Friday, August 30, 2024

[announce] Sept 4 NYC*BUG: GEFS: The Long road to Production Use, Ori Bernstein

GEFS: The Long road to Production Use, Ori Bernstein
2024-09-04 @ 18:45 EDT (22:45 UTC) - NYU Tandon Engineering Building
(new), 370 Jay St, 7th Floor kitchen area, Brooklyn

RSVP: Those either considering or wishing to attend, a guest list is
required by the venue. Please RVSP to rsvp at lists dot nycbug dot org
no later than noon localtime, day-of; an acknowledgement will be sent
and the email address will be used solely for the purpose of attendance
to this meeting's venue.

***The hard deadline for RSVPs is 12 noon EDT on the day of the meeting.***

Remote participation: Plans are to stream via NYC*BUG website. Q&A will
be via IRC on libera.chat channel #nycbug - please preface your
questions with '[Q]'.

GEFS: The Long road to Production Use

Since GEFS was announced and discussed, a lot of debugging and
stabilization has happened. I'm using it on my laptop. Others are
testing it out. But there's still a lot of work to do. Join for an
update on it.
_______________________________________________
announce mailing list
announce@lists.nycbug.org
https://lists.nycbug.org:8443/mailman/listinfo/announce

Thursday, August 29, 2024

Orphaned packages looking for new maintainers

Report started at 2024-08-29 21:00:06 UTC

The following packages are orphaned and will be retired when they
are orphaned for six weeks, unless someone adopts them. If you know for sure
that the package should be retired, please do so now with a proper reason:
https://fedoraproject.org/wiki/How_to_remove_a_package_at_end_of_life

Note: If you received this mail directly you (co)maintain one of the affected
packages or a package that depends on one. Please adopt the affected package or
retire your depending package to avoid broken dependencies, otherwise your
package will be retired when the affected package gets retired.

Request package ownership via the *Take* button in the left column on
https://src.fedoraproject.org/rpms/<pkgname>

Full report available at:
https://a.gtmx.me/orphans/orphans.txt
grep it for your FAS username and follow the dependency chain.

For human readable dependency chains,
see https://packager-dashboard.fedoraproject.org/
For all orphaned packages,
see https://packager-dashboard.fedoraproject.org/orphan

Package (co)maintainers Status Change
================================================================================
Cadence orphan 3 weeks ago
abrt-java-connector @abrt-sig, orphan 0 weeks ago
bfast orphan 5 weeks ago
ctemplate orphan 1 weeks ago
dmlite orphan 4 weeks ago
gearmand orphan 0 weeks ago
ghc-ConfigFile @haskell-lang-sig, orphan 0 weeks ago
ghc-MonadCatchIO-mtl @haskell-lang-sig, orphan 0 weeks ago
ghc-MonadCatchIO-transformers @haskell-lang-sig, orphan 0 weeks ago
ghc-cryptohash @haskell-lang-sig, orphan 0 weeks ago
ghc-highlighting-kate @haskell-lang-sig, orphan 0 weeks ago
ghc-libxml-sax @haskell-lang-sig, orphan 0 weeks ago
gimp-separate+ orphan 0 weeks ago
glsl-language-server orphan 2 weeks ago
java-diff-utils jvanek, orphan 4 weeks ago
libkindrv orphan 1 weeks ago
m2crypto @python-packagers-sig, mitr, 1 weeks ago
orphan
mingw-gdbm orphan 4 weeks ago
orocos-bfl orphan 1 weeks ago
orocos-kdl cottsay, orphan 1 weeks ago
pmix orion, orphan 0 weeks ago
python-bash-kernel orphan 3 weeks ago
python-case ngompa, orphan, pingou 1 weeks ago
python-ffmpeg-python orphan 2 weeks ago
python-grabbit orphan 1 weeks ago
python-hypothesis-fspaths @python-packagers-sig, orphan 2 weeks ago
python-iptools orphan 1 weeks ago
python-jupyter-sphinx orphan 3 weeks ago
python-nb2plots orphan 3 weeks ago
python-opentracing orphan 2 weeks ago
python-scripttester orphan 3 weeks ago
receptor @go-sig, orphan 4 weeks ago
scala mizdebsk, orphan 6 weeks ago

The following packages require above mentioned packages:
Depending on: gearmand (1), status change: 2024-08-26 (0 weeks ago)
php-pecl-gearman (maintained by: pwhalen, remi)
php-pecl-gearman-2.1.2-2.fc41.src requires libgearman-devel = 1.1.21-4.fc41
php-pecl-gearman-2.1.2-2.fc41.x86_64 requires libgearman.so.8()(64bit)

Depending on: ghc-MonadCatchIO-transformers (1), status change: 2024-08-28 (0 weeks ago)
ghc-MonadCatchIO-mtl (maintained by: @haskell-lang-sig, orphan)
ghc-MonadCatchIO-mtl-0.3.1.0-42.fc41.src requires ghc-MonadCatchIO-transformers-devel = 0.3.1.3-43.fc41, ghc-MonadCatchIO-transformers-prof = 0.3.1.3-43.fc41
ghc-MonadCatchIO-mtl-0.3.1.0-42.fc41.x86_64 requires libHSMonadCatchIO-transformers-0.3.1.3-IuU8g3wTFAp1pJuii8rNE2-ghc9.4.5.so()(64bit)
ghc-MonadCatchIO-mtl-devel-0.3.1.0-42.fc41.x86_64 requires ghc-devel(MonadCatchIO-transformers-0.3.1.3-IuU8g3wTFAp1pJuii8rNE2)
ghc-MonadCatchIO-mtl-prof-0.3.1.0-42.fc41.x86_64 requires ghc-prof(MonadCatchIO-transformers-0.3.1.3-IuU8g3wTFAp1pJuii8rNE2)

Depending on: java-diff-utils (4), status change: 2024-07-31 (4 weeks ago)
java-runtime-decompiler (maintained by: jvanek, pmikova, radekmanak)
java-runtime-decompiler-9.1-7.fc41.noarch requires java-diff-utils = 4.12-7.fc41, mvn(io.github.java-diff-utils:java-diff-utils) = 4.12
java-runtime-decompiler-9.1-7.fc41.src requires java-diff-utils = 4.12-7.fc41

scala (maintained by: mizdebsk, orphan)
scala-2.13.13-2.fc41~bootstrap.noarch requires mvn(io.github.java-diff-utils:java-diff-utils) = 4.12
scala-2.13.13-2.fc41~bootstrap.src requires mvn(io.github.java-diff-utils:java-diff-utils) = 4.12

truth (maintained by: orion)
truth-1.0.1-11.fc41.noarch requires mvn(io.github.java-diff-utils:java-diff-utils) = 4.12
truth-1.0.1-11.fc41.src requires mvn(io.github.java-diff-utils:java-diff-utils) = 4.12

vim-syntastic (maintained by: mhjacks)
vim-syntastic-scala-3.10.0-23.fc41.noarch requires scala = 2.13.13-2.fc41~bootstrap

