxq+GNtq
z7EO1Z2rS8tg2SxA7fx2JRKYlKIJlgdfF0xFE1fr8zy5arw99y0=
=5GlP
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6568-1
January 08, 2024
clamav update
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
ClamAV was updated to remain compatible with signature database downloads.
Software Description:
- clamav: Anti-virus utility for Unix
Details:
The ClamAV package was updated to a new upstream version to remain
compatible with signature database downloads.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
clamav 1.0.4+dfsg-0ubuntu0.23.10.1
Ubuntu 23.04:
clamav 0.103.11+dfsg-0ubuntu0.23.04.1
Ubuntu 22.04 LTS:
clamav 0.103.11+dfsg-0ubuntu0.22.04.1
Ubuntu 20.04 LTS:
clamav 0.103.11+dfsg-0ubuntu0.20.04.1
This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
References:
https://ubuntu.com/security/notices/USN-6568-1
https://launchpad.net/bugs/2046581
Package Information:
https://launchpad.net/ubuntu/+source/clamav/1.0.4+dfsg-0ubuntu0.23.10.1
https://launchpad.net/ubuntu/+source/clamav/0.103.11+dfsg-0ubuntu0.23.04.1
https://launchpad.net/ubuntu/+source/clamav/0.103.11+dfsg-0ubuntu0.22.04.1
https://launchpad.net/ubuntu/+source/clamav/0.103.11+dfsg-0ubuntu0.20.04.1
Monday, January 8, 2024
[USN-6569-1] libclamunrar vulnerabilities
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmWcUPQACgkQZWnYVadE
vpNrrQ//SOgZDSswTww7wbXXep9vM6G8fVPJ7tPdBAVO2lEhX5WI6puAzwHETolH
e5qAYkjItsYrbI0ViMWl4QjCZaVx5imFn9UbpzAQvVoWV6SDkUpr/1oAyeBYOWjB
raaOE95tqQ3ggqXF2UWXtoHFlYbU7V02k7a25O9xlLDh6AYiEW5QheWdYxPHWPkS
NkHhyZCKK9SxIYvrY0DuV/NYF9RQRpcRjXa/UDhBpLYCG40QrRDDleOkl15n01G/
8S4FcuMr2MajPjqvZ2HYN47JlEfqu+B8Yj/EYdFRBGzt+1cYGpz9atShbYsCJUQb
zbDzYFfG2tH+ET1gfQzC3/BA5OpzkGGWkBHkRRuOVJSC5c4+g2FUvwMHy+/xdpZB
tTDzqONY2xi5mzfhof9SlYD1AGeLs36YnG07yL8V0d3zbwyhASm5FysLZeMjmHaP
c0K8YYmBeC4OJwMChQ5lpHfcei51kNUymvCx4ngEwnU3YgNuFwuB7nw+WzYZd1AM
idnesG6gz1CgzFiYQt52s+uHqlQVVK0KnkTd1bzV2NJx80VBSv83JPMhALZhg7Dm
PH4mXF22Q/jnp/etTYhi6qNS8HI+qFMCM4dKa+TJI749I0YgmnIz2IIZCyqyHiM8
i7fT3k9nKcEmYD3QxfkA2rcnZ/Yt28wdVV2Egis0eTZJjfU0yI0=
=nlvN
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6569-1
January 08, 2024
libclamunrar vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in libclamunrar.
Software Description:
- libclamunrar: anti-virus utility for Unix - unrar support
Details:
it was discovered that libclamunrar incorrectly handled directories when
extracting RAR archives. A remote attacker could possibly use this issue to
overwrite arbitrary files and execute arbitrary code. This issue only
affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.04.
(CVE-2022-30333)
It was discovered that libclamunrar incorrectly validated certain
structures when extracting RAR archives. A remote attacker could possibly
use this issue to execute arbitrary code. (CVE-2023-40477)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
libclamunrar11 1.0.4-0ubuntu0.23.10.1
Ubuntu 23.04:
libclamunrar9 0.103.11-0ubuntu0.23.04.1
Ubuntu 22.04 LTS:
libclamunrar9 0.103.11-0ubuntu0.22.04.1
Ubuntu 20.04 LTS:
libclamunrar9 0.103.11-0ubuntu0.20.04.1
This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
References:
https://ubuntu.com/security/notices/USN-6569-1
CVE-2022-30333, CVE-2023-40477
Package Information:
https://launchpad.net/ubuntu/+source/libclamunrar/1.0.4-0ubuntu0.23.10.1
https://launchpad.net/ubuntu/+source/libclamunrar/0.103.11-0ubuntu0.23.04.1
https://launchpad.net/ubuntu/+source/libclamunrar/0.103.11-0ubuntu0.22.04.1
https://launchpad.net/ubuntu/+source/libclamunrar/0.103.11-0ubuntu0.20.04.1
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmWcUPQACgkQZWnYVadE
vpNrrQ//SOgZDSswTww7wbXXep9vM6G8fVPJ7tPdBAVO2lEhX5WI6puAzwHETolH
e5qAYkjItsYrbI0ViMWl4QjCZaVx5imFn9UbpzAQvVoWV6SDkUpr/1oAyeBYOWjB
raaOE95tqQ3ggqXF2UWXtoHFlYbU7V02k7a25O9xlLDh6AYiEW5QheWdYxPHWPkS
NkHhyZCKK9SxIYvrY0DuV/NYF9RQRpcRjXa/UDhBpLYCG40QrRDDleOkl15n01G/
8S4FcuMr2MajPjqvZ2HYN47JlEfqu+B8Yj/EYdFRBGzt+1cYGpz9atShbYsCJUQb
zbDzYFfG2tH+ET1gfQzC3/BA5OpzkGGWkBHkRRuOVJSC5c4+g2FUvwMHy+/xdpZB
tTDzqONY2xi5mzfhof9SlYD1AGeLs36YnG07yL8V0d3zbwyhASm5FysLZeMjmHaP
c0K8YYmBeC4OJwMChQ5lpHfcei51kNUymvCx4ngEwnU3YgNuFwuB7nw+WzYZd1AM
idnesG6gz1CgzFiYQt52s+uHqlQVVK0KnkTd1bzV2NJx80VBSv83JPMhALZhg7Dm
PH4mXF22Q/jnp/etTYhi6qNS8HI+qFMCM4dKa+TJI749I0YgmnIz2IIZCyqyHiM8
i7fT3k9nKcEmYD3QxfkA2rcnZ/Yt28wdVV2Egis0eTZJjfU0yI0=
=nlvN
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6569-1
January 08, 2024
libclamunrar vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in libclamunrar.
Software Description:
- libclamunrar: anti-virus utility for Unix - unrar support
Details:
it was discovered that libclamunrar incorrectly handled directories when
extracting RAR archives. A remote attacker could possibly use this issue to
overwrite arbitrary files and execute arbitrary code. This issue only
affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.04.
(CVE-2022-30333)
It was discovered that libclamunrar incorrectly validated certain
structures when extracting RAR archives. A remote attacker could possibly
use this issue to execute arbitrary code. (CVE-2023-40477)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
libclamunrar11 1.0.4-0ubuntu0.23.10.1
Ubuntu 23.04:
libclamunrar9 0.103.11-0ubuntu0.23.04.1
Ubuntu 22.04 LTS:
libclamunrar9 0.103.11-0ubuntu0.22.04.1
Ubuntu 20.04 LTS:
libclamunrar9 0.103.11-0ubuntu0.20.04.1
This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
References:
https://ubuntu.com/security/notices/USN-6569-1
CVE-2022-30333, CVE-2023-40477
Package Information:
https://launchpad.net/ubuntu/+source/libclamunrar/1.0.4-0ubuntu0.23.10.1
https://launchpad.net/ubuntu/+source/libclamunrar/0.103.11-0ubuntu0.23.04.1
https://launchpad.net/ubuntu/+source/libclamunrar/0.103.11-0ubuntu0.22.04.1
https://launchpad.net/ubuntu/+source/libclamunrar/0.103.11-0ubuntu0.20.04.1
[USN-6567-1] QEMU vulnerabilities
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmWcUKoACgkQZWnYVadE
vpOrMg/9HmBE+o5DLjlPUyIDcnJJcKlg3Gz295W2cgdUZ6FWQQhOGzznJJav2Qgb
PTUHq+sKZqacO8bf6BkFgKxQNu3cCSAgIsJdepW16XCRtuQM0jYneirSMcc5QGRE
HSHw6oGxnZjxfKomo1Q0bz96sqEHNPm/W4q4T2SMablM3Qlgr4llJ/uWH64H3PKm
AddUX1oDvk9n70e0tC+PznnD+iHFlCqymgYO9JHzRU6oR32G1EZUkMwnmgdipIBX
AAiR2Nb33hVWERYikosYQR0qxgL2ezkVjZ2wIbTReVczz4VqN09/zxo3ueg7nUsb
BNMl8w5T0VJRAHB1/Sce/c0xUZmSUfJWNzsX8YAD/TvZQsItmsh1BlLvv7pNdpI+
BfZqIEXyxCQpBTsA38BRM3jszH/AJJSXKJGO8YzQeejR8cA6GlJ5tRIa+a9cecsy
LxbH/E5+jgJ3xo6fdfBqocGCF0xtVq6nLiIgJKcI/J9pweNCWS6dqRI11lXHJqeC
RH6Hbti31FLVMoc+CDDddGjJc61Elxe2cE9X7VtW2Ou3R2AFJWeHPNIrXG372uZz
t8ZJvSXqVv17QzKBaAkmsT9Cbuoenl6SQOFgTJse+o0FP62GeuGxGnGk2Osbs9lh
t105fYXSaW8L8+rqH+js4peNkkZlBu4l9HsQi2WbsXhrp0wONb4=
=QIlg
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6567-1
January 08, 2024
qemu vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in QEMU.
Software Description:
- qemu: Machine emulator and virtualizer
Details:
Gaoning Pan and Xingwei Li discovered that QEMU incorrectly handled the
USB xHCI controller device. A privileged guest attacker could possibly use
this issue to cause QEMU to crash, leading to a denial of service. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2020-14394)
It was discovered that QEMU incorrectly handled the TCG Accelerator. A
local attacker could use this issue to cause QEMU to crash, leading to a
denial of service, or possibly execute arbitrary code and esclate
privileges. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-24165)
It was discovered that QEMU incorrectly handled the Intel HD audio device.
A malicious guest attacker could use this issue to cause QEMU to crash,
leading to a denial of service. This issue only affected Ubuntu 22.04 LTS.
(CVE-2021-3611)
It was discovered that QEMU incorrectly handled the ATI VGA device. A
malicious guest attacker could use this issue to cause QEMU to crash,
leading to a denial of service. This issue only affected Ubuntu 20.04 LTS.
(CVE-2021-3638)
It was discovered that QEMU incorrectly handled the VMWare paravirtual RDMA
device. A malicious guest attacker could use this issue to cause QEMU to
crash, leading to a denial of service. (CVE-2023-1544)
It was discovered that QEMU incorrectly handled the 9p passthrough
filesystem. A malicious guest attacker could possibly use this issue to
open special files and escape the exported 9p tree. This issue only
affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.04.
(CVE-2023-2861)
It was discovered that QEMU incorrectly handled the virtual crypto device.
A malicious guest attacker could use this issue to cause QEMU to crash,
leading to a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.04.
(CVE-2023-3180)
It was discovered that QEMU incorrectly handled the built-in VNC server.
A remote authenticated attacker could possibly use this issue to cause QEMU
to stop responding, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 23.04. (CVE-2023-3255)
It was discovered that QEMU incorrectly handled net device hot-unplugging.
A malicious guest attacker could use this issue to cause QEMU to crash,
leading to a denial of service. This issue only affected Ubuntu 22.04 LTS
and Ubuntu 23.04. (CVE-2023-3301)
It was discovered that QEMU incorrectly handled the built-in VNC server.
A remote attacker could possibly use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, and Ubuntu 23.04. (CVE-2023-3354)
It was discovered that QEMU incorrectly handled NVME devices. A malicious
guest attacker could use this issue to cause QEMU to crash, leading to a
denial of service. This issue only affected Ubuntu 23.10. (CVE-2023-40360)
It was discovered that QEMU incorrectly handled NVME devices. A malicious
guest attacker could use this issue to cause QEMU to crash, leading to a
denial of service, or possibly obtain sensitive information. This issue
only affected Ubuntu 23.10. (CVE-2023-4135)
It was discovered that QEMU incorrectly handled SCSI devices. A malicious
guest attacker could use this issue to cause QEMU to crash, leading to a
denial of service. This issue only affected Ubuntu 23.04 and Ubuntu 23.10.
