Tuesday, November 19, 2024
[USN-7119-1] Linux kernel (IoT) vulnerabilities
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmc9K/cFAwAAAAAACgkQZ0GeRcM5nt1B
FQf+IBO7U4qG8XvO/AgsUOzfhJkXH7Te3AQdxZiTMaKomoT/petR9kY1K7Qxu42RbI0NTVOKMmXa
OFFsp3UQv8wtiG43aO9NUIDVTBFmgPM6CD5419abRJ4RIRu4QRf8EvgZfz46EntAe5yuU2xKlC22
U6BzRvSeQ6wk28PJwhwmd4Kn2X6wiYCZKFz05FFekhJH+8szF1l6r8w40Vq4Pzf7BKJnzrNUn4y/
eIhrCaiQ+XFM+xneHGqSvGdRmLPgQPfTdeCiqKy4aS8C0luZ2WzvlHxdG8RoF6C5reKwPNj3RvHG
M0XamqgRr1lqKnmIhybMiCodnQ14HjwZoAaHzv53PA==
=23d4
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7119-1
November 19, 2024
linux-iot vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-iot: Linux kernel for IoT platforms
Details:
Ziming Zhang discovered that the VMware Virtual GPU DRM driver in the Linux
kernel contained an integer overflow vulnerability. A local attacker could
use this to cause a denial of service (system crash). (CVE-2022-36402)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- PowerPC architecture;
- User-Mode Linux (UML);
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Android drivers;
- Serial ATA and Parallel ATA drivers;
- ATM drivers;
- Drivers core;
- CPU frequency scaling framework;
- Device frequency scaling framework;
- GPU drivers;
- HID subsystem;
- Hardware monitoring drivers;
- InfiniBand drivers;
- Input Device core drivers;
- Input Device (Miscellaneous) drivers;
- IOMMU subsystem;
- IRQ chip drivers;
- ISDN/mISDN subsystem;
- Modular ISDN driver;
- LED subsystem;
- Multiple devices driver;
- Media drivers;
- EEPROM drivers;
- VMware VMCI Driver;
- MMC subsystem;
- Network drivers;
- Near Field Communication (NFC) drivers;
- NVME drivers;
- Device tree and open firmware driver;
- Parport drivers;
- PCI subsystem;
- Pin controllers subsystem;
- Remote Processor subsystem;
- S/390 drivers;
- SCSI drivers;
- QCOM SoC drivers;
- Direct Digital Synthesis drivers;
- TTY drivers;
- Userspace I/O drivers;
- DesignWare USB3 driver;
- USB Gadget drivers;
- USB Host Controller drivers;
- USB Serial drivers;
- USB Type-C Connector System Software Interface driver;
- USB over IP driver;
- Watchdog drivers;
- BTRFS file system;
- File systems infrastructure;
- Ext4 file system;
- F2FS file system;
- GFS2 file system;
- JFS file system;
- NILFS2 file system;
- Netfilter;
- BPF subsystem;
- Core kernel;
- DMA mapping infrastructure;
- Tracing infrastructure;
- Radix Tree data structure library;
- Kernel userspace event delivery library;
- Objagg library;
- Memory management;
- Amateur Radio drivers;
- Bluetooth subsystem;
- CAN network layer;
- Networking core;
- Ethtool driver;
- IPv4 networking;
- IPv6 networking;
- IUCV driver;
- KCM (Kernel Connection Multiplexor) sockets driver;
- MAC80211 subsystem;
- RxRPC session sockets;
- Network traffic control;