Depending on: m2crypto (10), status change: 2024-08-20 (1 weeks ago)
dmlite (maintained by: orphan)
dmlite-shell-1.15.2-21.fc41.x86_64 requires python3-m2crypto = 0.41.0^git20240613.3156614-1.fc41

dnsviz (maintained by: @dns-sig, jonathanspw, pemensik)
dnsviz-0.10.0-3.fc41.noarch requires python3-m2crypto = 0.41.0^git20240613.3156614-1.fc41
dnsviz-0.10.0-3.fc41.src requires python3-m2crypto = 0.41.0^git20240613.3156614-1.fc41, python3dist(m2crypto) = 0.41

fts-rest-client (maintained by: mipatras)
fts-rest-client-3.13.3-1.fc42.noarch requires python3-m2crypto = 0.41.0^git20240613.3156614-1.fc41, python3.13dist(m2crypto) = 0.41

hash-slinger (maintained by: frankcrawford)
hash-slinger-3.2-5.fc41.noarch requires python3-m2crypto = 0.41.0^git20240613.3156614-1.fc41

ipsilon (maintained by: jonathanspw, kevin, puiterwijk, simo)
ipsilon-3.0.4-17.fc41.src requires python3-m2crypto = 0.41.0^git20240613.3156614-1.fc41

module-build-service (maintained by: breilly, mikem)
module-build-service-3.9.2-9.fc41.noarch requires python3-m2crypto = 0.41.0^git20240613.3156614-1.fc41
module-build-service-3.9.2-9.fc41.src requires python3-m2crypto = 0.41.0^git20240613.3156614-1.fc41

oz (maintained by: clalance)
oz-0.18.1-15.fc41.noarch requires python3-m2crypto = 0.41.0^git20240613.3156614-1.fc41
oz-0.18.1-15.fc41.src requires python3-m2crypto = 0.41.0^git20240613.3156614-1.fc41

ursa-major (maintained by: cqi, julian8628)
ursa-major-0.4.2-12.fc41.noarch requires python3-m2crypto = 0.41.0^git20240613.3156614-1.fc41

imagefactory (maintained by: clalance, kevin)
imagefactory-1.1.16-14.fc41.noarch requires oz = 0.18.1-15.fc41

imagefactory-plugins (maintained by: kevin)
imagefactory-plugins-IndirectionCloud-1.1.16-13.fc41.noarch requires imagefactory-plugin-api = 1.0, oz = 0.18.1-15.fc41
imagefactory-plugins-OVA-1.1.16-13.fc41.noarch requires imagefactory-plugin-api = 1.0, oz = 0.18.1-15.fc41
imagefactory-plugins-TinMan-1.1.16-13.fc41.noarch requires imagefactory-plugin-api = 1.0, oz = 0.18.1-15.fc41
imagefactory-plugins-ovfcommon-1.1.16-13.fc41.noarch requires oz = 0.18.1-15.fc41
imagefactory-plugins-1.1.16-13.fc41.noarch requires imagefactory = 1.1.16-14.fc41
imagefactory-plugins-RHEVM-1.1.16-13.fc41.noarch requires imagefactory-plugin-api = 1.0
imagefactory-plugins-vSphere-1.1.16-13.fc41.noarch requires imagefactory-plugin-api = 1.0

Depending on: pmix (67), status change: 2024-08-28 (0 weeks ago)
openmpi (maintained by: dledford, orion, pkfed)
openmpi-5.0.5-2.fc41.src requires pmix-devel = 4.2.8-3.fc41
openmpi-5.0.5-2.fc41.x86_64 requires libpmix.so.2()(64bit)
openmpi-devel-5.0.5-2.fc41.x86_64 requires libpmix.so.2()(64bit)

prrte (maintained by: orion)
prrte-3.0.2-6.fc41.src requires pmix-devel = 4.2.8-3.fc41, pmix-tools = 4.2.8-3.fc41
prrte-3.0.2-6.fc41.x86_64 requires libpmix.so.2()(64bit)
prrte-libs-3.0.2-6.fc41.x86_64 requires libpmix.so.2()(64bit)

slurm (maintained by: @epel-packagers-sig, neil, salimma)
slurm-24.05.2-1.fc42.src requires pmix-devel = 4.2.8-3.fc41
slurm-24.05.2-1.fc42.x86_64 requires pmix = 4.2.8-3.fc41

MUMPS (maintained by: sagitter)
MUMPS-openmpi-5.6.2-6.fc42.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), libmpi_mpifh.so.40()(64bit)(openmpi-x86_64), libmpi_usempi_ignore_tkr.so.40()(64bit)(openmpi-x86_64), libmpi_usempif08.so.40()(64bit)(openmpi-x86_64), openmpi(x86-64) = 5.0.5-2.fc41
MUMPS-openmpi-examples-5.6.2-6.fc42.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), libmpi_mpifh.so.40()(64bit)(openmpi-x86_64), libmpi_usempi_ignore_tkr.so.40()(64bit)(openmpi-x86_64), libmpi_usempif08.so.40()(64bit)(openmpi-x86_64), openmpi = 5.0.5-2.fc41

MUSIC (maintained by: @neuro-sig, ankursinha)
MUSIC-1.2.1-7.fc41.src requires openmpi-devel = 5.0.5-2.fc41
MUSIC-openmpi-1.2.1-7.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi = 5.0.5-2.fc41
MUSIC-openmpi-devel-1.2.1-7.fc41.x86_64 requires openmpi = 5.0.5-2.fc41
python3-MUSIC-openmpi-1.2.1-7.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi = 5.0.5-2.fc41

amg4psblas (maintained by: sagitter)
amg4psblas-1.1.2-6.fc41.src requires openmpi-devel = 5.0.5-2.fc41
amg4psblas-openmpi-1.1.2-6.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi(x86-64) = 5.0.5-2.fc41

arbor (maintained by: @neuro-sig, ankursinha)
arbor-0.9.0-8.fc41.src requires openmpi-devel = 5.0.5-2.fc41
arbor-openmpi-0.9.0-8.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi = 5.0.5-2.fc41, python3-openmpi = 5.0.5-2.fc41

auryn (maintained by: @neuro-sig, ankursinha)
auryn-0.8.3-8.fc41.src requires openmpi-devel = 5.0.5-2.fc41
auryn-openmpi-0.8.3-8.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi = 5.0.5-2.fc41

boost (maintained by: denisarnaud, jwakely, mcermak, ppalka, trodgers)
boost-graph-openmpi-1.83.0-8.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)
boost-openmpi-1.83.0-8.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)
boost-openmpi-python3-1.83.0-8.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), python3-openmpi(x86-64) = 5.0.5-2.fc41

bout++ (maintained by: davidsch)
bout++-5.1.0-13.fc41.src requires openmpi-devel = 5.0.5-2.fc41
bout++-openmpi-5.1.0-13.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)
python3-bout++-openmpi-5.1.0-13.fc41.x86_64 requires openmpi = 5.0.5-2.fc41, python3-openmpi = 5.0.5-2.fc41

cgnslib (maintained by: cicku, loveshack, orion, smani)
cgnslib-openmpi-devel-4.4.0-5.fc41.x86_64 requires openmpi-devel = 5.0.5-2.fc41
cgnslib-openmpi-libs-4.4.0-5.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

coin-or-Ipopt (maintained by: pcpa, sagitter)
coin-or-Ipopt-3.14.14-2.fc41.src requires pkgconfig(ompi) = 5.0.5
coin-or-Ipopt-openmpi-3.14.14-2.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

combblas (maintained by: sagitter)
combblas-openmpi-2.0.0-8.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi(x86-64) = 5.0.5-2.fc41
combblas-openmpi-devel-2.0.0-8.fc41.x86_64 requires openmpi-devel(x86-64) = 5.0.5-2.fc41

cp2k (maintained by: @scitech_sig, jussilehtola, lecris, tomspur)
cp2k-openmpi-2024.1-8.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), libmpi_mpifh.so.40()(64bit)(openmpi-x86_64), libmpi_usempi_ignore_tkr.so.40()(64bit)(openmpi-x86_64), libmpi_usempif08.so.40()(64bit)(openmpi-x86_64)