(CVE-2023-42467)
It was discovered that QEMU incorrectly handled certain disk offsets. A
malicious guest attacker could possibly use this issue to gain control of
the host in certain nested virtualization scenarios. (CVE-2023-5088)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
qemu-system 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-arm 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-mips 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-misc 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-ppc 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-s390x 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-sparc 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-x86 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-x86-xen 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-xen 1:8.0.4+dfsg-1ubuntu3.23.10.2
Ubuntu 23.04:
qemu-system 1:7.2+dfsg-5ubuntu2.4
qemu-system-arm 1:7.2+dfsg-5ubuntu2.4
qemu-system-mips 1:7.2+dfsg-5ubuntu2.4
qemu-system-misc 1:7.2+dfsg-5ubuntu2.4
qemu-system-ppc 1:7.2+dfsg-5ubuntu2.4
qemu-system-s390x 1:7.2+dfsg-5ubuntu2.4
qemu-system-sparc 1:7.2+dfsg-5ubuntu2.4
qemu-system-x86 1:7.2+dfsg-5ubuntu2.4
qemu-system-x86-xen 1:7.2+dfsg-5ubuntu2.4
qemu-system-xen 1:7.2+dfsg-5ubuntu2.4
Ubuntu 22.04 LTS:
qemu 1:6.2+dfsg-2ubuntu6.16
qemu-system-arm 1:6.2+dfsg-2ubuntu6.16
qemu-system-mips 1:6.2+dfsg-2ubuntu6.16
qemu-system-misc 1:6.2+dfsg-2ubuntu6.16
qemu-system-ppc 1:6.2+dfsg-2ubuntu6.16
qemu-system-s390x 1:6.2+dfsg-2ubuntu6.16
qemu-system-sparc 1:6.2+dfsg-2ubuntu6.16
qemu-system-x86 1:6.2+dfsg-2ubuntu6.16
qemu-system-x86-microvm 1:6.2+dfsg-2ubuntu6.16
qemu-system-x86-xen 1:6.2+dfsg-2ubuntu6.16
Ubuntu 20.04 LTS:
qemu 1:4.2-3ubuntu6.28
qemu-system 1:4.2-3ubuntu6.28
qemu-system-arm 1:4.2-3ubuntu6.28
qemu-system-mips 1:4.2-3ubuntu6.28
qemu-system-misc 1:4.2-3ubuntu6.28
qemu-system-ppc 1:4.2-3ubuntu6.28
qemu-system-s390x 1:4.2-3ubuntu6.28
qemu-system-sparc 1:4.2-3ubuntu6.28
qemu-system-x86 1:4.2-3ubuntu6.28
qemu-system-x86-microvm 1:4.2-3ubuntu6.28
qemu-system-x86-xen 1:4.2-3ubuntu6.28
After a standard system update you need to restart all QEMU virtual
machines to make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6567-1
CVE-2020-14394, CVE-2020-24165, CVE-2021-3611, CVE-2021-3638,
CVE-2023-1544, CVE-2023-2861, CVE-2023-3180, CVE-2023-3255,
CVE-2023-3301, CVE-2023-3354, CVE-2023-40360, CVE-2023-4135,
CVE-2023-42467, CVE-2023-5088
Package Information:
https://launchpad.net/ubuntu/+source/qemu/1:8.0.4+dfsg-1ubuntu3.23.10.2
https://launchpad.net/ubuntu/+source/qemu/1:7.2+dfsg-5ubuntu2.4
https://launchpad.net/ubuntu/+source/qemu/1:6.2+dfsg-2ubuntu6.16
https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.28
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmWcUKoACgkQZWnYVadE
vpOrMg/9HmBE+o5DLjlPUyIDcnJJcKlg3Gz295W2cgdUZ6FWQQhOGzznJJav2Qgb
PTUHq+sKZqacO8bf6BkFgKxQNu3cCSAgIsJdepW16XCRtuQM0jYneirSMcc5QGRE
HSHw6oGxnZjxfKomo1Q0bz96sqEHNPm/W4q4T2SMablM3Qlgr4llJ/uWH64H3PKm
AddUX1oDvk9n70e0tC+PznnD+iHFlCqymgYO9JHzRU6oR32G1EZUkMwnmgdipIBX
AAiR2Nb33hVWERYikosYQR0qxgL2ezkVjZ2wIbTReVczz4VqN09/zxo3ueg7nUsb
BNMl8w5T0VJRAHB1/Sce/c0xUZmSUfJWNzsX8YAD/TvZQsItmsh1BlLvv7pNdpI+
BfZqIEXyxCQpBTsA38BRM3jszH/AJJSXKJGO8YzQeejR8cA6GlJ5tRIa+a9cecsy
LxbH/E5+jgJ3xo6fdfBqocGCF0xtVq6nLiIgJKcI/J9pweNCWS6dqRI11lXHJqeC
RH6Hbti31FLVMoc+CDDddGjJc61Elxe2cE9X7VtW2Ou3R2AFJWeHPNIrXG372uZz
t8ZJvSXqVv17QzKBaAkmsT9Cbuoenl6SQOFgTJse+o0FP62GeuGxGnGk2Osbs9lh
t105fYXSaW8L8+rqH+js4peNkkZlBu4l9HsQi2WbsXhrp0wONb4=
=QIlg
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6567-1
January 08, 2024
qemu vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in QEMU.
Software Description:
- qemu: Machine emulator and virtualizer
Details:
Gaoning Pan and Xingwei Li discovered that QEMU incorrectly handled the
USB xHCI controller device. A privileged guest attacker could possibly use
this issue to cause QEMU to crash, leading to a denial of service. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2020-14394)
It was discovered that QEMU incorrectly handled the TCG Accelerator. A
local attacker could use this issue to cause QEMU to crash, leading to a
denial of service, or possibly execute arbitrary code and esclate
privileges. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-24165)
It was discovered that QEMU incorrectly handled the Intel HD audio device.
A malicious guest attacker could use this issue to cause QEMU to crash,
leading to a denial of service. This issue only affected Ubuntu 22.04 LTS.
(CVE-2021-3611)
It was discovered that QEMU incorrectly handled the ATI VGA device. A
malicious guest attacker could use this issue to cause QEMU to crash,
leading to a denial of service. This issue only affected Ubuntu 20.04 LTS.
(CVE-2021-3638)
It was discovered that QEMU incorrectly handled the VMWare paravirtual RDMA
device. A malicious guest attacker could use this issue to cause QEMU to
crash, leading to a denial of service. (CVE-2023-1544)
It was discovered that QEMU incorrectly handled the 9p passthrough
filesystem. A malicious guest attacker could possibly use this issue to
open special files and escape the exported 9p tree. This issue only
affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.04.
(CVE-2023-2861)
It was discovered that QEMU incorrectly handled the virtual crypto device.
A malicious guest attacker could use this issue to cause QEMU to crash,
leading to a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.04.
(CVE-2023-3180)
It was discovered that QEMU incorrectly handled the built-in VNC server.
A remote authenticated attacker could possibly use this issue to cause QEMU
to stop responding, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 23.04. (CVE-2023-3255)
It was discovered that QEMU incorrectly handled net device hot-unplugging.
A malicious guest attacker could use this issue to cause QEMU to crash,
leading to a denial of service. This issue only affected Ubuntu 22.04 LTS
and Ubuntu 23.04. (CVE-2023-3301)
It was discovered that QEMU incorrectly handled the built-in VNC server.
A remote attacker could possibly use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, and Ubuntu 23.04. (CVE-2023-3354)
It was discovered that QEMU incorrectly handled NVME devices. A malicious
guest attacker could use this issue to cause QEMU to crash, leading to a
denial of service. This issue only affected Ubuntu 23.10. (CVE-2023-40360)
It was discovered that QEMU incorrectly handled NVME devices. A malicious
guest attacker could use this issue to cause QEMU to crash, leading to a
denial of service, or possibly obtain sensitive information. This issue
only affected Ubuntu 23.10. (CVE-2023-4135)
It was discovered that QEMU incorrectly handled SCSI devices. A malicious
guest attacker could use this issue to cause QEMU to crash, leading to a
denial of service. This issue only affected Ubuntu 23.04 and Ubuntu 23.10.
(CVE-2023-42467)
It was discovered that QEMU incorrectly handled certain disk offsets. A
malicious guest attacker could possibly use this issue to gain control of
the host in certain nested virtualization scenarios. (CVE-2023-5088)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
qemu-system 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-arm 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-mips 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-misc 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-ppc 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-s390x 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-sparc 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-x86 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-x86-xen 1:8.0.4+dfsg-1ubuntu3.23.10.2
qemu-system-xen 1:8.0.4+dfsg-1ubuntu3.23.10.2
Ubuntu 23.04:
qemu-system 1:7.2+dfsg-5ubuntu2.4
qemu-system-arm 1:7.2+dfsg-5ubuntu2.4
qemu-system-mips 1:7.2+dfsg-5ubuntu2.4
qemu-system-misc 1:7.2+dfsg-5ubuntu2.4
qemu-system-ppc 1:7.2+dfsg-5ubuntu2.4
qemu-system-s390x 1:7.2+dfsg-5ubuntu2.4
qemu-system-sparc 1:7.2+dfsg-5ubuntu2.4
qemu-system-x86 1:7.2+dfsg-5ubuntu2.4
qemu-system-x86-xen 1:7.2+dfsg-5ubuntu2.4
qemu-system-xen 1:7.2+dfsg-5ubuntu2.4
Ubuntu 22.04 LTS:
qemu 1:6.2+dfsg-2ubuntu6.16
qemu-system-arm 1:6.2+dfsg-2ubuntu6.16
qemu-system-mips 1:6.2+dfsg-2ubuntu6.16
qemu-system-misc 1:6.2+dfsg-2ubuntu6.16
qemu-system-ppc 1:6.2+dfsg-2ubuntu6.16
qemu-system-s390x 1:6.2+dfsg-2ubuntu6.16
qemu-system-sparc 1:6.2+dfsg-2ubuntu6.16
qemu-system-x86 1:6.2+dfsg-2ubuntu6.16
qemu-system-x86-microvm 1:6.2+dfsg-2ubuntu6.16
qemu-system-x86-xen 1:6.2+dfsg-2ubuntu6.16
Ubuntu 20.04 LTS:
qemu 1:4.2-3ubuntu6.28
qemu-system 1:4.2-3ubuntu6.28
qemu-system-arm 1:4.2-3ubuntu6.28
qemu-system-mips 1:4.2-3ubuntu6.28
qemu-system-misc 1:4.2-3ubuntu6.28
qemu-system-ppc 1:4.2-3ubuntu6.28
qemu-system-s390x 1:4.2-3ubuntu6.28
qemu-system-sparc 1:4.2-3ubuntu6.28
qemu-system-x86 1:4.2-3ubuntu6.28
qemu-system-x86-microvm 1:4.2-3ubuntu6.28
qemu-system-x86-xen 1:4.2-3ubuntu6.28
After a standard system update you need to restart all QEMU virtual
machines to make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6567-1
CVE-2020-14394, CVE-2020-24165, CVE-2021-3611, CVE-2021-3638,
CVE-2023-1544, CVE-2023-2861, CVE-2023-3180, CVE-2023-3255,
CVE-2023-3301, CVE-2023-3354, CVE-2023-40360, CVE-2023-4135,
CVE-2023-42467, CVE-2023-5088
Package Information:
https://launchpad.net/ubuntu/+source/qemu/1:8.0.4+dfsg-1ubuntu3.23.10.2
https://launchpad.net/ubuntu/+source/qemu/1:7.2+dfsg-5ubuntu2.4
https://launchpad.net/ubuntu/+source/qemu/1:6.2+dfsg-2ubuntu6.16
https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.28
[USN-6499-2] GnuTLS vulnerability
-----BEGIN PGP SIGNATURE-----
wsB5BAABCAAjFiEEGq96SdAIJY1vInRLbzAtCH6LqTYFAmWb4wYFAwAAAAAACgkQbzAtCH6LqTbu
QQf+NYlg2hsCjSEr2lH3IX1p6J2ixiNL4/KOwJIFnplk3Hf1/8Fx560htV0Gxe9+avILP8gYQila
4ejJuZnMIpov2ybD1icNyMrSM2S5dwb8bIiVYqZgrTqaE2Nqd6QXctvJCNUqTq5NGUtLlCmenN++
T3WlXlICwi4O9slFQr8XvMwoquCvYNdxU1SeoC0bmEj+hMspaS458auSh8KCzJytWQsE0tOg5hM1
mjctMcdfyYzSoH9aggB04TKifDdYwkT9s99cRCkeuRMRxhMbW5WOzdHbk5jANhjgZgTbuUnHeebx
nn1+ruom7MHPrQqpctmXeJSeWoazR2j7ABhHOZ+LjQ==
=+BJw
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6499-2
January 08, 2024
gnutls28 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
Summary:
GnuTLS could be made to expose sensitive information over the network.
Software Description:
- gnutls28: GNU TLS library
Details:
USN-6499-1 fixed vulnerabilities in GnuTLS. This update provides the
corresponding update for Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that GnuTLS had a timing side-channel when handling
certain RSA-PSK key exchanges. A remote attacker could possibly use this
issue to recover sensitive information.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS (Available with Ubuntu Pro):
libgnutls30 3.5.18-1ubuntu1.6+esm1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6499-2
https://ubuntu.com/security/notices/USN-6499-1
CVE-2023-5981
wsB5BAABCAAjFiEEGq96SdAIJY1vInRLbzAtCH6LqTYFAmWb4wYFAwAAAAAACgkQbzAtCH6LqTbu
QQf+NYlg2hsCjSEr2lH3IX1p6J2ixiNL4/KOwJIFnplk3Hf1/8Fx560htV0Gxe9+avILP8gYQila
4ejJuZnMIpov2ybD1icNyMrSM2S5dwb8bIiVYqZgrTqaE2Nqd6QXctvJCNUqTq5NGUtLlCmenN++
T3WlXlICwi4O9slFQr8XvMwoquCvYNdxU1SeoC0bmEj+hMspaS458auSh8KCzJytWQsE0tOg5hM1
mjctMcdfyYzSoH9aggB04TKifDdYwkT9s99cRCkeuRMRxhMbW5WOzdHbk5jANhjgZgTbuUnHeebx
nn1+ruom7MHPrQqpctmXeJSeWoazR2j7ABhHOZ+LjQ==
=+BJw
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6499-2
January 08, 2024
gnutls28 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
Summary:
GnuTLS could be made to expose sensitive information over the network.
Software Description:
- gnutls28: GNU TLS library
Details:
USN-6499-1 fixed vulnerabilities in GnuTLS. This update provides the
corresponding update for Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that GnuTLS had a timing side-channel when handling
certain RSA-PSK key exchanges. A remote attacker could possibly use this
issue to recover sensitive information.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS (Available with Ubuntu Pro):
libgnutls30 3.5.18-1ubuntu1.6+esm1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6499-2
https://ubuntu.com/security/notices/USN-6499-1
CVE-2023-5981
Friday, January 5, 2024
[USN-6549-4] Linux kernel (Intel IoTG) vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmWYBwUFAwAAAAAACgkQZ0GeRcM5nt1S
MwgAlmmwjex4aT4isQ/il7oBa9NHoOC5tdNrQxP71FlqQ7qTvNsfEt20ShTMoKS+SuTR542DBleo
+qXG55SwMfjQlfXrS1vwHGwKvKyuDy+AycjarxSC9CDM+Gvy1ZfQZUtLF75WbYOFt1i2rdr/G8p/
PhkWCY/OS/sK2vfoftM6r+yWXptHmvCAGi1AE3+teEzhgc3RWBcMRENnM07BsKD1WsKoodlsYCbm
COSQdz8AoM15sK8XG5+3CC042pHqW5Qd11dJ3WGuo0NqX3z26XV/aTuqV+NcKecs+nCNv01sjLO/
hYjsHuz8FHXZtVG1wf6Io6gXoZOvlTwNu9zy+ezBLw==
=8mXv
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6549-4
January 05, 2024
linux-intel-iotg vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-intel-iotg: Linux kernel for Intel IoT platforms
Details:
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel did not properly initialize a policy data structure, leading
to an out-of-bounds vulnerability. A local privileged attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information (kernel memory). (CVE-2023-3773)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Sunjoo Park discovered that the netfilter subsystem in the Linux kernel did
not properly validate u32 packets content, leading to an out-of-bounds read
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly expose sensitive information. (CVE-2023-39192)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate SCTP data, leading to an out-of-bounds read
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly expose sensitive information. (CVE-2023-39193)
Lucas Leong discovered that the Netlink Transformation (XFRM) subsystem in
the Linux kernel did not properly handle state filters, leading to an out-
of-bounds read vulnerability. A privileged local attacker could use this to
cause a denial of service (system crash) or possibly expose sensitive
information. (CVE-2023-39194)
It was discovered that a race condition existed in QXL virtual GPU driver
in the Linux kernel, leading to a use after free vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2023-39198)
Kyle Zeng discovered that the IPv4 implementation in the Linux kernel did
not properly handle socket buffers (skb) when performing IP routing in
certain circumstances, leading to a null pointer dereference vulnerability.
A privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-42754)
Jason Wang discovered that the virtio ring implementation in the Linux
kernel did not properly handle iov buffers in some situations. A local
attacker in a guest VM could use this to cause a denial of service (host
system crash). (CVE-2023-5158)
Alon Zahavi discovered that the NVMe-oF/TCP subsystem in the Linux kernel
did not properly handle queue initialization failures in certain
situations, leading to a use-after-free vulnerability. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2023-5178)
Budimir Markovic discovered that the perf subsystem in the Linux kernel did
not properly handle event groups, leading to an out-of-bounds write
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-5717)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS:
linux-image-5.15.0-1046-intel-iotg 5.15.0-1046.52
linux-image-intel-iotg 5.15.0.1046.46
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-6549-4
https://ubuntu.com/security/notices/USN-6549-1
CVE-2023-37453, CVE-2023-3773, CVE-2023-39189, CVE-2023-39192,
CVE-2023-39193, CVE-2023-39194, CVE-2023-39198, CVE-2023-42754,
CVE-2023-5158, CVE-2023-5178, CVE-2023-5717
Package Information:
https://launchpad.net/ubuntu/+source/linux-intel-iotg/5.15.0-1046.52
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmWYBwUFAwAAAAAACgkQZ0GeRcM5nt1S
MwgAlmmwjex4aT4isQ/il7oBa9NHoOC5tdNrQxP71FlqQ7qTvNsfEt20ShTMoKS+SuTR542DBleo
+qXG55SwMfjQlfXrS1vwHGwKvKyuDy+AycjarxSC9CDM+Gvy1ZfQZUtLF75WbYOFt1i2rdr/G8p/
PhkWCY/OS/sK2vfoftM6r+yWXptHmvCAGi1AE3+teEzhgc3RWBcMRENnM07BsKD1WsKoodlsYCbm
COSQdz8AoM15sK8XG5+3CC042pHqW5Qd11dJ3WGuo0NqX3z26XV/aTuqV+NcKecs+nCNv01sjLO/
hYjsHuz8FHXZtVG1wf6Io6gXoZOvlTwNu9zy+ezBLw==
=8mXv
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6549-4
January 05, 2024
linux-intel-iotg vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-intel-iotg: Linux kernel for Intel IoT platforms
Details:
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel did not properly initialize a policy data structure, leading
to an out-of-bounds vulnerability. A local privileged attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information (kernel memory). (CVE-2023-3773)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Sunjoo Park discovered that the netfilter subsystem in the Linux kernel did
not properly validate u32 packets content, leading to an out-of-bounds read
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly expose sensitive information. (CVE-2023-39192)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate SCTP data, leading to an out-of-bounds read
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly expose sensitive information. (CVE-2023-39193)
Lucas Leong discovered that the Netlink Transformation (XFRM) subsystem in
the Linux kernel did not properly handle state filters, leading to an out-
of-bounds read vulnerability. A privileged local attacker could use this to
cause a denial of service (system crash) or possibly expose sensitive
information. (CVE-2023-39194)
It was discovered that a race condition existed in QXL virtual GPU driver
in the Linux kernel, leading to a use after free vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2023-39198)
Kyle Zeng discovered that the IPv4 implementation in the Linux kernel did
not properly handle socket buffers (skb) when performing IP routing in
certain circumstances, leading to a null pointer dereference vulnerability.
A privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-42754)
Jason Wang discovered that the virtio ring implementation in the Linux
kernel did not properly handle iov buffers in some situations. A local
attacker in a guest VM could use this to cause a denial of service (host
system crash). (CVE-2023-5158)
Alon Zahavi discovered that the NVMe-oF/TCP subsystem in the Linux kernel
did not properly handle queue initialization failures in certain
situations, leading to a use-after-free vulnerability. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2023-5178)
Budimir Markovic discovered that the perf subsystem in the Linux kernel did
not properly handle event groups, leading to an out-of-bounds write
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-5717)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS:
linux-image-5.15.0-1046-intel-iotg 5.15.0-1046.52
linux-image-intel-iotg 5.15.0.1046.46
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-6549-4
https://ubuntu.com/security/notices/USN-6549-1
CVE-2023-37453, CVE-2023-3773, CVE-2023-39189, CVE-2023-39192,
CVE-2023-39193, CVE-2023-39194, CVE-2023-39198, CVE-2023-42754,
CVE-2023-5158, CVE-2023-5178, CVE-2023-5717
Package Information:
https://launchpad.net/ubuntu/+source/linux-intel-iotg/5.15.0-1046.52
Thursday, January 4, 2024
Last call for the 2024 FreeBSD Community Survey
Last chance to share your opinions on the FreeBSD Project and Foundation! The 2024 FreeBSD Community Survey closes on Monday, January 8, 2024.
Thank you for your help,
The purpose of this survey is to collect quantitative data from the public in order to help guide the Project's priorities and efforts. Your input and feedback are very important to us!
The FreeBSD Core Team and The FreeBSD Foundation
--
Anne Dickison
Marketing Director
FreeBSD Foundation
510.332.8323
Wednesday, January 3, 2024
[USN-6565-1] OpenSSH vulnerabilities
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmWVt6QACgkQZWnYVadE
vpOPIQ//T4LRmWBCcWMlvtaJMmBSHkX9eii2F1eA+YOAURAg08oqOp3SdRgKq+i3
imKew4t+cIk7akfDvW/kAhWXxShzcaCvdprVoRG5DWK/x+4bFbqpAacPX2aKKqHK
rCW/iY096qDj61/LzfoqMEJFgVjuibVRzTyORFxStx7Sj657sNbBnVT+89J9i0hv
W0lQzmaUl4+3OdnjJ7GUfwelxTAknhDNFIkQ8KWdjFsgMtWCeMnqkqYKEuU3ThSS
tYTjogZBoh2OVCFUxgCSgDHi06c9tJph92E7QTjqKR8sesn8OGNLQqdjd53MtBww
W19fCdjfo85zTHjgBZxYsRIMQ5gA06/d9NBPw1Tg948gs6Rs8EY+CInUsMt8Ti4/
uVpB/tL5cDNyynVki/SsQzW95KjrWnUbdbjiEFDEwXeCgKUw8f0tnGvkxg7cYfIP
8cZyJyipWu5XI27yKJwpBcG21rv1fX8TdnEIkBcA6gVQ8/ZHc+NkwH8DzMcJ3Zd6
34XJ6JpvyY7yCCZ6b5cWQzaEGWByguWN3yeFAcxhqfxvO9qt7X4dc35JjDDVi2qn
Gl2GT5cGDryzqgPVh14GFW91lWier8AtWA6bl2NU11xTFFyQ2BqBaGY9RzW6f5We
c79xVDO/Gj0VN8c58p0d865oa7gg0ufr4kJKkLWgYMGBfW6Y2Ek=
=Umlp
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6565-1
January 03, 2024
openssh vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in OpenSSH.
Software Description:
- openssh: secure shell (SSH) for secure access to remote machines
Details:
It was discovered that OpenSSH incorrectly handled supplemental groups when
running helper programs for AuthorizedKeysCommand and
AuthorizedPrincipalsCommand as a different user. An attacker could possibly
use this issue to escalate privileges. This issue only affected Ubuntu
20.04 LTS. (CVE-2021-41617)
It was discovered that OpenSSH incorrectly added destination constraints
when PKCS#11 token keys were added to ssh-agent, contrary to expectations.
This issue only affected Ubuntu 22.04 LTS, and Ubuntu 23.04.
(CVE-2023-51384)
It was discovered that OpenSSH incorrectly handled user names or host names
with shell metacharacters. An attacker could possibly use this issue to
perform OS command injection. (CVE-2023-51385)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
openssh-client 1:9.3p1-1ubuntu3.2
openssh-server 1:9.3p1-1ubuntu3.2
Ubuntu 23.04:
openssh-client 1:9.0p1-1ubuntu8.7
openssh-server 1:9.0p1-1ubuntu8.7
Ubuntu 22.04 LTS:
openssh-client 1:8.9p1-3ubuntu0.6
openssh-server 1:8.9p1-3ubuntu0.6
Ubuntu 20.04 LTS:
openssh-client 1:8.2p1-4ubuntu0.11
openssh-server 1:8.2p1-4ubuntu0.11
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6565-1
CVE-2021-41617, CVE-2023-51384, CVE-2023-51385
Package Information:
https://launchpad.net/ubuntu/+source/openssh/1:9.3p1-1ubuntu3.2
https://launchpad.net/ubuntu/+source/openssh/1:9.0p1-1ubuntu8.7
https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.6
https://launchpad.net/ubuntu/+source/openssh/1:8.2p1-4ubuntu0.11
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmWVt6QACgkQZWnYVadE
vpOPIQ//T4LRmWBCcWMlvtaJMmBSHkX9eii2F1eA+YOAURAg08oqOp3SdRgKq+i3
imKew4t+cIk7akfDvW/kAhWXxShzcaCvdprVoRG5DWK/x+4bFbqpAacPX2aKKqHK
rCW/iY096qDj61/LzfoqMEJFgVjuibVRzTyORFxStx7Sj657sNbBnVT+89J9i0hv
W0lQzmaUl4+3OdnjJ7GUfwelxTAknhDNFIkQ8KWdjFsgMtWCeMnqkqYKEuU3ThSS
tYTjogZBoh2OVCFUxgCSgDHi06c9tJph92E7QTjqKR8sesn8OGNLQqdjd53MtBww
W19fCdjfo85zTHjgBZxYsRIMQ5gA06/d9NBPw1Tg948gs6Rs8EY+CInUsMt8Ti4/
uVpB/tL5cDNyynVki/SsQzW95KjrWnUbdbjiEFDEwXeCgKUw8f0tnGvkxg7cYfIP
8cZyJyipWu5XI27yKJwpBcG21rv1fX8TdnEIkBcA6gVQ8/ZHc+NkwH8DzMcJ3Zd6
34XJ6JpvyY7yCCZ6b5cWQzaEGWByguWN3yeFAcxhqfxvO9qt7X4dc35JjDDVi2qn
Gl2GT5cGDryzqgPVh14GFW91lWier8AtWA6bl2NU11xTFFyQ2BqBaGY9RzW6f5We
c79xVDO/Gj0VN8c58p0d865oa7gg0ufr4kJKkLWgYMGBfW6Y2Ek=
=Umlp
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6565-1
January 03, 2024
openssh vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in OpenSSH.
Software Description:
- openssh: secure shell (SSH) for secure access to remote machines
Details:
It was discovered that OpenSSH incorrectly handled supplemental groups when
running helper programs for AuthorizedKeysCommand and
AuthorizedPrincipalsCommand as a different user. An attacker could possibly
use this issue to escalate privileges. This issue only affected Ubuntu
20.04 LTS. (CVE-2021-41617)
It was discovered that OpenSSH incorrectly added destination constraints
when PKCS#11 token keys were added to ssh-agent, contrary to expectations.
This issue only affected Ubuntu 22.04 LTS, and Ubuntu 23.04.
(CVE-2023-51384)
It was discovered that OpenSSH incorrectly handled user names or host names
with shell metacharacters. An attacker could possibly use this issue to
perform OS command injection. (CVE-2023-51385)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
openssh-client 1:9.3p1-1ubuntu3.2
openssh-server 1:9.3p1-1ubuntu3.2
Ubuntu 23.04:
openssh-client 1:9.0p1-1ubuntu8.7
openssh-server 1:9.0p1-1ubuntu8.7
Ubuntu 22.04 LTS:
openssh-client 1:8.9p1-3ubuntu0.6
openssh-server 1:8.9p1-3ubuntu0.6
Ubuntu 20.04 LTS:
openssh-client 1:8.2p1-4ubuntu0.11
openssh-server 1:8.2p1-4ubuntu0.11
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6565-1
CVE-2021-41617, CVE-2023-51384, CVE-2023-51385
Package Information:
https://launchpad.net/ubuntu/+source/openssh/1:9.3p1-1ubuntu3.2
https://launchpad.net/ubuntu/+source/openssh/1:9.0p1-1ubuntu8.7
https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.6
https://launchpad.net/ubuntu/+source/openssh/1:8.2p1-4ubuntu0.11
[USN-6566-1] SQLite vulnerabilities
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmWVt8AACgkQZWnYVadE
vpPjyw//dSZIRGbdrmnhy3fk0Qo9pEfqOh8VHs06EUp1qW3PzTZWRxcN2V6Ub82v
KzhcyMAfcjlcvGm4pgva7smMEgfgVKviU0TkPiARwlCxx91p6x0fSRlgBBucKbpP
Rmratgj3LPEzT/WNwWh5OmeaAQNHA03SHYjOGmD6Yo0WV3tTUusmDBnO56X6iPpI
lXo4gEqz2d10QeaTz0TmrmUJsgLHrnUEAeumqCLLfQKzJBRyP3VXthB8PxHTx9Xh
v7H54hUmMo8XybwRv1zsjSSt+8mk70CzERPr2KeTm+Utc+yH/ZAwJ2o/oYvDN/Nw
tfMSAHKKtqD90lpbt/kPcsdkfTfNkBO1L59TSv3W+wkMAxgLi/5tQhG9jZtSIyqD
/Wc3uesBmNuCxM1rqBv3Bpwg8YlMlHSZxtNFs9GO5RXXQ5onMWzUVA0EpVresQFS
sn5DvJBtPcn3duW17w47EqDnzdBX0sdu2ZqBSvDRkGznU3TjdpQjqA9cAOoWLVDD
WtsW8Wwo62YuphgW9XP1k2OjMu24N+bNFaLGQh5Eh7UW+n545y01jJHYNwmPLPwx
s4RNB1gmxX0BXNyL3tJ9nH4yNZD+Duu7rRPj+gCzLUYfntFhCVNnPU8jqZa0yNz9
P+WbNoB1th49hLDhHwjsFcFDVqyti1KF0AJB9517b3JwDC8uigA=
=QSxT
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6566-1
January 03, 2024
sqlite3 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in SQLite.