- SCTP protocol;
- Sun RPC protocol;
- TIPC protocol;
- TLS protocol;
- Wireless networking;
- AppArmor security module;
- Integrity Measurement Architecture(IMA) framework;
- Simplified Mandatory Access Control Kernel framework;
- SoC audio core drivers;
- USB sound devices;
(CVE-2024-46750, CVE-2024-43853, CVE-2024-46722, CVE-2024-42311,
CVE-2024-46679, CVE-2023-52918, CVE-2024-42309, CVE-2024-42160,
CVE-2024-26668, CVE-2024-42271, CVE-2024-40929, CVE-2024-46747,
CVE-2024-41064, CVE-2024-43839, CVE-2024-46757, CVE-2024-41059,
CVE-2024-42301, CVE-2024-46737, CVE-2024-42297, CVE-2024-41015,
CVE-2024-43854, CVE-2024-42289, CVE-2024-41017, CVE-2024-26787,
CVE-2024-47667, CVE-2024-46675, CVE-2024-42246, CVE-2024-46723,
CVE-2024-46817, CVE-2024-43841, CVE-2024-26800, CVE-2024-41098,
CVE-2022-48863, CVE-2023-52531, CVE-2024-42265, CVE-2024-46828,
CVE-2024-41020, CVE-2024-42305, CVE-2024-46755, CVE-2024-46744,
CVE-2024-43871, CVE-2024-43884, CVE-2024-41042, CVE-2024-43914,
CVE-2024-43856, CVE-2024-27397, CVE-2024-26607, CVE-2024-42228,
CVE-2024-41091, CVE-2024-26677, CVE-2024-38611, CVE-2024-43867,
CVE-2024-46829, CVE-2021-47188, CVE-2024-46756, CVE-2024-45025,
CVE-2024-42313, CVE-2024-44947, CVE-2024-26669, CVE-2024-47668,
CVE-2024-44987, CVE-2024-42295, CVE-2024-42281, CVE-2024-43880,
CVE-2024-46777, CVE-2024-46780, CVE-2024-42285, CVE-2024-26891,
CVE-2024-46714, CVE-2024-44999, CVE-2024-41068, CVE-2024-44944,
CVE-2024-43882, CVE-2024-27051, CVE-2024-41072, CVE-2024-46783,
CVE-2024-46781, CVE-2024-26885, CVE-2024-46844, CVE-2024-47669,
CVE-2024-45008, CVE-2024-46758, CVE-2024-44954, CVE-2024-45021,
CVE-2024-42304, CVE-2024-41081, CVE-2024-46798, CVE-2024-43890,
CVE-2024-46840, CVE-2024-44960, CVE-2024-41012, CVE-2022-48791,
CVE-2024-43908, CVE-2024-46721, CVE-2024-43829, CVE-2024-41073,
CVE-2024-42306, CVE-2024-46745, CVE-2024-43858, CVE-2024-47663,
CVE-2024-46782, CVE-2024-42244, CVE-2024-41090, CVE-2024-38602,
CVE-2024-45003, CVE-2024-35848, CVE-2024-43883, CVE-2024-46677,
CVE-2024-42280, CVE-2024-43846, CVE-2024-47659, CVE-2024-44965,
CVE-2024-43893, CVE-2024-26960, CVE-2024-46676, CVE-2024-45016,
CVE-2024-46689, CVE-2024-44998, CVE-2024-44995, CVE-2024-41022,
CVE-2024-45026, CVE-2024-46739, CVE-2024-43830, CVE-2024-42286,
CVE-2024-26640, CVE-2024-27012, CVE-2024-45006, CVE-2024-42276,
CVE-2024-46818, CVE-2024-39494, CVE-2024-43860, CVE-2024-41070,
CVE-2023-52614, CVE-2024-42283, CVE-2024-44969, CVE-2024-42229,
CVE-2024-46740, CVE-2024-44948, CVE-2024-46822, CVE-2024-46738,
CVE-2024-36484, CVE-2024-41065, CVE-2024-46685, CVE-2024-44935,
CVE-2024-46759, CVE-2024-42292, CVE-2024-43879, CVE-2024-42287,
CVE-2024-42288, CVE-2024-41063, CVE-2024-41011, CVE-2024-44946,
CVE-2024-42290, CVE-2024-38570, CVE-2024-42310, CVE-2024-46743,