dbcsr (maintained by: lecris, orion)
dbcsr-openmpi-2.6.0-6.fc41.x86_64 requires libmpi_mpifh.so.40()(64bit)(openmpi-x86_64), libmpi_usempi_ignore_tkr.so.40()(64bit)(openmpi-x86_64), libmpi_usempif08.so.40()(64bit)(openmpi-x86_64)

dl_poly (maintained by: loveshack)
dl_poly-1.10-22.fc41.src requires openmpi-devel = 5.0.5-2.fc41
dl_poly-openmpi-1.10-22.fc41.x86_64 requires libmpi_mpifh.so.40()(64bit)(openmpi-x86_64), openmpi(x86-64) = 5.0.5-2.fc41

elk (maintained by: marcindulak)
elk-9.2.12-2.fc41.src requires openmpi-devel = 5.0.5-2.fc41
elk-openmpi-9.2.12-2.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), libmpi_mpifh.so.40()(64bit)(openmpi-x86_64), libmpi_usempi_ignore_tkr.so.40()(64bit)(openmpi-x86_64), libmpi_usempif08.so.40()(64bit)(openmpi-x86_64)

espresso (maintained by: jngrad, junghans)
espresso-4.2.2-4.fc41.src requires openmpi-devel = 5.0.5-2.fc41
python3-espresso-openmpi-4.2.2-4.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

fftw (maintained by: dcantrell, jchaloup, jussilehtola, konradm)
fftw-openmpi-devel-3.3.10-13.fc41.x86_64 requires openmpi-devel = 5.0.5-2.fc41
fftw-openmpi-libs-double-3.3.10-13.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)
fftw-openmpi-libs-long-3.3.10-13.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)
fftw-openmpi-libs-single-3.3.10-13.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

freefem++ (maintained by: corsepiu)
freefem++-4.14-10.fc42.src requires openmpi-devel = 5.0.5-2.fc41
freefem++-openmpi-4.14-10.fc42.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

ga (maintained by: marcindulak)
ga-5.8.2-8.fc41.src requires openmpi-devel = 5.0.5-2.fc41
ga-openmpi-5.8.2-8.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), libmpi_mpifh.so.40()(64bit)(openmpi-x86_64), libmpi_usempi_ignore_tkr.so.40()(64bit)(openmpi-x86_64), libmpi_usempif08.so.40()(64bit)(openmpi-x86_64)
ga-openmpi-devel-5.8.2-8.fc41.x86_64 requires openmpi-devel = 5.0.5-2.fc41
ga-openmpi-static-5.8.2-8.fc41.x86_64 requires openmpi-devel = 5.0.5-2.fc41

gloo (maintained by: trix)
gloo-0.5.0^git20230824.01a0c81-12.fc41.src requires openmpi-devel = 5.0.5-2.fc41
gloo-openmpi-0.5.0^git20230824.01a0c81-12.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

gmsh (maintained by: hobbes1069, ignatenkobrain, jkastner, smani)
gmsh-4.13.2-3.fc41.src requires openmpi-devel = 5.0.5-2.fc41
gmsh-openmpi-devel-4.13.2-3.fc41.x86_64 requires openmpi-devel = 5.0.5-2.fc41
gmsh-openmpi-libs-4.13.2-3.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

gpaw (maintained by: marcindulak)
gpaw-24.1.0-3.fc41.src requires openmpi-devel = 5.0.5-2.fc41
python3-gpaw-openmpi-24.1.0-3.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

gretl (maintained by: hannes)
gretl-2024b-2.fc41.src requires openmpi-devel = 5.0.5-2.fc41
gretl-openmpi-2024b-2.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi = 5.0.5-2.fc41

gromacs (maintained by: junghans)
gromacs-2024.1-2.fc41.src requires openmpi-devel = 5.0.5-2.fc41
gromacs-openmpi-2024.1-2.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

hdf5 (maintained by: @scitech_sig, ignatenkobrain, orion, sagitter)
hdf5-openmpi-1.12.1-20.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)
hdf5-openmpi-devel-1.12.1-20.fc41.x86_64 requires openmpi-devel(x86-64) = 5.0.5-2.fc41

hpl (maintained by: jskarvad)
hpl-openmpi-2.2-19.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), libmpi_mpifh.so.40()(64bit)(openmpi-x86_64), libmpi_usempi_ignore_tkr.so.40()(64bit)(openmpi-x86_64), libmpi_usempif08.so.40()(64bit)(openmpi-x86_64)

hpx (maintained by: diehlpk, junghans)
hpx-1.10.0-4.fc42.src requires openmpi-devel = 5.0.5-2.fc41
hpx-openmpi-1.10.0-4.fc42.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi-devel = 5.0.5-2.fc41
hpx-openmpi-devel-1.10.0-4.fc42.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi-devel = 5.0.5-2.fc41
hpx-openmpi-examples-1.10.0-4.fc42.x86_64 requires openmpi = 5.0.5-2.fc41

hypre (maintained by: fuller, loveshack)
hypre-openmpi-2.24.0-15.fc42.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi(x86-64) = 5.0.5-2.fc41
hypre-openmpi-devel-2.24.0-15.fc42.x86_64 requires openmpi-devel(x86-64) = 5.0.5-2.fc41

intel-mpi-benchmarks (maintained by: kheib, michich)
intel-mpi-benchmarks-2021.8-4.fc41.src requires openmpi-devel = 5.0.5-2.fc41
intel-mpi-benchmarks-openmpi-2021.8-4.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi = 5.0.5-2.fc41

lammps (maintained by: cz4rs, ellio167, junghans, rberger)
lammps-openmpi-20230802.2-3.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi = 5.0.5-2.fc41

libcircle (maintained by: junghans)
libcircle-0.3-17.fc41.src requires openmpi-devel = 5.0.5-2.fc41
libcircle-openmpi-0.3-17.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

libneurosim (maintained by: @neuro-sig, ankursinha)
libneurosim-openmpi-1.2.0-12.20210110.gitafc003f.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi = 5.0.5-2.fc41
libneurosim-openmpi-devel-1.2.0-12.20210110.gitafc003f.fc41.x86_64 requires openmpi = 5.0.5-2.fc41

mathgl (maintained by: krege)
mathgl-openmpi-8.0.1-14.fc42.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

mfem (maintained by: topazus)
mfem-4.7-3.fc41.src requires openmpi-devel = 5.0.5-2.fc41
mfem-openmpi-4.7-3.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi(x86-64) = 5.0.5-2.fc41
mfem-openmpi-devel-4.7-3.fc41.x86_64 requires openmpi-devel(x86-64) = 5.0.5-2.fc41

mpi4py (maintained by: @python-packagers-sig, limb, tomspur)
mpi4py-4.0.0-1.fc41.src requires openmpi-devel = 5.0.5-2.fc41
python3-mpi4py-openmpi-4.0.0-1.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), python3-openmpi(x86-64) = 5.0.5-2.fc41

mpibash (maintained by: junghans)
mpibash-1.4-2.fc41.src requires openmpi-devel = 5.0.5-2.fc41
mpibash-openmpi-1.4-2.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

nest (maintained by: @neuro-sig, ankursinha)
nest-3.8-1.fc42.src requires openmpi-devel = 5.0.5-2.fc41
nest-openmpi-3.8-1.fc42.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi = 5.0.5-2.fc41
python3-nest-openmpi-3.8-1.fc42.x86_64 requires openmpi = 5.0.5-2.fc41

netcdf-cxx4 (maintained by: @scitech_sig, orion)
netcdf-cxx4-openmpi-4.3.1-13.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)
netcdf-cxx4-openmpi-devel-4.3.1-13.fc41.x86_64 requires openmpi-devel = 5.0.5-2.fc41