Software Description:
- sqlite3: C library that implements an SQL database engine
Details:
It was discovered that SQLite incorrectly handled certain protection
mechanisms when using a CLI script with the --safe option, contrary to
expectations. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-46908)
It was discovered that SQLite incorrectly handled certain memory operations
in the sessions extension. A remote attacker could possibly use this issue
to cause SQLite to crash, resulting in a denial of service. (CVE-2023-7104)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
libsqlite3-0 3.42.0-1ubuntu0.1
Ubuntu 23.04:
libsqlite3-0 3.40.1-1ubuntu0.1
Ubuntu 22.04 LTS:
libsqlite3-0 3.37.2-2ubuntu0.3
Ubuntu 20.04 LTS:
libsqlite3-0 3.31.1-4ubuntu0.6
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6566-1
CVE-2022-46908, CVE-2023-7104
Package Information:
https://launchpad.net/ubuntu/+source/sqlite3/3.42.0-1ubuntu0.1
https://launchpad.net/ubuntu/+source/sqlite3/3.40.1-1ubuntu0.1
https://launchpad.net/ubuntu/+source/sqlite3/3.37.2-2ubuntu0.3
https://launchpad.net/ubuntu/+source/sqlite3/3.31.1-4ubuntu0.6
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmWVt8AACgkQZWnYVadE
vpPjyw//dSZIRGbdrmnhy3fk0Qo9pEfqOh8VHs06EUp1qW3PzTZWRxcN2V6Ub82v
KzhcyMAfcjlcvGm4pgva7smMEgfgVKviU0TkPiARwlCxx91p6x0fSRlgBBucKbpP
Rmratgj3LPEzT/WNwWh5OmeaAQNHA03SHYjOGmD6Yo0WV3tTUusmDBnO56X6iPpI
lXo4gEqz2d10QeaTz0TmrmUJsgLHrnUEAeumqCLLfQKzJBRyP3VXthB8PxHTx9Xh
v7H54hUmMo8XybwRv1zsjSSt+8mk70CzERPr2KeTm+Utc+yH/ZAwJ2o/oYvDN/Nw
tfMSAHKKtqD90lpbt/kPcsdkfTfNkBO1L59TSv3W+wkMAxgLi/5tQhG9jZtSIyqD
/Wc3uesBmNuCxM1rqBv3Bpwg8YlMlHSZxtNFs9GO5RXXQ5onMWzUVA0EpVresQFS
sn5DvJBtPcn3duW17w47EqDnzdBX0sdu2ZqBSvDRkGznU3TjdpQjqA9cAOoWLVDD
WtsW8Wwo62YuphgW9XP1k2OjMu24N+bNFaLGQh5Eh7UW+n545y01jJHYNwmPLPwx
s4RNB1gmxX0BXNyL3tJ9nH4yNZD+Duu7rRPj+gCzLUYfntFhCVNnPU8jqZa0yNz9
P+WbNoB1th49hLDhHwjsFcFDVqyti1KF0AJB9517b3JwDC8uigA=
=QSxT
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6566-1
January 03, 2024
sqlite3 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in SQLite.
Software Description:
- sqlite3: C library that implements an SQL database engine
Details:
It was discovered that SQLite incorrectly handled certain protection
mechanisms when using a CLI script with the --safe option, contrary to
expectations. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-46908)
It was discovered that SQLite incorrectly handled certain memory operations
in the sessions extension. A remote attacker could possibly use this issue
to cause SQLite to crash, resulting in a denial of service. (CVE-2023-7104)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
libsqlite3-0 3.42.0-1ubuntu0.1
Ubuntu 23.04:
libsqlite3-0 3.40.1-1ubuntu0.1
Ubuntu 22.04 LTS:
libsqlite3-0 3.37.2-2ubuntu0.3
Ubuntu 20.04 LTS:
libsqlite3-0 3.31.1-4ubuntu0.6
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6566-1
CVE-2022-46908, CVE-2023-7104
Package Information:
https://launchpad.net/ubuntu/+source/sqlite3/3.42.0-1ubuntu0.1
https://launchpad.net/ubuntu/+source/sqlite3/3.40.1-1ubuntu0.1
https://launchpad.net/ubuntu/+source/sqlite3/3.37.2-2ubuntu0.3
https://launchpad.net/ubuntu/+source/sqlite3/3.31.1-4ubuntu0.6
[USN-6564-1] Node.js vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsD5BAABCAAjFiEELRdhz3KY7FGicMD8Vjg+NdFTuLIFAmWVR1oFAwAAAAAACgkQVjg+NdFTuLLV
OQv8DZ3jrg2gABV3VPFOvzClcTQbG1RSqxyj9+ItSqWNprNdBnp30UU6HWZTIqax8EO9KUWAIJ6d
RJHsmBv8LfgSqT21xj0CGCwS4YZdJB9jrhNik7HJuOpAz0VjIRgD+wC+rn/yef0yUQUJo+VYfGlB
VdtFjYhlMWZ22Ap+sNGuHzA2sbWyUtsmDx15Zw+QRXF8MtpFESyMTUGefAPS4k3FsT6Elx+nnABu
bCH5L8Rd5E8HldckLlGBoZFnR/fPC1RlT3NZZYg5xN4SYfDGbqe3/9p8vshhMJGmukYQmR0n2DEj
KR+/j3HuynY0nFLFer43uh960GQELK03bmW2NXA16vuspWrp4Mm3JJKt2He8iyweCqBilMOn3Sdj
E/YvVKR4Mwn8Z2PTddC6Fz+x8tB2XOWXrunVi3iiWAWZL8UkI6546p59et2dRFWg4/eagwXoWB5V
FH5bAiqObioAMWCzXdRJroWpWEvpwYsgjG12SJpuV0zCY7zdwHAOH3qJdHkh
=0Aqp
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6564-1
January 03, 2024
nodejs vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in Node.js.
Software Description:
- nodejs: An open-source, cross-platform JavaScript runtime environment.
Details:
Hubert Kario discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted input
file, a remote attacker could possibly use this issue to obtain sensitive
information. (CVE-2022-4304)
CarpetFuzz, Dawei Wang discovered that Node.js incorrectly handled certain
inputs. If a user or an automated system were tricked into opening a specially
crafted input file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2022-4450)
Octavio Galland and Marcel Böhme discovered that Node.js incorrectly handled
certain inputs. If a user or an automated system were tricked into opening a
specially crafted input file, a remote attacker could possibly use this issue
to cause a denial of service. (CVE-2023-0215)
David Benjamin discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted input
file, a remote attacker could possibly use this issue to obtain sensitive
information. (CVE-2023-0286)
Hubert Kario and Dmitry Belyavsky discovered that Node.js incorrectly handled
certain inputs. If a user or an automated system were tricked into opening a
specially crafted input file, a remote attacker could possibly use this issue
to cause a denial of service. (CVE-2023-0401)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS:
libnode-dev 12.22.9~dfsg-1ubuntu3.3
libnode72 12.22.9~dfsg-1ubuntu3.3
nodejs 12.22.9~dfsg-1ubuntu3.3
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6564-1
CVE-2022-4304, CVE-2022-4450, CVE-2023-0215, CVE-2023-0286,
CVE-2023-0401
Package Information:
https://launchpad.net/ubuntu/+source/nodejs/12.22.9~dfsg-1ubuntu3.3
wsD5BAABCAAjFiEELRdhz3KY7FGicMD8Vjg+NdFTuLIFAmWVR1oFAwAAAAAACgkQVjg+NdFTuLLV
OQv8DZ3jrg2gABV3VPFOvzClcTQbG1RSqxyj9+ItSqWNprNdBnp30UU6HWZTIqax8EO9KUWAIJ6d
RJHsmBv8LfgSqT21xj0CGCwS4YZdJB9jrhNik7HJuOpAz0VjIRgD+wC+rn/yef0yUQUJo+VYfGlB
VdtFjYhlMWZ22Ap+sNGuHzA2sbWyUtsmDx15Zw+QRXF8MtpFESyMTUGefAPS4k3FsT6Elx+nnABu
bCH5L8Rd5E8HldckLlGBoZFnR/fPC1RlT3NZZYg5xN4SYfDGbqe3/9p8vshhMJGmukYQmR0n2DEj
KR+/j3HuynY0nFLFer43uh960GQELK03bmW2NXA16vuspWrp4Mm3JJKt2He8iyweCqBilMOn3Sdj
E/YvVKR4Mwn8Z2PTddC6Fz+x8tB2XOWXrunVi3iiWAWZL8UkI6546p59et2dRFWg4/eagwXoWB5V
FH5bAiqObioAMWCzXdRJroWpWEvpwYsgjG12SJpuV0zCY7zdwHAOH3qJdHkh
=0Aqp
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6564-1
January 03, 2024
nodejs vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in Node.js.
Software Description:
- nodejs: An open-source, cross-platform JavaScript runtime environment.
Details:
Hubert Kario discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted input
file, a remote attacker could possibly use this issue to obtain sensitive
information. (CVE-2022-4304)
CarpetFuzz, Dawei Wang discovered that Node.js incorrectly handled certain
inputs. If a user or an automated system were tricked into opening a specially
crafted input file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2022-4450)
Octavio Galland and Marcel Böhme discovered that Node.js incorrectly handled
certain inputs. If a user or an automated system were tricked into opening a
specially crafted input file, a remote attacker could possibly use this issue
to cause a denial of service. (CVE-2023-0215)
David Benjamin discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted input
file, a remote attacker could possibly use this issue to obtain sensitive
information. (CVE-2023-0286)
Hubert Kario and Dmitry Belyavsky discovered that Node.js incorrectly handled
certain inputs. If a user or an automated system were tricked into opening a
specially crafted input file, a remote attacker could possibly use this issue
to cause a denial of service. (CVE-2023-0401)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS:
libnode-dev 12.22.9~dfsg-1ubuntu3.3
libnode72 12.22.9~dfsg-1ubuntu3.3
nodejs 12.22.9~dfsg-1ubuntu3.3
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6564-1
CVE-2022-4304, CVE-2022-4450, CVE-2023-0215, CVE-2023-0286,
CVE-2023-0401
Package Information:
https://launchpad.net/ubuntu/+source/nodejs/12.22.9~dfsg-1ubuntu3.3
Orphaned packages looking for new maintainers
The following packages are orphaned and will be retired when they
are orphaned for six weeks, unless someone adopts them. If you know for sure
that the package should be retired, please do so now with a proper reason:
https://fedoraproject.org/wiki/How_to_remove_a_package_at_end_of_life
Note: If you received this mail directly you (co)maintain one of the affected
packages or a package that depends on one. Please adopt the affected package or
retire your depending package to avoid broken dependencies, otherwise your
package will fail to install and/or build when the affected package gets retired.
Request package ownership via the *Take* button in he left column on
https://src.fedoraproject.org/rpms/<pkgname>
Full report available at:
https://churchyard.fedorapeople.org/orphans-2024-01-03.txt
grep it for your FAS username and follow the dependency chain.
For human readable dependency chains,
see https://packager-dashboard.fedoraproject.org/
For all orphaned packages,
see https://packager-dashboard.fedoraproject.org/orphan
Package (co)maintainers Status Change
================================================================================
cdsclient astro-sig, orphan 0 weeks ago
clash go-sig, orphan 5 weeks ago
csmith orphan 0 weeks ago
drumstick orphan, yanqiyu 0 weeks ago
drumstick0 orphan, yanqiyu 0 weeks ago
kmetronome orphan 0 weeks ago
libASL orion, orphan, slaanesh 2 weeks ago
mrpt jkastner, kwizart, orphan, 5 weeks ago
robotics-sig
mygnuhealth orphan 0 weeks ago
obs-service-cargo_vendor orphan 2 weeks ago
python-compressed-rtf orphan 0 weeks ago
python-google-cloud-access- fkolwa, miyunari, orphan, 2 weeks ago
approval python-packagers-sig
python-google-cloud-access- fkolwa, miyunari, orphan, 2 weeks ago
context-manager python-packagers-sig
python-google-cloud-api-gateway fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-apigee- fkolwa, miyunari, orphan, 2 weeks ago
connect python-packagers-sig
python-google-cloud-appengine- fkolwa, miyunari, orphan, 2 weeks ago
admin python-packagers-sig
python-google-cloud-asset fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-automl fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-bigquery fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-bigquery- fkolwa, miyunari, orphan, 2 weeks ago
connection python-packagers-sig
python-google-cloud-bigquery- fkolwa, miyunari, orphan, 2 weeks ago
datatransfer python-packagers-sig
python-google-cloud-bigquery- fkolwa, miyunari, orphan, 2 weeks ago
reservation python-packagers-sig
python-google-cloud-bigquery- fkolwa, miyunari, orphan, 2 weeks ago
storage python-packagers-sig
python-google-cloud-bigtable fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-billing fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-billing- fkolwa, miyunari, orphan, 2 weeks ago
budgets python-packagers-sig
python-google-cloud-build fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-common fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-container fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud- fkolwa, miyunari, orphan, 2 weeks ago
containeranalysis python-packagers-sig
python-google-cloud-data-fusion fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-datacatalog fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-dataproc fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-dataproc- fkolwa, miyunari, orphan, 2 weeks ago
metastore python-packagers-sig
python-google-cloud-debugger- fkolwa, miyunari, orphan, 2 weeks ago
client python-packagers-sig
python-google-cloud-deploy fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-dlp fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-dms fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-domains fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-filestore fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-firestore fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-functions fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-iam fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-kms fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-org-policy fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-os-config fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-private-ca fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-pubsub fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-redis fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-shell fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-source- fkolwa, miyunari, orphan, 2 weeks ago
context python-packagers-sig
python-google-cloud-spanner fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-testutils fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-crc32c fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-resumable-media fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-grafeas orphan, python-packagers-sig 2 weeks ago
python-maya neuro-sig, orphan 2 weeks ago
python-pymoc astro-sig, orphan 2 weeks ago
python-red-black-tree-mod orphan 0 weeks ago
qterm orphan 0 weeks ago
recorder orphan 0 weeks ago
rubygem-hrx jcpunk, orphan, tdawson 2 weeks ago
rubygem-linked-list jcpunk, orphan, tdawson 2 weeks ago
rubygem-rails- orphan 2 weeks ago
deprecated_sanitizer
scamp astro-sig, orphan 0 weeks ago
sonivox orphan 0 weeks ago
tofrodos cicku, orphan, tdawson 2 weeks ago
vmpk orphan 0 weeks ago
wput orphan 2 weeks ago
The following packages require above mentioned packages:
Depending on: cdsclient (1), status change: 2023-12-29 (0 weeks ago)
scamp (maintained by: astro-sig, orphan)
scamp-2.10.0-5.fc38.src requires cdsclient = 3.84-16.fc39
scamp-2.10.0-5.fc38.x86_64 requires cdsclient = 3.84-16.fc39
Depending on: drumstick (2), status change: 2023-12-31 (0 weeks ago)
kmetronome (maintained by: orphan)