CVE-2024-43861, CVE-2024-42131, CVE-2021-47212, CVE-2024-46719,
CVE-2024-46815, CVE-2024-26641, CVE-2024-43894, CVE-2024-44988,
CVE-2024-42259, CVE-2024-46771, CVE-2024-46673, CVE-2024-45028,
CVE-2024-46761, CVE-2024-41071, CVE-2024-38630, CVE-2024-43835,
CVE-2024-46800, CVE-2024-42284)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS
linux-image-5.4.0-1044-iot 5.4.0-1044.45
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7119-1
CVE-2021-47188, CVE-2021-47212, CVE-2022-36402, CVE-2022-48791,
CVE-2022-48863, CVE-2023-52531, CVE-2023-52614, CVE-2023-52918,
CVE-2024-26607, CVE-2024-26640, CVE-2024-26641, CVE-2024-26668,
CVE-2024-26669, CVE-2024-26677, CVE-2024-26787, CVE-2024-26800,
CVE-2024-26885, CVE-2024-26891, CVE-2024-26960, CVE-2024-27012,
CVE-2024-27051, CVE-2024-27397, CVE-2024-35848, CVE-2024-36484,
CVE-2024-38570, CVE-2024-38602, CVE-2024-38611, CVE-2024-38630,
CVE-2024-39494, CVE-2024-40929, CVE-2024-41011, CVE-2024-41012,
CVE-2024-41015, CVE-2024-41017, CVE-2024-41020, CVE-2024-41022,
CVE-2024-41042, CVE-2024-41059, CVE-2024-41063, CVE-2024-41064,
CVE-2024-41065, CVE-2024-41068, CVE-2024-41070, CVE-2024-41071,
CVE-2024-41072, CVE-2024-41073, CVE-2024-41081, CVE-2024-41090,
CVE-2024-41091, CVE-2024-41098, CVE-2024-42131, CVE-2024-42160,
CVE-2024-42228, CVE-2024-42229, CVE-2024-42244, CVE-2024-42246,
CVE-2024-42259, CVE-2024-42265, CVE-2024-42271, CVE-2024-42276,
CVE-2024-42280, CVE-2024-42281, CVE-2024-42283, CVE-2024-42284,
CVE-2024-42285, CVE-2024-42286, CVE-2024-42287, CVE-2024-42288,
CVE-2024-42289, CVE-2024-42290, CVE-2024-42292, CVE-2024-42295,
CVE-2024-42297, CVE-2024-42301, CVE-2024-42304, CVE-2024-42305,
CVE-2024-42306, CVE-2024-42309, CVE-2024-42310, CVE-2024-42311,
CVE-2024-42313, CVE-2024-43829, CVE-2024-43830, CVE-2024-43835,
CVE-2024-43839, CVE-2024-43841, CVE-2024-43846, CVE-2024-43853,
CVE-2024-43854, CVE-2024-43856, CVE-2024-43858, CVE-2024-43860,
CVE-2024-43861, CVE-2024-43867, CVE-2024-43871, CVE-2024-43879,
CVE-2024-43880, CVE-2024-43882, CVE-2024-43883, CVE-2024-43884,
CVE-2024-43890, CVE-2024-43893, CVE-2024-43894, CVE-2024-43908,
CVE-2024-43914, CVE-2024-44935, CVE-2024-44944, CVE-2024-44946,
CVE-2024-44947, CVE-2024-44948, CVE-2024-44954, CVE-2024-44960,
CVE-2024-44965, CVE-2024-44969, CVE-2024-44987, CVE-2024-44988,
CVE-2024-44995, CVE-2024-44998, CVE-2024-44999, CVE-2024-45003,
CVE-2024-45006, CVE-2024-45008, CVE-2024-45016, CVE-2024-45021,
CVE-2024-45025, CVE-2024-45026, CVE-2024-45028, CVE-2024-46673,
CVE-2024-46675, CVE-2024-46676, CVE-2024-46677, CVE-2024-46679,
CVE-2024-46685, CVE-2024-46689, CVE-2024-46714, CVE-2024-46719,
CVE-2024-46721, CVE-2024-46722, CVE-2024-46723, CVE-2024-46737,
CVE-2024-46738, CVE-2024-46739, CVE-2024-46740, CVE-2024-46743,
CVE-2024-46744, CVE-2024-46745, CVE-2024-46747, CVE-2024-46750,