netcdf-fortran (maintained by: @scitech_sig, orion)
netcdf-fortran-4.6.1-2.fc41.src requires openmpi-devel = 5.0.5-2.fc41
netcdf-fortran-openmpi-devel-4.6.1-2.fc41.x86_64 requires openmpi-devel = 5.0.5-2.fc41

netcdf (maintained by: @scitech_sig, orion)
netcdf-openmpi-4.9.2-6.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)
netcdf-openmpi-devel-4.9.2-6.fc41.x86_64 requires openmpi-devel(x86-64) = 5.0.5-2.fc41

netgen-mesher (maintained by: hobbes1069, smani)
netgen-mesher-6.2.2404-2.fc41.src requires openmpi-devel = 5.0.5-2.fc41
netgen-mesher-openmpi-devel-6.2.2404-2.fc41.x86_64 requires openmpi-devel = 5.0.5-2.fc41
netgen-mesher-openmpi-libs-6.2.2404-2.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)
python3-netgen-mesher-openmpi-6.2.2404-2.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

neuron (maintained by: @neuro-sig, ankursinha)
neuron-8.2.2-11.fc41.src requires openmpi-devel = 5.0.5-2.fc41
neuron-openmpi-8.2.2-11.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi = 5.0.5-2.fc41

nwchem (maintained by: marcindulak)
nwchem-7.2.2-7.fc41.src requires openmpi-devel = 5.0.5-2.fc41
nwchem-openmpi-7.2.2-7.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), libmpi_mpifh.so.40()(64bit)(openmpi-x86_64), libmpi_usempi_ignore_tkr.so.40()(64bit)(openmpi-x86_64), libmpi_usempif08.so.40()(64bit)(openmpi-x86_64), openmpi = 5.0.5-2.fc41

orsa (maintained by: lkundrak, zbyszek)
orsa-openmpi-0.7.0-78.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

osu-micro-benchmarks (maintained by: kheib, michich)
osu-micro-benchmarks-7.4-1.fc41.src requires openmpi-devel = 5.0.5-2.fc41
osu-micro-benchmarks-openmpi-7.4-1.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi = 5.0.5-2.fc41

paraview (maintained by: @scitech_sig, orion, sagitter)
paraview-5.12.1-5.fc41.src requires openmpi-devel = 5.0.5-2.fc41
paraview-openmpi-5.12.1-5.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

petsc (maintained by: sagitter)
petsc-openmpi-3.20.6-10.fc42.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), libmpi_mpifh.so.40()(64bit)(openmpi-x86_64)
petsc-openmpi-devel-3.20.6-10.fc42.x86_64 requires openmpi-devel(x86-64) = 5.0.5-2.fc41
python3-petsc-openmpi-3.20.6-10.fc42.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi(x86-64) = 5.0.5-2.fc41

psblas3 (maintained by: sagitter)
psblas3-3.8.1-6.post2.fc41.src requires openmpi-devel = 5.0.5-2.fc41
psblas3-openmpi-3.8.1-6.post2.fc41.x86_64 requires libmpi_mpifh.so.40()(64bit)(openmpi-x86_64), openmpi(x86-64) = 5.0.5-2.fc41
psblas3-openmpi-static-3.8.1-6.post2.fc41.x86_64 requires openmpi(x86-64) = 5.0.5-2.fc41

scotch (maintained by: fuller, smani)
ptscotch-openmpi-7.0.5-1.fc42.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

python-dijitso (maintained by: limb)
python-dijitso-2019.1.0-20.fc41.src requires openmpi-devel = 5.0.5-2.fc41

python-lfpy (maintained by: @neuro-sig, lbazan, victortyau)
python-lfpy-2.3-7.fc41.src requires openmpi-devel = 5.0.5-2.fc41

python-pytest-mpi (maintained by: orion)
python-pytest-mpi-0.6-10.fc41.src requires openmpi-devel = 5.0.5-2.fc41

python-steps (maintained by: @neuro-sig, ankursinha)
python-steps-3.6.0-36.fc41.src requires openmpi-devel = 5.0.5-2.fc41
python3-steps-openmpi-3.6.0-36.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi = 5.0.5-2.fc41

python-torch (maintained by: @rocm-packagers-sig, trix)
python-torch-2.4.0-8.fc42.src requires openmpi-devel = 5.0.5-2.fc41

h5py (maintained by: orion, stevetraylen, terjeros)
python3-h5py-openmpi-3.11.0-3.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi = 5.0.5-2.fc41

vtk (maintained by: @scitech_sig, orion)
python3-vtk-openmpi-9.2.6-17.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)
vtk-openmpi-9.2.6-17.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)
vtk-openmpi-devel-9.2.6-17.fc41.x86_64 requires openmpi-devel = 5.0.5-2.fc41

quantum-espresso (maintained by: marcindulak)
quantum-espresso-7.0-12.fc41.src requires openmpi-devel = 5.0.5-2.fc41
quantum-espresso-openmpi-7.0-12.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), libmpi_mpifh.so.40()(64bit)(openmpi-x86_64), openmpi = 5.0.5-2.fc41

sandia-omega-h (maintained by: @neuro-sig, gui1ty)
sandia-omega-h-9.34.13-7.fc41.src requires openmpi-devel = 5.0.5-2.fc41
sandia-omega-h-openmpi-9.34.13-7.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi = 5.0.5-2.fc41
sandia-omega-h-openmpi-devel-9.34.13-7.fc41.x86_64 requires openmpi-devel = 5.0.5-2.fc41

scalapack (maintained by: spot, tomspur)
scalapack-openmpi-2.2.0-10.fc41.x86_64 requires openmpi = 5.0.5-2.fc41
scalapack-openmpi-devel-2.2.0-10.fc41.x86_64 requires openmpi-devel = 5.0.5-2.fc41

scalasca (maintained by: loveshack)
scalasca-2.6.1-7.fc41.src requires openmpi-devel = 5.0.5-2.fc41
scalasca-openmpi-2.6.1-7.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi(x86-64) = 5.0.5-2.fc41

scorep (maintained by: jreuter, loveshack, orion)
scorep-8.4-3.fc41.src requires openmpi-devel = 5.0.5-2.fc41

sundials (maintained by: sagitter)
sundials-openmpi-6.7.0-4.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

superlu_dist (maintained by: fuller, loveshack, sagitter)
superlu_dist-openmpi-1:8.2.0-5.fc42.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), libmpi_mpifh.so.40()(64bit)(openmpi-x86_64), libmpi_usempi_ignore_tkr.so.40()(64bit)(openmpi-x86_64), libmpi_usempif08.so.40()(64bit)(openmpi-x86_64)
superlu_dist-openmpi-devel-1:8.2.0-5.fc42.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64), openmpi-devel(x86-64) = 5.0.5-2.fc41

valgrind (maintained by: ahajkova, dodji, fche, jakub, jcheca, mjw)
valgrind-openmpi-1:3.23.0-5.fc41.x86_64 requires libmpi.so.40()(64bit)(openmpi-x86_64)

votca (maintained by: junghans)
votca-2024.1-1.fc41.src requires openmpi-devel = 5.0.5-2.fc41

Too many dependencies for pmix, not all listed here

Depending on: python-bash-kernel (1), status change: 2024-08-05 (3 weeks ago)
python-jupyter-sphinx (maintained by: orphan)
python-jupyter-sphinx-0.5.3-5.fc41.src requires python3dist(bash-kernel) = 0.9.3

Depending on: python-case (1), status change: 2024-08-16 (1 weeks ago)
python-hpilo (maintained by: aekoroglu)
python-hpilo-4.4.3-9.fc41.src requires python3-case = 1.5.3-22.fc41