kmetronome-1.3.1-3.fc39.src requires drumstick-devel = 2.8.1-1.fc40
kmetronome-1.3.1-3.fc39.x86_64 requires libdrumstick-alsa.so.2()(64bit)
vmpk (maintained by: orphan)
vmpk-0.8.10-1.fc40.src requires drumstick-devel = 2.8.1-1.fc40
vmpk-0.8.10-1.fc40.x86_64 requires libdrumstick-rt.so.2()(64bit),
libdrumstick-widgets.so.2()(64bit)
Depending on: drumstick0 (1), status change: 2023-12-31 (0 weeks ago)
kmid2 (maintained by: cheeselee, kkofler)
kmid2-2.4.0-27.fc39.src requires drumstick0-devel = 0.5.0-34.fc39
kmid2-2.4.0-27.fc39.x86_64 requires drumstick0 = 0.5.0-34.fc39,
libdrumstick-alsa.so.0()(64bit), libdrumstick-file.so.0()(64bit)
Depending on: python-google-cloud-access-context-manager (1), status change:
2023-12-15 (2 weeks ago)
python-google-cloud-asset (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-asset-3.22.0-1.fc40.src requires
python3dist(google-cloud-access-context-manager) = 0.1.16
python3-google-cloud-asset-3.22.0-1.fc40.noarch requires
python3.12dist(google-cloud-access-context-manager) = 0.1.16
Depending on: python-google-cloud-bigquery-storage (1), status change:
2023-12-15 (2 weeks ago)
python-google-cloud-bigquery (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-bigquery-3.14.0-2.fc40.src requires
python3dist(google-cloud-bigquery-storage) = 2.24
python3-google-cloud-bigquery+bqstorage-3.14.0-2.fc40.noarch requires
python3.12dist(google-cloud-bigquery-storage) = 2.24
Depending on: python-google-cloud-common (1), status change: 2023-12-15 (2
weeks ago)
python-google-cloud-filestore (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-filestore-1.5.0-3.fc39.src requires
python3dist(google-cloud-common) = 1.2
python3-google-cloud-filestore-1.5.0-3.fc39.noarch requires
python3.12dist(google-cloud-common) = 1.2
Depending on: python-google-cloud-org-policy (1), status change: 2023-12-15 (2
weeks ago)
python-google-cloud-asset (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-asset-3.22.0-1.fc40.src requires
python3dist(google-cloud-org-policy) = 1.8.3
python3-google-cloud-asset-3.22.0-1.fc40.noarch requires
python3.12dist(google-cloud-org-policy) = 1.8.3
Depending on: python-google-cloud-os-config (1), status change: 2023-12-15 (2
weeks ago)
python-google-cloud-asset (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-asset-3.22.0-1.fc40.src requires
python3dist(google-cloud-os-config) = 1.16
python3-google-cloud-asset-3.22.0-1.fc40.noarch requires
python3.12dist(google-cloud-os-config) = 1.16
Depending on: python-google-cloud-source-context (1), status change: 2023-12-15
(2 weeks ago)
python-google-cloud-debugger-client (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-debugger-client-1.7.0-2.fc39.src requires
python3dist(google-cloud-source-context) = 1.5
python3-google-cloud-debugger-client-1.7.0-2.fc39.noarch requires
python3.12dist(google-cloud-source-context) = 1.5
Depending on: python-google-cloud-testutils (3), status change: 2023-12-15 (2
weeks ago)
python-google-cloud-bigquery (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-bigquery-3.14.0-2.fc40.src requires
python3dist(google-cloud-testutils) = 1.3.3
python-google-cloud-bigquery-datatransfer (maintained by: fkolwa, miyunari,
orphan, python-packagers-sig)
python-google-cloud-bigquery-datatransfer-3.13.0-2.fc40.src requires
python3dist(google-cloud-testutils) = 1.3.3
python-google-cloud-firestore (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-firestore-2.14.0-3.fc40.src requires
python3dist(google-cloud-testutils) = 1.3.3
Depending on: python-google-crc32c (23), status change: 2023-12-15 (2 weeks ago)
python-google-cloud-storage (maintained by: fkolwa, jonathanspw, miyunari,
python-packagers-sig)
python-google-cloud-storage-2.14.0-2.fc40.src requires
python3dist(google-crc32c) = 1.1.2, python3dist(google-resumable-media) = 2.6
python3-google-cloud-storage-2.14.0-2.fc40.noarch requires
python3.12dist(google-crc32c) = 1.1.2, python3.12dist(google-resumable-media) = 2.6
python-google-resumable-media (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-resumable-media-2.6.0-1.fc40.src requires
python3dist(google-crc32c) = 1.1.2
python3-google-resumable-media-2.6.0-1.fc40.noarch requires
python3.12dist(google-crc32c) = 1.1.2
snakemake (maintained by: major, neuro-sig)
snakemake-7.32.4-2.fc40.src requires python3dist(google-cloud-storage) =
2.14, python3dist(google-crc32c) = 1.1.2
snakemake+google-cloud-7.32.4-2.fc40.noarch requires
python3.12dist(google-cloud-storage) = 2.14, python3.12dist(google-crc32c) = 1.1.2
python-gcsfs (maintained by: fab)
python-gcsfs-2023.6.0-1.fc39.src requires python3dist(fsspec) = 2023.12.2,
python3dist(google-cloud-storage) = 2.14
python3-gcsfs-2023.6.0-1.fc39.noarch requires python3.12dist(fsspec) =
2023.12.2, python3.12dist(google-cloud-storage) = 2.14
python-google-cloud-automl (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-automl-2.12.0-2.fc40.src requires
python3dist(google-cloud-storage) = 2.14
python-google-cloud-bigquery (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-bigquery-3.14.0-2.fc40.src requires
python3dist(google-resumable-media) = 2.6
python3-google-cloud-bigquery-3.14.0-2.fc40.noarch requires
python3.12dist(google-resumable-media) = 2.6
python3-google-cloud-bigquery+geopandas-3.14.0-2.fc40.noarch requires
python3.12dist(geopandas) = 0.14.1
python-fsspec (maintained by: epel-packagers-sig, jonathanspw,
python-packagers-sig, qulogic)
python-fsspec-2023.12.2-1.fc40.src requires python3dist(gcsfs) = 2023.6
python-papermill (maintained by: ankursinha, neuro-sig)
python-papermill-2.4.0-7.fc40.src requires python3dist(gcsfs) = 2023.6
python3-papermill+all-2.4.0-7.fc40.noarch requires python3.12dist(gcsfs) = 2023.6
python3-papermill+gcs-2.4.0-7.fc40.noarch requires python3.12dist(gcsfs) = 2023.6
python-dask (maintained by: epel-packagers-sig, jonathanspw,
python-packagers-sig, qulogic)
python-dask-2023.8.1-3.fc40~bootstrap.src requires python3dist(fsspec) =
2023.12.2
python3-dask-2023.8.1-3.fc40~bootstrap.noarch requires python3.12dist(fsspec)
= 2023.12.2
python-geopandas (maintained by: python-packagers-sig, qulogic)
python-geopandas-0.14.1-1.fc40.src requires python3dist(fsspec) = 2023.12.2
python-reproject (maintained by: astro-sig, sergiopr)
python-reproject-0.13.0-2.fc40.src requires python3dist(dask) = 2023.8.1,
python3dist(dask[array]) = 2023.8.1, python3dist(fsspec) = 2023.12.2
python3-reproject-0.13.0-2.fc40.x86_64 requires python3.12dist(dask) =
2023.8.1, python3.12dist(dask[array]) = 2023.8.1, python3.12dist(fsspec) =
2023.12.2
python-torch (maintained by: trix)
python-torch-2.1.2-1.fc40.src requires python3dist(fsspec) = 2023.12.2
python3-torch-2.1.2-1.fc40.x86_64 requires python3.12dist(fsspec) = 2023.12.2
python-zarr (maintained by: epel-packagers-sig, jonathanspw,
python-packagers-sig, qulogic)
python-zarr-2.16.1-1.fc40.src requires python3dist(fsspec) = 2023.12.2
python-bluepyopt (maintained by: ankursinha, neuro-sig)
python-bluepyopt-1.14.6-5.fc40.src requires python3dist(papermill) = 2.4
python-xarray (maintained by: epel-packagers-sig, jonathanspw,
python-packagers-sig, qulogic)
python-xarray-2023.8.0-1.fc40.src requires python3dist(dask[array]) =
2023.8.1, python3dist(dask[dataframe]) = 2023.8.1
python-xbout (maintained by: davidsch)
python-xbout-0.3.5-8.fc39.src requires python3dist(dask) = 2023.8.1,
python3dist(dask[array]) = 2023.8.1
python3-xbout-0.3.5-8.fc39.noarch requires python3.12dist(dask) = 2023.8.1,
python3.12dist(dask[array]) = 2023.8.1
python-earthpy (maintained by: iztokf)
python-earthpy-0.9.4-9.fc39.src requires python3dist(geopandas) = 0.14.1
python3-earthpy-0.9.4-9.fc39.noarch requires python3.12dist(geopandas) = 0.14.1
python-geodatasets (maintained by: qulogic)
python-geodatasets-2023.12.0-1.fc40.src requires python3-geopandas =
0.14.1-1.fc40
python-geoplot (maintained by: python-packagers-sig, qulogic)
python-geoplot-0.5.1-7.fc40.src requires python3dist(geopandas) = 0.14.1
python3-geoplot-0.5.1-7.fc40.noarch requires python3.12dist(geopandas) = 0.14.1
python-libpysal (maintained by: python-packagers-sig, qulogic)
python-libpysal-4.7.0-5.fc40.src requires python3dist(geopandas) = 0.14.1
python-mapclassify (maintained by: python-packagers-sig, qulogic)
python-mapclassify-2.5.0-2.fc40.src requires python3dist(geopandas) = 0.14.1
python-networkx (maintained by: jjames, plautrba)
python-networkx-3.2.1-2.fc40.src requires python3dist(geopandas) = 0.14.1
python-plotnine (maintained by: gui1ty, neuro-sig)
python-plotnine-0.12.4-4.fc40.src requires python3-geopandas = 0.14.1-1.fc40
python3-plotnine+extra-0.12.4-4.fc40.noarch requires
python3.12dist(geopandas) = 0.14.1
Too many dependencies for python-google-crc32c, not all listed here
Depending on: python-google-resumable-media (22), status change: 2023-12-15 (2
weeks ago)
python-google-cloud-bigquery (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-bigquery-3.14.0-2.fc40.src requires
python3dist(google-resumable-media) = 2.6
python3-google-cloud-bigquery-3.14.0-2.fc40.noarch requires
python3.12dist(google-resumable-media) = 2.6
python3-google-cloud-bigquery+geopandas-3.14.0-2.fc40.noarch requires
python3.12dist(geopandas) = 0.14.1
python-google-cloud-storage (maintained by: fkolwa, jonathanspw, miyunari,
python-packagers-sig)
python-google-cloud-storage-2.14.0-2.fc40.src requires
python3dist(google-resumable-media) = 2.6
python3-google-cloud-storage-2.14.0-2.fc40.noarch requires
python3.12dist(google-resumable-media) = 2.6
python-gcsfs (maintained by: fab)
python-gcsfs-2023.6.0-1.fc39.src requires python3dist(fsspec) = 2023.12.2,
python3dist(google-cloud-storage) = 2.14
python3-gcsfs-2023.6.0-1.fc39.noarch requires python3.12dist(fsspec) =
2023.12.2, python3.12dist(google-cloud-storage) = 2.14
python-google-cloud-automl (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-automl-2.12.0-2.fc40.src requires
python3dist(google-cloud-storage) = 2.14
snakemake (maintained by: major, neuro-sig)
snakemake-7.32.4-2.fc40.src requires python3dist(google-cloud-storage) = 2.14
snakemake+google-cloud-7.32.4-2.fc40.noarch requires
python3.12dist(google-cloud-storage) = 2.14
python-fsspec (maintained by: epel-packagers-sig, jonathanspw,
python-packagers-sig, qulogic)
python-fsspec-2023.12.2-1.fc40.src requires python3dist(gcsfs) = 2023.6
python-papermill (maintained by: ankursinha, neuro-sig)
python-papermill-2.4.0-7.fc40.src requires python3dist(gcsfs) = 2023.6
python3-papermill+all-2.4.0-7.fc40.noarch requires python3.12dist(gcsfs) = 2023.6
python3-papermill+gcs-2.4.0-7.fc40.noarch requires python3.12dist(gcsfs) = 2023.6
python-dask (maintained by: epel-packagers-sig, jonathanspw,
python-packagers-sig, qulogic)
python-dask-2023.8.1-3.fc40~bootstrap.src requires python3dist(fsspec) =
2023.12.2
python3-dask-2023.8.1-3.fc40~bootstrap.noarch requires python3.12dist(fsspec)
= 2023.12.2
python-geopandas (maintained by: python-packagers-sig, qulogic)
python-geopandas-0.14.1-1.fc40.src requires python3dist(fsspec) = 2023.12.2
python-reproject (maintained by: astro-sig, sergiopr)
python-reproject-0.13.0-2.fc40.src requires python3dist(dask) = 2023.8.1,
python3dist(dask[array]) = 2023.8.1, python3dist(fsspec) = 2023.12.2
python3-reproject-0.13.0-2.fc40.x86_64 requires python3.12dist(dask) =
2023.8.1, python3.12dist(dask[array]) = 2023.8.1, python3.12dist(fsspec) =
2023.12.2
python-torch (maintained by: trix)
python-torch-2.1.2-1.fc40.src requires python3dist(fsspec) = 2023.12.2
python3-torch-2.1.2-1.fc40.x86_64 requires python3.12dist(fsspec) = 2023.12.2
python-zarr (maintained by: epel-packagers-sig, jonathanspw,
python-packagers-sig, qulogic)
python-zarr-2.16.1-1.fc40.src requires python3dist(fsspec) = 2023.12.2
python-bluepyopt (maintained by: ankursinha, neuro-sig)
python-bluepyopt-1.14.6-5.fc40.src requires python3dist(papermill) = 2.4
python-xarray (maintained by: epel-packagers-sig, jonathanspw,
python-packagers-sig, qulogic)
python-xarray-2023.8.0-1.fc40.src requires python3dist(dask[array]) =
2023.8.1, python3dist(dask[dataframe]) = 2023.8.1
python-xbout (maintained by: davidsch)
python-xbout-0.3.5-8.fc39.src requires python3dist(dask) = 2023.8.1,
python3dist(dask[array]) = 2023.8.1
python3-xbout-0.3.5-8.fc39.noarch requires python3.12dist(dask) = 2023.8.1,
python3.12dist(dask[array]) = 2023.8.1
python-earthpy (maintained by: iztokf)
python-earthpy-0.9.4-9.fc39.src requires python3dist(geopandas) = 0.14.1
python3-earthpy-0.9.4-9.fc39.noarch requires python3.12dist(geopandas) = 0.14.1
python-geodatasets (maintained by: qulogic)
python-geodatasets-2023.12.0-1.fc40.src requires python3-geopandas =
0.14.1-1.fc40
python-geoplot (maintained by: python-packagers-sig, qulogic)
python-geoplot-0.5.1-7.fc40.src requires python3dist(geopandas) = 0.14.1
python3-geoplot-0.5.1-7.fc40.noarch requires python3.12dist(geopandas) = 0.14.1
python-libpysal (maintained by: python-packagers-sig, qulogic)
python-libpysal-4.7.0-5.fc40.src requires python3dist(geopandas) = 0.14.1
python-mapclassify (maintained by: python-packagers-sig, qulogic)
python-mapclassify-2.5.0-2.fc40.src requires python3dist(geopandas) = 0.14.1
python-networkx (maintained by: jjames, plautrba)
python-networkx-3.2.1-2.fc40.src requires python3dist(geopandas) = 0.14.1
python-plotnine (maintained by: gui1ty, neuro-sig)
python-plotnine-0.12.4-4.fc40.src requires python3-geopandas = 0.14.1-1.fc40
python3-plotnine+extra-0.12.4-4.fc40.noarch requires
python3.12dist(geopandas) = 0.14.1
Too many dependencies for python-google-resumable-media, not all listed here
Depending on: python-grafeas (1), status change: 2023-12-15 (2 weeks ago)
python-google-cloud-containeranalysis (maintained by: fkolwa, miyunari,
orphan, python-packagers-sig)
python-google-cloud-containeranalysis-2.12.4-1.fc40.src requires
python3dist(grafeas) = 1.9
python3-google-cloud-containeranalysis-2.12.4-1.fc40.noarch requires
python3.12dist(grafeas) = 1.9