Depending on: python-scripttester (1), status change: 2024-08-03 (3 weeks ago)
python-nb2plots (maintained by: orphan)
python-nb2plots-0.7.2-5.fc41.src requires python3dist(scripttester) = 0.1

Depending on: scala (1), status change: 2024-07-18 (6 weeks ago)
vim-syntastic (maintained by: mhjacks)
vim-syntastic-scala-3.10.0-23.fc41.noarch requires scala = 2.13.13-2.fc41~bootstrap

Affected (co)maintainers
@abrt-sig: abrt-java-connector
@dns-sig: m2crypto
@epel-packagers-sig: pmix
@go-sig: receptor
@haskell-lang-sig: ghc-MonadCatchIO-mtl, ghc-ConfigFile, ghc-highlighting-kate, ghc-MonadCatchIO-transformers, ghc-cryptohash, ghc-libxml-sax
@neuro-sig: pmix
@python-packagers-sig: m2crypto, pmix, python-hypothesis-fspaths
@rocm-packagers-sig: pmix
@scitech_sig: pmix
aekoroglu: python-case
ahajkova: pmix
ankursinha: pmix
breilly: m2crypto
cicku: pmix
clalance: m2crypto
corsepiu: pmix
cottsay: orocos-kdl
cqi: m2crypto
cz4rs: pmix
davidsch: pmix
dcantrell: pmix
denisarnaud: pmix
diehlpk: pmix
dledford: pmix
dodji: pmix
ellio167: pmix
fche: pmix
frankcrawford: m2crypto
fuller: pmix
gui1ty: pmix
hannes: pmix
hobbes1069: pmix
ignatenkobrain: pmix
jakub: pmix
jchaloup: pmix
jcheca: pmix
jkastner: pmix
jngrad: pmix
jonathanspw: m2crypto
jreuter: pmix
jskarvad: pmix
julian8628: m2crypto
junghans: pmix
jussilehtola: pmix
jvanek: java-diff-utils
jwakely: pmix
kevin: m2crypto
kheib: pmix
konradm: pmix
krege: pmix
lbazan: pmix
lecris: pmix
limb: pmix
lkundrak: pmix
loveshack: pmix
marcindulak: pmix
mcermak: pmix
mhjacks: scala, java-diff-utils
michich: pmix
mikem: m2crypto
mipatras: m2crypto
mitr: m2crypto
mizdebsk: scala, java-diff-utils
mjw: pmix
neil: pmix
ngompa: python-case
orion: pmix, java-diff-utils
pcpa: pmix
pemensik: m2crypto
pingou: python-case
pkfed: pmix
pmikova: java-diff-utils
ppalka: pmix
puiterwijk: m2crypto
pwhalen: gearmand
radekmanak: java-diff-utils
rberger: pmix
remi: gearmand
sagitter: pmix
salimma: pmix
simo: m2crypto
smani: pmix
spot: pmix
stevetraylen: pmix
terjeros: pmix
tomspur: pmix
topazus: pmix
trix: pmix
trodgers: pmix
victortyau: pmix
zbyszek: pmix

Orphans (33): Cadence abrt-java-connector bfast ctemplate dmlite
gearmand ghc-ConfigFile ghc-MonadCatchIO-mtl
ghc-MonadCatchIO-transformers ghc-cryptohash ghc-highlighting-kate
ghc-libxml-sax gimp-separate+ glsl-language-server java-diff-utils
libkindrv m2crypto mingw-gdbm orocos-bfl orocos-kdl pmix
python-bash-kernel python-case python-ffmpeg-python python-grabbit
python-hypothesis-fspaths python-iptools python-jupyter-sphinx
python-nb2plots python-opentracing python-scripttester receptor
scala


Orphans (dependend on) (9): gearmand ghc-MonadCatchIO-transformers
java-diff-utils m2crypto pmix python-bash-kernel python-case
python-scripttester scala


Orphans (rawhide) for at least 6 weeks (dependend on) (1): scala


Orphans (rawhide) (not depended on) (24): Cadence abrt-java-connector
bfast ctemplate dmlite ghc-ConfigFile ghc-MonadCatchIO-mtl
ghc-cryptohash ghc-highlighting-kate ghc-libxml-sax gimp-separate+
glsl-language-server libkindrv mingw-gdbm orocos-bfl orocos-kdl
python-ffmpeg-python python-grabbit python-hypothesis-fspaths
python-iptools python-jupyter-sphinx python-nb2plots
python-opentracing receptor


Orphans (rawhide) for at least 6 weeks (not dependend on) (0):


Depending packages (rawhide) (86): MUMPS MUSIC amg4psblas arbor auryn
boost bout++ cgnslib coin-or-Ipopt combblas cp2k dbcsr dl_poly
dmlite dnsviz elk espresso fftw freefem++ fts-rest-client ga
ghc-MonadCatchIO-mtl gloo gmsh gpaw gretl gromacs h5py
hash-slinger hdf5 hpl hpx hypre imagefactory imagefactory-plugins
intel-mpi-benchmarks ipsilon java-runtime-decompiler lammps
libcircle libneurosim mathgl mfem module-build-service mpi4py
mpibash nest netcdf netcdf-cxx4 netcdf-fortran netgen-mesher
neuron nwchem openmpi orsa osu-micro-benchmarks oz paraview petsc
php-pecl-gearman prrte psblas3 python-dijitso python-hpilo
python-jupyter-sphinx python-lfpy python-nb2plots
python-pytest-mpi python-steps python-torch quantum-espresso
sandia-omega-h scala scalapack scalasca scorep scotch slurm
sundials superlu_dist truth ursa-major valgrind vim-syntastic
votca vtk


Packages depending on packages orphaned (rawhide) for more than 6
weeks (1): vim-syntastic

--
The script creating this output is run and developed by Fedora
Release Engineering. Please report issues at its pagure instance:
https://pagure.io/releng/
The sources of this script can be found at:
https://pagure.io/releng/blob/main/f/scripts/find_unblocked_orphans.py

Report finished at 2024-08-29 21:05:41 UTC

Ubuntu 24.04.1 LTS released

The Ubuntu team is pleased to announce the release of Ubuntu 24.04.1 LTS
(Long-Term Support) for its Desktop, Server, and Cloud products, as well
as other flavours of Ubuntu with long-term support.

As usual, this point release includes many updates and updated
installation media has been provided so that fewer updates will need to
be downloaded after installation. These include security updates and
corrections for other high-severity bugs, with a focus on maintaining
stability and compatibility with Ubuntu 24.04 LTS.

Kubuntu 24.04.1 LTS, Ubuntu Budgie 24.04.1 LTS, Ubuntu MATE 24.04.1 LTS,
Lubuntu 24.04.1 LTS, Ubuntu Kylin 24.04.1 LTS, Ubuntu Studio 24.04.1 LTS,
Xubuntu 24.04.1 LTS, Edubuntu 24.04.1 LTS, Ubuntu Cinnamon 24.04.1 LTS
and Ubuntu Unity 24.04.1 LTS are also now available. More details can be
found in their individual release notes (see 'Official flavours'):

https://discourse.ubuntu.com/t/ubuntu-24-04-lts-noble-numbat-release-notes/39890

Maintenance updates will be provided for 5 years from the initial 24.04 LTS
release for Ubuntu Desktop, Ubuntu Server, Ubuntu Cloud, and Ubuntu Core.
All the remaining flavours will be supported for 3 years. Additional security
support is available with ESM (Expanded Security Maintenance).

To get Ubuntu 24.04.1 LTS
-------------------------

In order to download Ubuntu 24.04.1 LTS, visit:

https://ubuntu.com/download

Users of Ubuntu 22.04 LTS will be offered an automatic upgrade to
24.04.1 LTS via Update Manager.

We recommend that all users read the 24.04.1 LTS release notes, which
document caveats and workarounds for known issues, as well as more
in-depth notes on the release itself. They are available at:

https://discourse.ubuntu.com/t/ubuntu-24-04-lts-noble-numbat-release-notes/39890

If you have a question, or if you think you may have found a bug but
aren't sure, you can try asking in any of the following places:

#ubuntu on irc.libera.chat
https://lists.ubuntu.com/mailman/listinfo/ubuntu-users
https://ubuntuforums.org
https://askubuntu.com


Help Shape Ubuntu
-----------------

If you would like to help shape Ubuntu, take a look at the list of ways
you can participate at:

https://discourse.ubuntu.com/contribute


About Ubuntu
------------

Ubuntu is a full-featured Linux distribution for desktops, laptops,
clouds and servers, with a fast and easy installation and regular
releases. A tightly-integrated selection of excellent applications is
included, and an incredible variety of add-on software is just a few
clicks away.

Professional services including support are available from Canonical and
hundreds of other companies around the world. For more information
about support, visit:

https://ubuntu.com/support


More Information
----------------

You can learn more about Ubuntu and about this release on our website
listed below:

https://ubuntu.com/

To sign up for future Ubuntu announcements, please subscribe to Ubuntu's
very low volume announcement list at:

https://lists.ubuntu.com/mailman/listinfo/ubuntu-announce

On behalf of the Ubuntu Release Team,
Łukasz 'sil2100' Zemczak

--
ubuntu-announce mailing list
ubuntu-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-announce

Wednesday, August 28, 2024

[USN-6972-4] Linux kernel (Oracle) vulnerabilities

-----BEGIN PGP SIGNATURE-----

wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmbPqF4FAwAAAAAACgkQZ0GeRcM5nt2N
BwgAshUwFfFT++oAFR2eayjnK3aaKQHrKjQKVewUH0Ov+qL/oczl9pbHaVniAA7713qECM4qMaI6
lU3PRRHx7mFIg7et1ChLVZJsg+0wAudhGLuSl9ijQdHserzL5ALjpSMxR9/eastZ9RUDmdLAWU3z
AMbKrPVXgZ1eAxRPnq5gJowOLPXYhrZbGDkjDD+dlBFkD3nMul6NbYOBHFj7n43wecqzkm1gvuyJ
7lbzz7FqQ4k7mW8CzW8GcOXAC8G7ufAxtuL6kpf5j4LZOoOJtYVAaJqzw085jBZawVNpEswQOVl4
kkD9r+CZDsWoJWYUXIN/ZNNRJ3hQJXiV6jryR3M8PA==
=shkw
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6972-4
August 28, 2024

linux-oracle vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-oracle: Linux kernel for Oracle Cloud systems

Details:

Yuxuan Hu discovered that the Bluetooth RFCOMM protocol driver in the Linux
Kernel contained a race condition, leading to a NULL pointer dereference.
An attacker could possibly use this to cause a denial of service (system
crash). (CVE-2024-22099)

It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel, leading to a null pointer dereference vulnerability. A
privileged local attacker could use this to possibly cause a denial of
service (system crash). (CVE-2024-24860)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SuperH RISC architecture;
- User-Mode Linux (UML);
- GPU drivers;
- MMC subsystem;
- Network drivers;
- PHY drivers;
- Pin controllers subsystem;
- Xen hypervisor drivers;
- GFS2 file system;
- Core kernel;
- Bluetooth subsystem;
- IPv4 networking;
- IPv6 networking;
- HD-audio driver;
- ALSA SH drivers;
(CVE-2024-26903, CVE-2024-35835, CVE-2023-52644, CVE-2024-39292,
CVE-2024-36940, CVE-2024-26600, CVE-2023-52629, CVE-2024-35955,
CVE-2023-52760, CVE-2023-52806, CVE-2024-39484, CVE-2024-26679,
CVE-2024-26654, CVE-2024-36901, CVE-2024-26687, CVE-2023-52470)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS
linux-image-4.15.0-1134-oracle 4.15.0-1134.145
Available with Ubuntu Pro
linux-image-oracle-lts-18.04 4.15.0.1134.139
Available with Ubuntu Pro

Ubuntu 16.04 LTS
linux-image-4.15.0-1134-oracle 4.15.0-1134.145~16.04.1
Available with Ubuntu Pro
linux-image-oracle 4.15.0.1134.145~16.04.1
Available with Ubuntu Pro

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-6972-4
https://ubuntu.com/security/notices/USN-6972-3
https://ubuntu.com/security/notices/USN-6972-2
https://ubuntu.com/security/notices/USN-6972-1
CVE-2023-52470, CVE-2023-52629, CVE-2023-52644, CVE-2023-52760,
CVE-2023-52806, CVE-2024-22099, CVE-2024-24860, CVE-2024-26600,
CVE-2024-26654, CVE-2024-26679, CVE-2024-26687, CVE-2024-26903,
CVE-2024-35835, CVE-2024-35955, CVE-2024-36901, CVE-2024-36940,
CVE-2024-39292, CVE-2024-39484

Planned Outage - network hardware updates - 2024-08-27 15:00 UTC

The content of this message was lost. It was probably cross-posted to
multiple lists and previously handled on another list.
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue

Tuesday, August 27, 2024

[USN-6981-1] Drupal vulnerabilities

-----BEGIN PGP SIGNATURE-----

wsF5BAABCAAjFiEER/Iq56J1QpFyK/CQ9uFA9ts1nlgFAmbOCZUFAwAAAAAACgkQ9uFA9ts1nljQ
Wg//aBa2S3AEt+78u8EnFUmFgn78X/WoLgjTNedvzzIWir9wEwNh3bUCN2TLHNNmS37/5+30tgn2
G/x19j1AAIjfiiAwXAJWITOHwH+7rvCMp4WRnkJLGEtQqsXjN/iBPnvjLmRgE2Jo7GeNNCHow2aS
tEQKMrQnHDsISFBOdN+Z1cmb9Stw/8um5XHs4f7S9ltPmDZ8jYCSmD1m9tA28jt9z189be1+m9Kg
CM3I2KNHXBLRU3WRz+QLzqTKOoIOOWx6BdG2blRKyN3PwOgeZ5Uw262AVHfxZBJ9rpV+C2zM9598
7cRg6bevkTSP4mtWyEMxdWyCxYuh78w7PquOD+GILS+aYs5Ur1t6cc92hSEFmbdUv7rrVG9w4Ei2
6TQCaCnvVN/xzICp3RP/sN4t5hEMOOHW2e7w8/zYvMY7M6v/W+BUUYY39/0b7b8+c0v4yPhwdNEO
j+S1NjpMSoM1gVQeIQy1VhaM/slBox/3T8Hv4KusnenHOdRP9rJVl0SJuphYhoLA+FsWG81BHnHa
j4ltOR+zQN8abXID7sC3Pgl2PlGoL5iwifDlrtyq7HhpyTFnxm9yo8fcqB7YOG+jLuTqwI7Sqy9r
RiCaMFskn5UikfwzjpXZZWI1ABvccd9GKWEkiBAOCwysZzb6vw5j+/zl9rJ0FLIWj0MF0zShzKGr
bGo=
=hg+A
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6981-1
August 27, 2024

drupal7 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Drupal could be made to crash or run programs if it received
specially crafted network traffic.