Depending on: rubygem-linked-list (1), status change: 2023-12-18 (2 weeks ago)
rubygem-hrx (maintained by: jcpunk, orphan, tdawson)
rubygem-hrx-1.0.0-9.fc39.noarch requires rubygem(linked-list) = 0.0.16
rubygem-hrx-1.0.0-9.fc39.src requires rubygem(linked-list) = 0.0.16
Depending on: sonivox (3), status change: 2023-12-31 (0 weeks ago)
drumstick (maintained by: orphan, yanqiyu)
drumstick-2.8.1-1.fc40.i686 requires libsonivox.so.3
drumstick-2.8.1-1.fc40.src requires sonivox-devel = 3.6.12-2.fc39
drumstick-2.8.1-1.fc40.x86_64 requires libsonivox.so.3()(64bit)
kmetronome (maintained by: orphan)
kmetronome-1.3.1-3.fc39.src requires drumstick-devel = 2.8.1-1.fc40
kmetronome-1.3.1-3.fc39.x86_64 requires libdrumstick-alsa.so.2()(64bit)
vmpk (maintained by: orphan)
vmpk-0.8.10-1.fc40.src requires drumstick-devel = 2.8.1-1.fc40
vmpk-0.8.10-1.fc40.x86_64 requires libdrumstick-rt.so.2()(64bit),
libdrumstick-widgets.so.2()(64bit)
See dependency chains of your packages at
https://packager-dashboard.fedoraproject.org/
See all orphaned packages at https://packager-dashboard.fedoraproject.org/orphan
Affected (co)maintainers (either directly or via packages' dependencies):
ankursinha: python-google-crc32c, python-google-resumable-media
astro-sig: python-pymoc, cdsclient, scamp, python-google-resumable-media,
python-google-crc32c
cheeselee: drumstick0
cicku: tofrodos
davidsch: python-google-crc32c, python-google-resumable-media
epel-packagers-sig: python-google-crc32c, python-google-resumable-media
fab: python-google-crc32c, python-google-resumable-media
fkolwa: python-google-cloud-data-fusion,
python-google-cloud-bigquery-reservation,
python-google-cloud-containeranalysis, python-google-cloud-asset,
python-google-cloud-domains, python-google-cloud-kms,
python-google-cloud-billing-budgets, python-google-cloud-debugger-client,
python-google-cloud-dms, python-google-cloud-source-context,
python-google-cloud-testutils, python-google-cloud-shell,
python-google-cloud-bigquery-datatransfer,
python-google-cloud-bigquery-connection, python-google-cloud-functions,
python-google-cloud-private-ca, python-google-cloud-pubsub,
python-google-cloud-redis, python-google-cloud-api-gateway,
python-google-cloud-spanner, python-google-cloud-dataproc-metastore,
python-google-cloud-firestore, python-google-cloud-org-policy,
python-google-cloud-access-context-manager, python-google-cloud-apigee-connect,
python-google-cloud-datacatalog, python-google-cloud-bigquery,
python-google-cloud-dataproc, python-google-cloud-bigtable,
python-google-cloud-access-approval, python-google-cloud-bigquery-storage,
python-google-resumable-media, python-google-crc32c, python-google-cloud-build,
python-google-cloud-deploy, python-google-cloud-dlp, python-grafeas,
python-google-cloud-iam, python-google-cloud-filestore,
python-google-cloud-common, python-google-cloud-container,
python-google-cloud-billing, python-google-cloud-automl,
python-google-cloud-os-config, python-google-cloud-appengine-admin
go-sig: clash
gui1ty: python-google-crc32c, python-google-resumable-media
iztokf: python-google-crc32c, python-google-resumable-media
jcpunk: rubygem-hrx, rubygem-linked-list
jjames: python-google-crc32c, python-google-resumable-media
jkastner: mrpt
jonathanspw: python-google-crc32c, python-google-resumable-media
kkofler: drumstick0
kwizart: mrpt
major: python-google-crc32c, python-google-resumable-media
miyunari: python-google-cloud-data-fusion,
python-google-cloud-bigquery-reservation,
python-google-cloud-containeranalysis, python-google-cloud-asset,
python-google-cloud-domains, python-google-cloud-kms,
python-google-cloud-billing-budgets, python-google-cloud-debugger-client,
python-google-cloud-dms, python-google-cloud-source-context,
python-google-cloud-testutils, python-google-cloud-shell,
python-google-cloud-bigquery-datatransfer,
python-google-cloud-bigquery-connection, python-google-cloud-functions,
python-google-cloud-private-ca, python-google-cloud-pubsub,
python-google-cloud-redis, python-google-cloud-api-gateway,
python-google-cloud-spanner, python-google-cloud-dataproc-metastore,
python-google-cloud-firestore, python-google-cloud-org-policy,
python-google-cloud-access-context-manager, python-google-cloud-apigee-connect,
python-google-cloud-datacatalog, python-google-cloud-bigquery,
python-google-cloud-dataproc, python-google-cloud-bigtable,
python-google-cloud-access-approval, python-google-cloud-bigquery-storage,
python-google-resumable-media, python-google-crc32c, python-google-cloud-build,
python-google-cloud-deploy, python-google-cloud-dlp, python-grafeas,
python-google-cloud-iam, python-google-cloud-filestore,
python-google-cloud-common, python-google-cloud-container,
python-google-cloud-billing, python-google-cloud-automl,
python-google-cloud-os-config, python-google-cloud-appengine-admin
neuro-sig: python-google-crc32c, python-maya, python-google-resumable-media
orion: libASL
plautrba: python-google-crc32c, python-google-resumable-media
python-packagers-sig: python-google-cloud-data-fusion,
python-google-cloud-bigquery-reservation,
python-google-cloud-containeranalysis, python-google-cloud-asset,
python-google-cloud-domains, python-google-cloud-kms,
python-google-cloud-billing-budgets, python-google-cloud-debugger-client,
python-google-cloud-dms, python-google-cloud-source-context,
python-google-cloud-testutils, python-google-cloud-shell,
python-google-cloud-bigquery-datatransfer,
python-google-cloud-bigquery-connection, python-google-cloud-functions,
python-google-cloud-private-ca, python-google-cloud-pubsub,
python-google-cloud-redis, python-google-cloud-api-gateway,
python-google-cloud-spanner, python-google-cloud-dataproc-metastore,
python-google-cloud-firestore, python-google-cloud-org-policy,
python-google-cloud-access-context-manager, python-google-cloud-apigee-connect,
python-google-cloud-datacatalog, python-google-cloud-bigquery,
python-google-cloud-dataproc, python-google-cloud-bigtable,
python-google-cloud-access-approval, python-google-cloud-bigquery-storage,
python-google-resumable-media, python-google-crc32c, python-google-cloud-build,
python-google-cloud-deploy, python-google-cloud-dlp, python-grafeas,
python-google-cloud-iam, python-google-cloud-filestore,
python-google-cloud-common, python-google-cloud-container,
python-google-cloud-billing, python-google-cloud-automl,
python-google-cloud-os-config, python-google-cloud-appengine-admin
qulogic: python-google-crc32c, python-google-resumable-media
robotics-sig: mrpt
sergiopr: python-google-crc32c, python-google-resumable-media
slaanesh: libASL
tdawson: tofrodos, rubygem-hrx, rubygem-linked-list
trix: python-google-crc32c, python-google-resumable-media
yanqiyu: drumstick0, sonivox, drumstick
--
The script creating this output is run and developed by Fedora
Release Engineering. Please report issues at its pagure instance:
https://pagure.io/releng/
The sources of this script can be found at:
https://pagure.io/releng/blob/main/f/scripts/find_unblocked_orphans.py
Report finished at 2024-01-03 08:56:26 UTC
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
are orphaned for six weeks, unless someone adopts them. If you know for sure
that the package should be retired, please do so now with a proper reason:
https://fedoraproject.org/wiki/How_to_remove_a_package_at_end_of_life
Note: If you received this mail directly you (co)maintain one of the affected
packages or a package that depends on one. Please adopt the affected package or
retire your depending package to avoid broken dependencies, otherwise your
package will fail to install and/or build when the affected package gets retired.
Request package ownership via the *Take* button in he left column on
https://src.fedoraproject.org/rpms/<pkgname>
Full report available at:
https://churchyard.fedorapeople.org/orphans-2024-01-03.txt
grep it for your FAS username and follow the dependency chain.
For human readable dependency chains,
see https://packager-dashboard.fedoraproject.org/
For all orphaned packages,
see https://packager-dashboard.fedoraproject.org/orphan
Package (co)maintainers Status Change
================================================================================
cdsclient astro-sig, orphan 0 weeks ago
clash go-sig, orphan 5 weeks ago
csmith orphan 0 weeks ago
drumstick orphan, yanqiyu 0 weeks ago
drumstick0 orphan, yanqiyu 0 weeks ago
kmetronome orphan 0 weeks ago
libASL orion, orphan, slaanesh 2 weeks ago
mrpt jkastner, kwizart, orphan, 5 weeks ago
robotics-sig
mygnuhealth orphan 0 weeks ago
obs-service-cargo_vendor orphan 2 weeks ago
python-compressed-rtf orphan 0 weeks ago
python-google-cloud-access- fkolwa, miyunari, orphan, 2 weeks ago
approval python-packagers-sig
python-google-cloud-access- fkolwa, miyunari, orphan, 2 weeks ago
context-manager python-packagers-sig
python-google-cloud-api-gateway fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-apigee- fkolwa, miyunari, orphan, 2 weeks ago
connect python-packagers-sig
python-google-cloud-appengine- fkolwa, miyunari, orphan, 2 weeks ago
admin python-packagers-sig
python-google-cloud-asset fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-automl fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-bigquery fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-bigquery- fkolwa, miyunari, orphan, 2 weeks ago
connection python-packagers-sig
python-google-cloud-bigquery- fkolwa, miyunari, orphan, 2 weeks ago
datatransfer python-packagers-sig
python-google-cloud-bigquery- fkolwa, miyunari, orphan, 2 weeks ago
reservation python-packagers-sig
python-google-cloud-bigquery- fkolwa, miyunari, orphan, 2 weeks ago
storage python-packagers-sig
python-google-cloud-bigtable fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-billing fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-billing- fkolwa, miyunari, orphan, 2 weeks ago
budgets python-packagers-sig
python-google-cloud-build fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-common fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-container fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud- fkolwa, miyunari, orphan, 2 weeks ago
containeranalysis python-packagers-sig
python-google-cloud-data-fusion fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-datacatalog fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-dataproc fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-dataproc- fkolwa, miyunari, orphan, 2 weeks ago
metastore python-packagers-sig
python-google-cloud-debugger- fkolwa, miyunari, orphan, 2 weeks ago
client python-packagers-sig
python-google-cloud-deploy fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-dlp fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-dms fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-domains fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-filestore fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-firestore fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-functions fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-iam fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-kms fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-org-policy fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-os-config fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-private-ca fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-pubsub fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-redis fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-shell fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-source- fkolwa, miyunari, orphan, 2 weeks ago
context python-packagers-sig
python-google-cloud-spanner fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-cloud-testutils fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-crc32c fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-google-resumable-media fkolwa, miyunari, orphan, 2 weeks ago
python-packagers-sig
python-grafeas orphan, python-packagers-sig 2 weeks ago
python-maya neuro-sig, orphan 2 weeks ago
python-pymoc astro-sig, orphan 2 weeks ago
python-red-black-tree-mod orphan 0 weeks ago
qterm orphan 0 weeks ago
recorder orphan 0 weeks ago
rubygem-hrx jcpunk, orphan, tdawson 2 weeks ago
rubygem-linked-list jcpunk, orphan, tdawson 2 weeks ago
rubygem-rails- orphan 2 weeks ago
deprecated_sanitizer
scamp astro-sig, orphan 0 weeks ago
sonivox orphan 0 weeks ago
tofrodos cicku, orphan, tdawson 2 weeks ago
vmpk orphan 0 weeks ago
wput orphan 2 weeks ago
The following packages require above mentioned packages:
Depending on: cdsclient (1), status change: 2023-12-29 (0 weeks ago)
scamp (maintained by: astro-sig, orphan)
scamp-2.10.0-5.fc38.src requires cdsclient = 3.84-16.fc39
scamp-2.10.0-5.fc38.x86_64 requires cdsclient = 3.84-16.fc39
Depending on: drumstick (2), status change: 2023-12-31 (0 weeks ago)
kmetronome (maintained by: orphan)
kmetronome-1.3.1-3.fc39.src requires drumstick-devel = 2.8.1-1.fc40
kmetronome-1.3.1-3.fc39.x86_64 requires libdrumstick-alsa.so.2()(64bit)
vmpk (maintained by: orphan)
vmpk-0.8.10-1.fc40.src requires drumstick-devel = 2.8.1-1.fc40
vmpk-0.8.10-1.fc40.x86_64 requires libdrumstick-rt.so.2()(64bit),
libdrumstick-widgets.so.2()(64bit)
Depending on: drumstick0 (1), status change: 2023-12-31 (0 weeks ago)
kmid2 (maintained by: cheeselee, kkofler)
kmid2-2.4.0-27.fc39.src requires drumstick0-devel = 0.5.0-34.fc39
kmid2-2.4.0-27.fc39.x86_64 requires drumstick0 = 0.5.0-34.fc39,
libdrumstick-alsa.so.0()(64bit), libdrumstick-file.so.0()(64bit)
Depending on: python-google-cloud-access-context-manager (1), status change:
2023-12-15 (2 weeks ago)
python-google-cloud-asset (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-asset-3.22.0-1.fc40.src requires
python3dist(google-cloud-access-context-manager) = 0.1.16
python3-google-cloud-asset-3.22.0-1.fc40.noarch requires
python3.12dist(google-cloud-access-context-manager) = 0.1.16
Depending on: python-google-cloud-bigquery-storage (1), status change:
2023-12-15 (2 weeks ago)
python-google-cloud-bigquery (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-bigquery-3.14.0-2.fc40.src requires
python3dist(google-cloud-bigquery-storage) = 2.24
python3-google-cloud-bigquery+bqstorage-3.14.0-2.fc40.noarch requires
python3.12dist(google-cloud-bigquery-storage) = 2.24
Depending on: python-google-cloud-common (1), status change: 2023-12-15 (2
weeks ago)
python-google-cloud-filestore (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-filestore-1.5.0-3.fc39.src requires
python3dist(google-cloud-common) = 1.2
python3-google-cloud-filestore-1.5.0-3.fc39.noarch requires
python3.12dist(google-cloud-common) = 1.2
Depending on: python-google-cloud-org-policy (1), status change: 2023-12-15 (2
weeks ago)
python-google-cloud-asset (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-asset-3.22.0-1.fc40.src requires
python3dist(google-cloud-org-policy) = 1.8.3
python3-google-cloud-asset-3.22.0-1.fc40.noarch requires
python3.12dist(google-cloud-org-policy) = 1.8.3
Depending on: python-google-cloud-os-config (1), status change: 2023-12-15 (2
weeks ago)
python-google-cloud-asset (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-asset-3.22.0-1.fc40.src requires
python3dist(google-cloud-os-config) = 1.16
python3-google-cloud-asset-3.22.0-1.fc40.noarch requires
python3.12dist(google-cloud-os-config) = 1.16
Depending on: python-google-cloud-source-context (1), status change: 2023-12-15
(2 weeks ago)
python-google-cloud-debugger-client (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-debugger-client-1.7.0-2.fc39.src requires
python3dist(google-cloud-source-context) = 1.5
python3-google-cloud-debugger-client-1.7.0-2.fc39.noarch requires
python3.12dist(google-cloud-source-context) = 1.5
Depending on: python-google-cloud-testutils (3), status change: 2023-12-15 (2
weeks ago)
python-google-cloud-bigquery (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-bigquery-3.14.0-2.fc40.src requires
python3dist(google-cloud-testutils) = 1.3.3
python-google-cloud-bigquery-datatransfer (maintained by: fkolwa, miyunari,
orphan, python-packagers-sig)
python-google-cloud-bigquery-datatransfer-3.13.0-2.fc40.src requires
python3dist(google-cloud-testutils) = 1.3.3
python-google-cloud-firestore (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-firestore-2.14.0-3.fc40.src requires
python3dist(google-cloud-testutils) = 1.3.3
Depending on: python-google-crc32c (23), status change: 2023-12-15 (2 weeks ago)
python-google-cloud-storage (maintained by: fkolwa, jonathanspw, miyunari,
python-packagers-sig)
python-google-cloud-storage-2.14.0-2.fc40.src requires
python3dist(google-crc32c) = 1.1.2, python3dist(google-resumable-media) = 2.6
python3-google-cloud-storage-2.14.0-2.fc40.noarch requires
python3.12dist(google-crc32c) = 1.1.2, python3.12dist(google-resumable-media) = 2.6
python-google-resumable-media (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-resumable-media-2.6.0-1.fc40.src requires
python3dist(google-crc32c) = 1.1.2
python3-google-resumable-media-2.6.0-1.fc40.noarch requires
python3.12dist(google-crc32c) = 1.1.2
snakemake (maintained by: major, neuro-sig)
snakemake-7.32.4-2.fc40.src requires python3dist(google-cloud-storage) =
2.14, python3dist(google-crc32c) = 1.1.2
snakemake+google-cloud-7.32.4-2.fc40.noarch requires
python3.12dist(google-cloud-storage) = 2.14, python3.12dist(google-crc32c) = 1.1.2
python-gcsfs (maintained by: fab)
python-gcsfs-2023.6.0-1.fc39.src requires python3dist(fsspec) = 2023.12.2,
python3dist(google-cloud-storage) = 2.14
python3-gcsfs-2023.6.0-1.fc39.noarch requires python3.12dist(fsspec) =
2023.12.2, python3.12dist(google-cloud-storage) = 2.14
python-google-cloud-automl (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-automl-2.12.0-2.fc40.src requires
python3dist(google-cloud-storage) = 2.14
python-google-cloud-bigquery (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-bigquery-3.14.0-2.fc40.src requires
python3dist(google-resumable-media) = 2.6
python3-google-cloud-bigquery-3.14.0-2.fc40.noarch requires
python3.12dist(google-resumable-media) = 2.6
python3-google-cloud-bigquery+geopandas-3.14.0-2.fc40.noarch requires
python3.12dist(geopandas) = 0.14.1
python-fsspec (maintained by: epel-packagers-sig, jonathanspw,
python-packagers-sig, qulogic)
python-fsspec-2023.12.2-1.fc40.src requires python3dist(gcsfs) = 2023.6
python-papermill (maintained by: ankursinha, neuro-sig)
python-papermill-2.4.0-7.fc40.src requires python3dist(gcsfs) = 2023.6
python3-papermill+all-2.4.0-7.fc40.noarch requires python3.12dist(gcsfs) = 2023.6
python3-papermill+gcs-2.4.0-7.fc40.noarch requires python3.12dist(gcsfs) = 2023.6
python-dask (maintained by: epel-packagers-sig, jonathanspw,
python-packagers-sig, qulogic)
python-dask-2023.8.1-3.fc40~bootstrap.src requires python3dist(fsspec) =
2023.12.2
python3-dask-2023.8.1-3.fc40~bootstrap.noarch requires python3.12dist(fsspec)
= 2023.12.2
python-geopandas (maintained by: python-packagers-sig, qulogic)
python-geopandas-0.14.1-1.fc40.src requires python3dist(fsspec) = 2023.12.2
python-reproject (maintained by: astro-sig, sergiopr)
python-reproject-0.13.0-2.fc40.src requires python3dist(dask) = 2023.8.1,
python3dist(dask[array]) = 2023.8.1, python3dist(fsspec) = 2023.12.2
python3-reproject-0.13.0-2.fc40.x86_64 requires python3.12dist(dask) =
2023.8.1, python3.12dist(dask[array]) = 2023.8.1, python3.12dist(fsspec) =
2023.12.2
python-torch (maintained by: trix)
python-torch-2.1.2-1.fc40.src requires python3dist(fsspec) = 2023.12.2
python3-torch-2.1.2-1.fc40.x86_64 requires python3.12dist(fsspec) = 2023.12.2
python-zarr (maintained by: epel-packagers-sig, jonathanspw,
python-packagers-sig, qulogic)
python-zarr-2.16.1-1.fc40.src requires python3dist(fsspec) = 2023.12.2
python-bluepyopt (maintained by: ankursinha, neuro-sig)
python-bluepyopt-1.14.6-5.fc40.src requires python3dist(papermill) = 2.4
python-xarray (maintained by: epel-packagers-sig, jonathanspw,
python-packagers-sig, qulogic)
python-xarray-2023.8.0-1.fc40.src requires python3dist(dask[array]) =
2023.8.1, python3dist(dask[dataframe]) = 2023.8.1
python-xbout (maintained by: davidsch)
python-xbout-0.3.5-8.fc39.src requires python3dist(dask) = 2023.8.1,
python3dist(dask[array]) = 2023.8.1
python3-xbout-0.3.5-8.fc39.noarch requires python3.12dist(dask) = 2023.8.1,
python3.12dist(dask[array]) = 2023.8.1
python-earthpy (maintained by: iztokf)
python-earthpy-0.9.4-9.fc39.src requires python3dist(geopandas) = 0.14.1
python3-earthpy-0.9.4-9.fc39.noarch requires python3.12dist(geopandas) = 0.14.1
python-geodatasets (maintained by: qulogic)
python-geodatasets-2023.12.0-1.fc40.src requires python3-geopandas =
0.14.1-1.fc40
python-geoplot (maintained by: python-packagers-sig, qulogic)
python-geoplot-0.5.1-7.fc40.src requires python3dist(geopandas) = 0.14.1
python3-geoplot-0.5.1-7.fc40.noarch requires python3.12dist(geopandas) = 0.14.1
python-libpysal (maintained by: python-packagers-sig, qulogic)
python-libpysal-4.7.0-5.fc40.src requires python3dist(geopandas) = 0.14.1
python-mapclassify (maintained by: python-packagers-sig, qulogic)
python-mapclassify-2.5.0-2.fc40.src requires python3dist(geopandas) = 0.14.1
python-networkx (maintained by: jjames, plautrba)
python-networkx-3.2.1-2.fc40.src requires python3dist(geopandas) = 0.14.1
python-plotnine (maintained by: gui1ty, neuro-sig)
python-plotnine-0.12.4-4.fc40.src requires python3-geopandas = 0.14.1-1.fc40
python3-plotnine+extra-0.12.4-4.fc40.noarch requires
python3.12dist(geopandas) = 0.14.1
Too many dependencies for python-google-crc32c, not all listed here
Depending on: python-google-resumable-media (22), status change: 2023-12-15 (2
weeks ago)
python-google-cloud-bigquery (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-bigquery-3.14.0-2.fc40.src requires
python3dist(google-resumable-media) = 2.6
python3-google-cloud-bigquery-3.14.0-2.fc40.noarch requires
python3.12dist(google-resumable-media) = 2.6
python3-google-cloud-bigquery+geopandas-3.14.0-2.fc40.noarch requires
python3.12dist(geopandas) = 0.14.1
python-google-cloud-storage (maintained by: fkolwa, jonathanspw, miyunari,
python-packagers-sig)
python-google-cloud-storage-2.14.0-2.fc40.src requires
python3dist(google-resumable-media) = 2.6
python3-google-cloud-storage-2.14.0-2.fc40.noarch requires
python3.12dist(google-resumable-media) = 2.6
python-gcsfs (maintained by: fab)
python-gcsfs-2023.6.0-1.fc39.src requires python3dist(fsspec) = 2023.12.2,
python3dist(google-cloud-storage) = 2.14
python3-gcsfs-2023.6.0-1.fc39.noarch requires python3.12dist(fsspec) =
2023.12.2, python3.12dist(google-cloud-storage) = 2.14
python-google-cloud-automl (maintained by: fkolwa, miyunari, orphan,
python-packagers-sig)
python-google-cloud-automl-2.12.0-2.fc40.src requires
python3dist(google-cloud-storage) = 2.14
snakemake (maintained by: major, neuro-sig)
snakemake-7.32.4-2.fc40.src requires python3dist(google-cloud-storage) = 2.14
snakemake+google-cloud-7.32.4-2.fc40.noarch requires
python3.12dist(google-cloud-storage) = 2.14
python-fsspec (maintained by: epel-packagers-sig, jonathanspw,
python-packagers-sig, qulogic)
python-fsspec-2023.12.2-1.fc40.src requires python3dist(gcsfs) = 2023.6
python-papermill (maintained by: ankursinha, neuro-sig)
python-papermill-2.4.0-7.fc40.src requires python3dist(gcsfs) = 2023.6
python3-papermill+all-2.4.0-7.fc40.noarch requires python3.12dist(gcsfs) = 2023.6
python3-papermill+gcs-2.4.0-7.fc40.noarch requires python3.12dist(gcsfs) = 2023.6
python-dask (maintained by: epel-packagers-sig, jonathanspw,
python-packagers-sig, qulogic)
python-dask-2023.8.1-3.fc40~bootstrap.src requires python3dist(fsspec) =
2023.12.2
python3-dask-2023.8.1-3.fc40~bootstrap.noarch requires python3.12dist(fsspec)
= 2023.12.2
python-geopandas (maintained by: python-packagers-sig, qulogic)
python-geopandas-0.14.1-1.fc40.src requires python3dist(fsspec) = 2023.12.2
python-reproject (maintained by: astro-sig, sergiopr)
python-reproject-0.13.0-2.fc40.src requires python3dist(dask) = 2023.8.1,
python3dist(dask[array]) = 2023.8.1, python3dist(fsspec) = 2023.12.2
python3-reproject-0.13.0-2.fc40.x86_64 requires python3.12dist(dask) =
2023.8.1, python3.12dist(dask[array]) = 2023.8.1, python3.12dist(fsspec) =
2023.12.2
python-torch (maintained by: trix)
python-torch-2.1.2-1.fc40.src requires python3dist(fsspec) = 2023.12.2
python3-torch-2.1.2-1.fc40.x86_64 requires python3.12dist(fsspec) = 2023.12.2
python-zarr (maintained by: epel-packagers-sig, jonathanspw,
python-packagers-sig, qulogic)
python-zarr-2.16.1-1.fc40.src requires python3dist(fsspec) = 2023.12.2
python-bluepyopt (maintained by: ankursinha, neuro-sig)
python-bluepyopt-1.14.6-5.fc40.src requires python3dist(papermill) = 2.4
python-xarray (maintained by: epel-packagers-sig, jonathanspw,
python-packagers-sig, qulogic)
python-xarray-2023.8.0-1.fc40.src requires python3dist(dask[array]) =
2023.8.1, python3dist(dask[dataframe]) = 2023.8.1
python-xbout (maintained by: davidsch)
python-xbout-0.3.5-8.fc39.src requires python3dist(dask) = 2023.8.1,
python3dist(dask[array]) = 2023.8.1
python3-xbout-0.3.5-8.fc39.noarch requires python3.12dist(dask) = 2023.8.1,
python3.12dist(dask[array]) = 2023.8.1
python-earthpy (maintained by: iztokf)
python-earthpy-0.9.4-9.fc39.src requires python3dist(geopandas) = 0.14.1
python3-earthpy-0.9.4-9.fc39.noarch requires python3.12dist(geopandas) = 0.14.1
python-geodatasets (maintained by: qulogic)
python-geodatasets-2023.12.0-1.fc40.src requires python3-geopandas =
0.14.1-1.fc40
python-geoplot (maintained by: python-packagers-sig, qulogic)
python-geoplot-0.5.1-7.fc40.src requires python3dist(geopandas) = 0.14.1
python3-geoplot-0.5.1-7.fc40.noarch requires python3.12dist(geopandas) = 0.14.1
python-libpysal (maintained by: python-packagers-sig, qulogic)
python-libpysal-4.7.0-5.fc40.src requires python3dist(geopandas) = 0.14.1
python-mapclassify (maintained by: python-packagers-sig, qulogic)
python-mapclassify-2.5.0-2.fc40.src requires python3dist(geopandas) = 0.14.1
python-networkx (maintained by: jjames, plautrba)
python-networkx-3.2.1-2.fc40.src requires python3dist(geopandas) = 0.14.1
python-plotnine (maintained by: gui1ty, neuro-sig)
python-plotnine-0.12.4-4.fc40.src requires python3-geopandas = 0.14.1-1.fc40
python3-plotnine+extra-0.12.4-4.fc40.noarch requires
python3.12dist(geopandas) = 0.14.1
Too many dependencies for python-google-resumable-media, not all listed here
Depending on: python-grafeas (1), status change: 2023-12-15 (2 weeks ago)
python-google-cloud-containeranalysis (maintained by: fkolwa, miyunari,
orphan, python-packagers-sig)
python-google-cloud-containeranalysis-2.12.4-1.fc40.src requires
python3dist(grafeas) = 1.9
python3-google-cloud-containeranalysis-2.12.4-1.fc40.noarch requires
python3.12dist(grafeas) = 1.9
Depending on: rubygem-linked-list (1), status change: 2023-12-18 (2 weeks ago)
rubygem-hrx (maintained by: jcpunk, orphan, tdawson)
rubygem-hrx-1.0.0-9.fc39.noarch requires rubygem(linked-list) = 0.0.16
rubygem-hrx-1.0.0-9.fc39.src requires rubygem(linked-list) = 0.0.16
Depending on: sonivox (3), status change: 2023-12-31 (0 weeks ago)
drumstick (maintained by: orphan, yanqiyu)
drumstick-2.8.1-1.fc40.i686 requires libsonivox.so.3
drumstick-2.8.1-1.fc40.src requires sonivox-devel = 3.6.12-2.fc39
drumstick-2.8.1-1.fc40.x86_64 requires libsonivox.so.3()(64bit)
kmetronome (maintained by: orphan)
kmetronome-1.3.1-3.fc39.src requires drumstick-devel = 2.8.1-1.fc40
kmetronome-1.3.1-3.fc39.x86_64 requires libdrumstick-alsa.so.2()(64bit)
vmpk (maintained by: orphan)
vmpk-0.8.10-1.fc40.src requires drumstick-devel = 2.8.1-1.fc40
vmpk-0.8.10-1.fc40.x86_64 requires libdrumstick-rt.so.2()(64bit),
libdrumstick-widgets.so.2()(64bit)
See dependency chains of your packages at
https://packager-dashboard.fedoraproject.org/
See all orphaned packages at https://packager-dashboard.fedoraproject.org/orphan