Software Description:
- drupal7: fully-featured content management framework

Details:

It was discovered that Drupal incorrectly sanitized uploaded filenames. A
remote attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-13671)

It was discovered that Drupal incorrectly sanitized archived filenames. A
remote attacker could possibly use this issue to overwrite arbitrary files,
or execute arbitrary code. (CVE-2020-28948, CVE-2020-28949)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS
  drupal7                         7.44-1ubuntu1~16.04.0+esm2
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-6981-1
  CVE-2020-13671, CVE-2020-28948, CVE-2020-28949

Fedora Linux 41 Bodhi updates-testing activation & Beta freeze

Hi all,

Today's an important day on the Fedora Linux 41 schedule [1], with
several significant cut-offs. First, today is the Bodhi
updates-testing activation point [2]. That means that from now on, all
Fedora Linux 41 packages must be submitted for updates-testing and
pass the relevant requirements [3] before they are marked as 'stable'
and moved to the Fedora Repository.

Today is also the Beta freeze [4]. This means only packages that fix
accepted blocker or freeze exception bugs [5][6] will be marked as
'stable' and included in the Beta composes. Other builds will remain
in updates-testing until the Beta release is approved, at which point
the Beta freeze is lifted and packages can move to 'stable' as usual
until the Final freeze.

Today is also the Software String freeze [7], which means that strings
marked for translation in Fedora-translated projects should not now be
changed for Fedora Linux f41.

Finally, today is the 'completion deadline' Change Checkpoint [8],
meaning that Fedora Linux 41 Changes must now be 'feature complete or
close enough to completion that a majority of its functionality can be
tested'. All tracking bugs should be on ON_QA state or later to
reflect this.

Regards,
Fedora Release Engineering

[1] https://fedorapeople.org/groups/schedule/f-41/f-41-key-tasks.html
[2] https://fedoraproject.org/wiki/Updates_Policy#Bodhi_enabling
[3] https://fedoraproject.org/wiki/Updates_Policy#Branched_release
[4] https://fedoraproject.org/wiki/Milestone_freezes
[5] https://fedoraproject.org/wiki/QA:SOP_blocker_bug_process
[6] https://fedoraproject.org/wiki/QA:SOP_freeze_exception_bug_process
[7] https://fedoraproject.org/wiki/ReleaseEngineering/StringFreezePolicy
[8] https://fedoraproject.org/wiki/Changes/Policy
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue

Monday, August 26, 2024

[USN-6973-3] Linux kernel (AWS) vulnerabilities

-----BEGIN PGP SIGNATURE-----

wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmbMx2IFAwAAAAAACgkQZ0GeRcM5nt0k
MAf9HaGy4yVrH8k7vASd07hyZMw9r2c0Vj3Ns/Yhki7bc6GaQqvYlbOHW3q7At46af2HBVDtU3eG
RMjSHQ3I1D67UsYN6MZ2mFW+cMf9aqI7qXkBQSE4/SOrM2nGkGJa5dNh01REPrmk/QK1v+1ovxob
MgOl6uglJ8hMKUjyNZyvfy0kD76c2tqo3e7qPlkkVC6zfokjzfqXC8Za0+Mp+7AEAu+8RLnLcrrG
xVPo0rFmIJThhhXUCiK3XG8A+qv5w2WhucR2n9Nuq5yIT1e2wZNtC4yqGAyXQPbhmi36Y3uUypZd
jU5t77BHmpL9rONYwiic0bUMZ74RouPyMKhA44p1GQ==
=PaX3
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6973-3
August 26, 2024

linux-aws-5.4 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-aws-5.4: Linux kernel for Amazon Web Services (AWS) systems

Details:

It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel, leading to a null pointer dereference vulnerability. A
privileged local attacker could use this to possibly cause a denial of
service (system crash). (CVE-2024-24860)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SuperH RISC architecture;
- MMC subsystem;
- Network drivers;
- SCSI drivers;
- GFS2 file system;
- IPv4 networking;
- IPv6 networking;
- HD-audio driver;
(CVE-2024-26830, CVE-2024-39484, CVE-2024-36901, CVE-2024-26929,
CVE-2024-26921, CVE-2021-46926, CVE-2023-52629, CVE-2023-52760)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS
linux-image-5.4.0-1131-aws 5.4.0-1131.141~18.04.1
Available with Ubuntu Pro
linux-image-aws 5.4.0.1131.141~18.04.1
Available with Ubuntu Pro

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-6973-3
https://ubuntu.com/security/notices/USN-6973-2
https://ubuntu.com/security/notices/USN-6973-1
CVE-2021-46926, CVE-2023-52629, CVE-2023-52760, CVE-2024-24860,
CVE-2024-26830, CVE-2024-26921, CVE-2024-26929, CVE-2024-36901,
CVE-2024-39484

Saturday, August 24, 2024

rpki-client 9.2 released

rpki-client 9.2 has just been released and will be available in the
rpki-client directory of any OpenBSD mirror soon. It is recommended
that all users upgrade to this version for improved reliability.

rpki-client is a FREE, easy-to-use implementation of the Resource
Public Key Infrastructure (RPKI) for Relying Parties to facilitate
validation of BGP announcements. The program queries the global RPKI
repository system and validates untrusted network inputs. The program
outputs validated ROA payloads, BGPsec Router keys, and ASPA payloads
in configuration formats suitable for OpenBGPD and BIRD, and supports
emitting CSV and JSON for consumption by other routing stacks.

See RFC 6480 and RFC 6811 for a description of how RPKI and BGP Prefix
Origin Validation help secure the global Internet routing system.

rpki-client was primarily developed by Kristaps Dzonsons, Claudio
Jeker, Job Snijders, Theo Buehler, Theo de Raadt and Sebastian Benoit
as part of the OpenBSD Project.

This release includes the following changes to the previous release:

- Ensure synchronization jobs are stopped when the timeout is reached.

- Fix a corner case in repository handling. If the last RRDP repository
failed to load, rpki-client would fail to fall back to rsync due to an
ordering bug in the event loop.

- Improve detection of duplicate file paths. Only trigger a duplicate
error if a valid path is revisited otherwise a bad CA could prevent
legitimate files from being considered valid.

- Normalize internal representation of the caRepository to have a
trailing slash and ensure that the rpkiManifest is a file inside it.

rpki-client works on all operating systems with a libcrypto library
based on OpenSSL 1.1 or LibreSSL 3.6, a libtls library compatible with
LibreSSL 3.6 or later, expat and zlib.

rpki-client is known to compile and run on at least the following
operating systems: Alpine, CentOS, Debian, Fedora, FreeBSD, Red Hat,
Rocky, Ubuntu, macOS, and of course OpenBSD!

It is our hope that packagers take interest and help adapt
rpki-client-portable to more distributions.

The mirrors where rpki-client is available can be found on
https://www.rpki-client.org/portable.html

Reporting Bugs:
===============

General bugs may be reported to tech@openbsd.org

Portable bugs may be filed at
https://github.com/rpki-client/rpki-client-portable

We welcome feedback and improvements from the broader community.
Thanks to all of the contributors who helped make this release
possible.

Assistance to coordinate security issues is available via
security@openbsd.org.

Friday, August 23, 2024

[USN-6972-3] Linux kernel (Azure) vulnerabilities

-----BEGIN PGP SIGNATURE-----

wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmbIuysFAwAAAAAACgkQZ0GeRcM5nt3K
3Af9H/UkSKFvwcwHtFrh5Ezw3MKni0tBhoU+vKY4AZRZugpIVky+n1jBgSPVGAoacM26f3L0aQVr
YgO8ueUVaa1O4asJPk6qsaTAeCOK1ZnV6gk+4WUjKPrIYIg2cOkzEN88cPelvEgseC17aHo8hbLF
+3LOcqUYkC02STOVq0Wit2tzKizzhZ6EH5XUa+Zy7Mz+wSo+379/RxOlzyJKaXFPfOd3ybhdqIV5
9irBZhTCZvv7KGKywLGkh4/CTUi60sjQDaSiu0M1mhNtTRCiqoleMrTkkS5cPN4K76Cl9qriTttI
avvHAIJ2bPoNfYsLzgFZBgYgmt1E2tcw+ev6C8mCRQ==
=0WuN
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6972-3
August 23, 2024

linux-azure, linux-azure-4.15 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-azure-4.15: Linux kernel for Microsoft Azure Cloud systems
- linux-azure: Linux kernel for Microsoft Azure Cloud systems

Details:

Yuxuan Hu discovered that the Bluetooth RFCOMM protocol driver in the Linux
Kernel contained a race condition, leading to a NULL pointer dereference.
An attacker could possibly use this to cause a denial of service (system
crash). (CVE-2024-22099)

It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel, leading to a null pointer dereference vulnerability. A
privileged local attacker could use this to possibly cause a denial of
service (system crash). (CVE-2024-24860)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SuperH RISC architecture;
- User-Mode Linux (UML);
- GPU drivers;
- MMC subsystem;
- Network drivers;
- PHY drivers;
- Pin controllers subsystem;
- Xen hypervisor drivers;
- GFS2 file system;
- Core kernel;
- Bluetooth subsystem;
- IPv4 networking;
- IPv6 networking;
- HD-audio driver;
- ALSA SH drivers;
(CVE-2024-26903, CVE-2024-35835, CVE-2023-52644, CVE-2024-39292,
CVE-2024-36940, CVE-2024-26600, CVE-2023-52629, CVE-2024-35955,
CVE-2023-52760, CVE-2023-52806, CVE-2024-39484, CVE-2024-26679,
CVE-2024-26654, CVE-2024-36901, CVE-2024-26687, CVE-2023-52470)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS
linux-image-4.15.0-1180-azure 4.15.0-1180.195
Available with Ubuntu Pro
linux-image-azure-lts-18.04 4.15.0.1180.148
Available with Ubuntu Pro

Ubuntu 16.04 LTS
linux-image-4.15.0-1180-azure 4.15.0-1180.195~16.04.1
Available with Ubuntu Pro
linux-image-azure 4.15.0.1180.195~16.04.1
Available with Ubuntu Pro

Ubuntu 14.04 LTS
linux-image-4.15.0-1180-azure 4.15.0-1180.195~14.04.1
Available with Ubuntu Pro
linux-image-azure 4.15.0.1180.195~14.04.1
Available with Ubuntu Pro

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-6972-3
https://ubuntu.com/security/notices/USN-6972-2
https://ubuntu.com/security/notices/USN-6972-1
CVE-2023-52470, CVE-2023-52629, CVE-2023-52644, CVE-2023-52760,
CVE-2023-52806, CVE-2024-22099, CVE-2024-24860, CVE-2024-26600,
CVE-2024-26654, CVE-2024-26679, CVE-2024-26687, CVE-2024-26903,
CVE-2024-35835, CVE-2024-35955, CVE-2024-36901, CVE-2024-36940,
CVE-2024-39292, CVE-2024-39484

[USN-6974-2] Linux kernel (Oracle) vulnerabilities

-----BEGIN PGP SIGNATURE-----

wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmbIuzoFAwAAAAAACgkQZ0GeRcM5nt3R
agf8C4ua/MfEDax2yZMwyGaQxuEeaA/6AQe9YZgculrbFcWIo2scnM9O5QHFhYB9J7Vpl52zI4lL
ScQvVXcvRbv+kWeTYArtWL+RK6Q6bZYKeHNwh2OVkOzIdIuwg4AD3euvFi+MZwLklrFDd2EnXfJC
/5ViStPjDgTeY++r1mJplRz3h7/kS3AsGrOq/vSwC1MHGRICLCsSBqQIY44knDCDx/guUkB/HiW2
8SpGmW62U+wGoMKOMw+eMc6dUXm6svBvJ+mGOEJ8qzNm94oycFds38s6Q73/wzwhW7LFNBZ43jUP
hlaYi9Kv4kZC+/s+QxVywKZ7rXqM95mKTKyzjvdzVw==
=PmQ6
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6974-2
August 23, 2024

linux-oracle-5.15 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-oracle-5.15: Linux kernel for Oracle Cloud systems

Details:

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SuperH RISC architecture;
- User-Mode Linux (UML);
- MMC subsystem;
- Network drivers;
- GFS2 file system;
- IPv4 networking;
- IPv6 networking;
(CVE-2024-26921, CVE-2023-52629, CVE-2024-26680, CVE-2024-26830,
CVE-2024-39484, CVE-2024-39292, CVE-2024-36901, CVE-2023-52760)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
linux-image-5.15.0-1066-oracle 5.15.0-1066.72~20.04.1
linux-image-oracle 5.15.0.1066.72~20.04.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-6974-2
https://ubuntu.com/security/notices/USN-6974-1
CVE-2023-52629, CVE-2023-52760, CVE-2024-26680, CVE-2024-26830,
CVE-2024-26921, CVE-2024-36901, CVE-2024-39292, CVE-2024-39484

Package Information:

https://launchpad.net/ubuntu/+source/linux-oracle-5.15/5.15.0-1066.72~20.04.1

[USN-6973-2] Linux kernel (Azure) vulnerabilities

-----BEGIN PGP SIGNATURE-----

wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmbIuzEFAwAAAAAACgkQZ0GeRcM5nt1L
GQf+OQx/FIa8Y+tqDxtVG3YQaJmxZeU4O6SSECAlg3ylcHzkfO3/LoWMIHy65zuK52+wA0ZMXy4+
aLL+kalSlV08CNkXrf4daR773mMFTxbRF/WZ4/rGOIXcNxau/zbrhSkUV7pd6BJNKd+60Jxp4YzS
GlK1lcj/4Wi/C+boVvyhqcABpx1IL5oHB6mlJfiH2n8xOWRzG41bCHl0RoQbjGBNTWsWxMvoptEr
fuhwymU9fmUmiBHlHOpP9jN96vWbgI5ohq9JkezRwIq/bdvBWwxxi6+h+QLDK9IzoEdIK2WO3q93
FAVneOxDXGuB9R04GvXmOjXthjFjR5TypXPc1qXGng==
=9eVH
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6973-2
August 23, 2024

linux-azure-5.4 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-azure-5.4: Linux kernel for Microsoft Azure cloud systems

Details:

It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel, leading to a null pointer dereference vulnerability. A
privileged local attacker could use this to possibly cause a denial of
service (system crash). (CVE-2024-24860)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SuperH RISC architecture;
- MMC subsystem;
- Network drivers;
- SCSI drivers;
- GFS2 file system;
- IPv4 networking;
- IPv6 networking;
- HD-audio driver;
(CVE-2024-26830, CVE-2024-39484, CVE-2024-36901, CVE-2024-26929,
CVE-2024-26921, CVE-2021-46926, CVE-2023-52629, CVE-2023-52760)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS
linux-image-5.4.0-1136-azure 5.4.0-1136.143~18.04.1
Available with Ubuntu Pro
linux-image-azure 5.4.0.1136.143~18.04.1
Available with Ubuntu Pro

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-6973-2
https://ubuntu.com/security/notices/USN-6973-1
CVE-2021-46926, CVE-2023-52629, CVE-2023-52760, CVE-2024-24860,
CVE-2024-26830, CVE-2024-26921, CVE-2024-26929, CVE-2024-36901,
CVE-2024-39484