Affected (co)maintainers (either directly or via packages' dependencies):
ankursinha: python-google-crc32c, python-google-resumable-media
astro-sig: python-pymoc, cdsclient, scamp, python-google-resumable-media,
python-google-crc32c
cheeselee: drumstick0
cicku: tofrodos
davidsch: python-google-crc32c, python-google-resumable-media
epel-packagers-sig: python-google-crc32c, python-google-resumable-media
fab: python-google-crc32c, python-google-resumable-media
fkolwa: python-google-cloud-data-fusion,
python-google-cloud-bigquery-reservation,
python-google-cloud-containeranalysis, python-google-cloud-asset,
python-google-cloud-domains, python-google-cloud-kms,
python-google-cloud-billing-budgets, python-google-cloud-debugger-client,
python-google-cloud-dms, python-google-cloud-source-context,
python-google-cloud-testutils, python-google-cloud-shell,
python-google-cloud-bigquery-datatransfer,
python-google-cloud-bigquery-connection, python-google-cloud-functions,
python-google-cloud-private-ca, python-google-cloud-pubsub,
python-google-cloud-redis, python-google-cloud-api-gateway,
python-google-cloud-spanner, python-google-cloud-dataproc-metastore,
python-google-cloud-firestore, python-google-cloud-org-policy,
python-google-cloud-access-context-manager, python-google-cloud-apigee-connect,
python-google-cloud-datacatalog, python-google-cloud-bigquery,
python-google-cloud-dataproc, python-google-cloud-bigtable,
python-google-cloud-access-approval, python-google-cloud-bigquery-storage,
python-google-resumable-media, python-google-crc32c, python-google-cloud-build,
python-google-cloud-deploy, python-google-cloud-dlp, python-grafeas,
python-google-cloud-iam, python-google-cloud-filestore,
python-google-cloud-common, python-google-cloud-container,
python-google-cloud-billing, python-google-cloud-automl,
python-google-cloud-os-config, python-google-cloud-appengine-admin
go-sig: clash
gui1ty: python-google-crc32c, python-google-resumable-media
iztokf: python-google-crc32c, python-google-resumable-media
jcpunk: rubygem-hrx, rubygem-linked-list
jjames: python-google-crc32c, python-google-resumable-media
jkastner: mrpt
jonathanspw: python-google-crc32c, python-google-resumable-media
kkofler: drumstick0
kwizart: mrpt
major: python-google-crc32c, python-google-resumable-media
miyunari: python-google-cloud-data-fusion,
python-google-cloud-bigquery-reservation,
python-google-cloud-containeranalysis, python-google-cloud-asset,
python-google-cloud-domains, python-google-cloud-kms,
python-google-cloud-billing-budgets, python-google-cloud-debugger-client,
python-google-cloud-dms, python-google-cloud-source-context,
python-google-cloud-testutils, python-google-cloud-shell,
python-google-cloud-bigquery-datatransfer,
python-google-cloud-bigquery-connection, python-google-cloud-functions,
python-google-cloud-private-ca, python-google-cloud-pubsub,
python-google-cloud-redis, python-google-cloud-api-gateway,
python-google-cloud-spanner, python-google-cloud-dataproc-metastore,
python-google-cloud-firestore, python-google-cloud-org-policy,
python-google-cloud-access-context-manager, python-google-cloud-apigee-connect,
python-google-cloud-datacatalog, python-google-cloud-bigquery,
python-google-cloud-dataproc, python-google-cloud-bigtable,
python-google-cloud-access-approval, python-google-cloud-bigquery-storage,
python-google-resumable-media, python-google-crc32c, python-google-cloud-build,
python-google-cloud-deploy, python-google-cloud-dlp, python-grafeas,
python-google-cloud-iam, python-google-cloud-filestore,
python-google-cloud-common, python-google-cloud-container,
python-google-cloud-billing, python-google-cloud-automl,
python-google-cloud-os-config, python-google-cloud-appengine-admin
neuro-sig: python-google-crc32c, python-maya, python-google-resumable-media
orion: libASL
plautrba: python-google-crc32c, python-google-resumable-media
python-packagers-sig: python-google-cloud-data-fusion,
python-google-cloud-bigquery-reservation,
python-google-cloud-containeranalysis, python-google-cloud-asset,
python-google-cloud-domains, python-google-cloud-kms,
python-google-cloud-billing-budgets, python-google-cloud-debugger-client,
python-google-cloud-dms, python-google-cloud-source-context,
python-google-cloud-testutils, python-google-cloud-shell,
python-google-cloud-bigquery-datatransfer,
python-google-cloud-bigquery-connection, python-google-cloud-functions,
python-google-cloud-private-ca, python-google-cloud-pubsub,
python-google-cloud-redis, python-google-cloud-api-gateway,
python-google-cloud-spanner, python-google-cloud-dataproc-metastore,
python-google-cloud-firestore, python-google-cloud-org-policy,
python-google-cloud-access-context-manager, python-google-cloud-apigee-connect,
python-google-cloud-datacatalog, python-google-cloud-bigquery,
python-google-cloud-dataproc, python-google-cloud-bigtable,
python-google-cloud-access-approval, python-google-cloud-bigquery-storage,
python-google-resumable-media, python-google-crc32c, python-google-cloud-build,
python-google-cloud-deploy, python-google-cloud-dlp, python-grafeas,
python-google-cloud-iam, python-google-cloud-filestore,
python-google-cloud-common, python-google-cloud-container,
python-google-cloud-billing, python-google-cloud-automl,
python-google-cloud-os-config, python-google-cloud-appengine-admin
qulogic: python-google-crc32c, python-google-resumable-media
robotics-sig: mrpt
sergiopr: python-google-crc32c, python-google-resumable-media
slaanesh: libASL
tdawson: tofrodos, rubygem-hrx, rubygem-linked-list
trix: python-google-crc32c, python-google-resumable-media
yanqiyu: drumstick0, sonivox, drumstick
--
The script creating this output is run and developed by Fedora
Release Engineering. Please report issues at its pagure instance:
https://pagure.io/releng/
The sources of this script can be found at:
https://pagure.io/releng/blob/main/f/scripts/find_unblocked_orphans.py
Report finished at 2024-01-03 08:56:26 UTC
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
Tuesday, January 2, 2024
[USN-6563-1] Thunderbird vulnerabilities
==========================================================================
Ubuntu Security Notice USN-6563-1
January 02, 2024
thunderbird vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in Thunderbird.
Software Description:
- thunderbird: Mozilla Open Source mail and newsgroup client
Details:
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.(CVE-2023-6857, CVE-2023-6858,
CVE-2023-6859, CVE-2023-6861, CVE-2023-6862, CVE-2023-6863, CVE-2023-6864)
Marcus Brinkmann discovered that Thunderbird did not properly parse a PGP/MIME
payload that contains digitally signed text. An attacker could potentially
exploit this issue to spoof an email message. (CVE-2023-50762)
Marcus Brinkmann discovered that Thunderbird did not properly compare the
signature creation date with the message date and time when using digitally
signed S/MIME email message. An attacker could potentially exploit this
issue to spoof date and time of an email message. (CVE-2023-50761)
DoHyun Lee discovered that Thunderbird did not properly manage memory when
used on systems with the Mesa VM driver. An attacker could potentially
exploit this issue to execute arbitrary code. (CVE-2023-6856)
Andrew Osmond discovered that Thunderbird did not properly validate the
textures produced by remote decoders. An attacker could potentially exploit
this issue to escape the sandbox. (CVE-2023-6860)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
thunderbird 1:115.6.0+build2-0ubuntu0.23.10.1
Ubuntu 23.04:
thunderbird 1:115.6.0+build2-0ubuntu0.23.04.1
Ubuntu 22.04 LTS:
thunderbird 1:115.6.0+build2-0ubuntu0.22.04.1
Ubuntu 20.04 LTS:
thunderbird 1:115.6.0+build2-0ubuntu0.20.04.1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6563-1
CVE-2023-50761, CVE-2023-50762, CVE-2023-6856, CVE-2023-6857,
CVE-2023-6858, CVE-2023-6859, CVE-2023-6860, CVE-2023-6861,
CVE-2023-6862, CVE-2023-6863, CVE-2023-6864
Package Information:
https://launchpad.net/ubuntu/+source/thunderbird/1:115.6.0+build2-0ubuntu0.23.10.1
https://launchpad.net/ubuntu/+source/thunderbird/1:115.6.0+build2-0ubuntu0.23.04.1
https://launchpad.net/ubuntu/+source/thunderbird/1:115.6.0+build2-0ubuntu0.22.04.1
https://launchpad.net/ubuntu/+source/thunderbird/1:115.6.0+build2-0ubuntu0.20.04.1
Ubuntu Security Notice USN-6563-1
January 02, 2024
thunderbird vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in Thunderbird.
Software Description:
- thunderbird: Mozilla Open Source mail and newsgroup client
Details:
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.(CVE-2023-6857, CVE-2023-6858,
CVE-2023-6859, CVE-2023-6861, CVE-2023-6862, CVE-2023-6863, CVE-2023-6864)
Marcus Brinkmann discovered that Thunderbird did not properly parse a PGP/MIME
payload that contains digitally signed text. An attacker could potentially
exploit this issue to spoof an email message. (CVE-2023-50762)
Marcus Brinkmann discovered that Thunderbird did not properly compare the
signature creation date with the message date and time when using digitally
signed S/MIME email message. An attacker could potentially exploit this
issue to spoof date and time of an email message. (CVE-2023-50761)
DoHyun Lee discovered that Thunderbird did not properly manage memory when
used on systems with the Mesa VM driver. An attacker could potentially
exploit this issue to execute arbitrary code. (CVE-2023-6856)
Andrew Osmond discovered that Thunderbird did not properly validate the
textures produced by remote decoders. An attacker could potentially exploit
this issue to escape the sandbox. (CVE-2023-6860)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
thunderbird 1:115.6.0+build2-0ubuntu0.23.10.1
Ubuntu 23.04:
thunderbird 1:115.6.0+build2-0ubuntu0.23.04.1
Ubuntu 22.04 LTS:
thunderbird 1:115.6.0+build2-0ubuntu0.22.04.1
Ubuntu 20.04 LTS:
thunderbird 1:115.6.0+build2-0ubuntu0.20.04.1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6563-1
CVE-2023-50761, CVE-2023-50762, CVE-2023-6856, CVE-2023-6857,
CVE-2023-6858, CVE-2023-6859, CVE-2023-6860, CVE-2023-6861,
CVE-2023-6862, CVE-2023-6863, CVE-2023-6864
Package Information:
https://launchpad.net/ubuntu/+source/thunderbird/1:115.6.0+build2-0ubuntu0.23.10.1
https://launchpad.net/ubuntu/+source/thunderbird/1:115.6.0+build2-0ubuntu0.23.04.1
https://launchpad.net/ubuntu/+source/thunderbird/1:115.6.0+build2-0ubuntu0.22.04.1
https://launchpad.net/ubuntu/+source/thunderbird/1:115.6.0+build2-0ubuntu0.20.04.1
Monday, January 1, 2024
[USN-6562-1] Firefox vulnerabilities
==========================================================================
Ubuntu Security Notice USN-6562-1
January 02, 2024
firefox vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in Firefox.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code.(CVE-2023-6865,
CVE-2023-6857, CVE-2023-6858, CVE-2023-6859, CVE-2023-6866, CVE-2023-6867,
CVE-2023-6861, CVE-2023-6869, CVE-2023-6871, CVE-2023-6872, CVE-2023-6863,
CVE-2023-6864, CVE-2023-6873)
DoHyun Lee discovered that Firefox did not properly manage memory when used
on systems with the Mesa VM driver. An attacker could potentially exploit
this issue to execute arbitrary code. (CVE-2023-6856)
George Pantela and Hubert Kario discovered that Firefox using multiple NSS
NIST curves which were susceptible to a side-channel attack known as
"Minerva". An attacker could potentially exploit this issue to obtain
sensitive information. (CVE-2023-6135)
Andrew Osmond discovered that Firefox did not properly validate the textures
produced by remote decoders. An attacker could potentially exploit this
issue to escape the sandbox. (CVE-2023-6860)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS:
firefox 121.0+build1-0ubuntu0.20.04.1
After a standard system update you need to restart Firefox to make all the
necessary changes.
References:
https://ubuntu.com/security/notices/USN-6562-1
CVE-2023-6135, CVE-2023-6856, CVE-2023-6857, CVE-2023-6858,
CVE-2023-6859, CVE-2023-6860, CVE-2023-6861, CVE-2023-6863,
CVE-2023-6864, CVE-2023-6865, CVE-2023-6866, CVE-2023-6867,
CVE-2023-6869, CVE-2023-6871, CVE-2023-6872, CVE-2023-6873
Package Information:
https://launchpad.net/ubuntu/+source/firefox/121.0+build1-0ubuntu0.20.04.1
Ubuntu Security Notice USN-6562-1
January 02, 2024
firefox vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in Firefox.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code.(CVE-2023-6865,
CVE-2023-6857, CVE-2023-6858, CVE-2023-6859, CVE-2023-6866, CVE-2023-6867,
CVE-2023-6861, CVE-2023-6869, CVE-2023-6871, CVE-2023-6872, CVE-2023-6863,
CVE-2023-6864, CVE-2023-6873)
DoHyun Lee discovered that Firefox did not properly manage memory when used
on systems with the Mesa VM driver. An attacker could potentially exploit
this issue to execute arbitrary code. (CVE-2023-6856)
George Pantela and Hubert Kario discovered that Firefox using multiple NSS
NIST curves which were susceptible to a side-channel attack known as
"Minerva". An attacker could potentially exploit this issue to obtain
sensitive information. (CVE-2023-6135)
Andrew Osmond discovered that Firefox did not properly validate the textures
produced by remote decoders. An attacker could potentially exploit this
issue to escape the sandbox. (CVE-2023-6860)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS:
firefox 121.0+build1-0ubuntu0.20.04.1
After a standard system update you need to restart Firefox to make all the
necessary changes.
References:
https://ubuntu.com/security/notices/USN-6562-1
CVE-2023-6135, CVE-2023-6856, CVE-2023-6857, CVE-2023-6858,
CVE-2023-6859, CVE-2023-6860, CVE-2023-6861, CVE-2023-6863,
CVE-2023-6864, CVE-2023-6865, CVE-2023-6866, CVE-2023-6867,
CVE-2023-6869, CVE-2023-6871, CVE-2023-6872, CVE-2023-6873
Package Information:
https://launchpad.net/ubuntu/+source/firefox/121.0+build1-0ubuntu0.20.04.1
Subscribe to:
Posts (Atom)