CVE-2024-46755, CVE-2024-46756, CVE-2024-46757, CVE-2024-46758,
CVE-2024-46759, CVE-2024-46761, CVE-2024-46771, CVE-2024-46777,
CVE-2024-46780, CVE-2024-46781, CVE-2024-46782, CVE-2024-46783,
CVE-2024-46798, CVE-2024-46800, CVE-2024-46815, CVE-2024-46817,
CVE-2024-46818, CVE-2024-46822, CVE-2024-46828, CVE-2024-46829,
CVE-2024-46840, CVE-2024-46844, CVE-2024-47659, CVE-2024-47663,
CVE-2024-47667, CVE-2024-47668, CVE-2024-47669
Package Information:
https://launchpad.net/ubuntu/+source/linux-iot/5.4.0-1044.45
[USN-7120-1] Linux kernel vulnerabilities
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmc9LAoFAwAAAAAACgkQZ0GeRcM5nt2K
1wf/XKx812eDJf6mk7FHGYDnTRzwhhHSCoG4+A67mkAgladHdUbJNuCGfwSvVsNH5T8fZkhz3Rub
JECR0+DvLnAA6bc6w/CPQ9qWPI+BP2ccuBV0SLFI5Un8k5PbWVmN9VsmUG2FBtTLu9LM66GrqhN1
DxpkwaB71Ng05nxuTx/KD3CfkT/U4iVz+mXjEjd7KBlp4on6TCwWwxWZI3uocnRwBY3VCWKxSyQa
JBx7ZF454qH9q+iPoTmSXQil78hwcN9Q9aSXJBCW9UUr1jGZaHhBL50inhJNaZAJxHD0x5HzxMA4
jJTeMO1ViqBqyJkC9sus6ctaQKkkX6znKvXrcXKHow==
=YQpD
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7120-1
November 19, 2024
linux, linux-aws, linux-gcp, linux-gcp-6.8, linux-gke, linux-hwe-6.8,
linux-ibm, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency,
linux-oem-6.8, linux-oracle, linux-raspi vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux: Linux kernel
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-gke: Linux kernel for Google Container Engine (GKE) systems
- linux-ibm: Linux kernel for IBM cloud systems
- linux-nvidia: Linux kernel for NVIDIA systems
- linux-nvidia-lowlatency: Linux low latency kernel for NVIDIA systems
- linux-oem-6.8: Linux kernel for OEM systems
- linux-oracle: Linux kernel for Oracle Cloud systems
- linux-raspi: Linux kernel for Raspberry Pi systems
- linux-gcp-6.8: Linux kernel for Google Cloud Platform (GCP) systems
- linux-hwe-6.8: Linux hardware enablement (HWE) kernel
- linux-nvidia-6.8: Linux kernel for NVIDIA systems
Details:
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- File systems infrastructure;
- Network traffic control;
(CVE-2024-46800, CVE-2024-43882)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.04 LTS
linux-image-6.8.0-1014-gke 6.8.0-1014.18
linux-image-6.8.0-1015-raspi 6.8.0-1015.17
linux-image-6.8.0-1016-ibm 6.8.0-1016.16
linux-image-6.8.0-1016-oracle 6.8.0-1016.17
linux-image-6.8.0-1016-oracle-64k 6.8.0-1016.17
linux-image-6.8.0-1017-oem 6.8.0-1017.17
linux-image-6.8.0-1018-gcp 6.8.0-1018.20
linux-image-6.8.0-1018-nvidia 6.8.0-1018.20
linux-image-6.8.0-1018-nvidia-64k 6.8.0-1018.20
linux-image-6.8.0-1018-nvidia-lowlatency 6.8.0-1018.20.1
linux-image-6.8.0-1018-nvidia-lowlatency-64k 6.8.0-1018.20.1
linux-image-6.8.0-1019-aws 6.8.0-1019.21
linux-image-6.8.0-49-generic 6.8.0-49.49
linux-image-6.8.0-49-generic-64k 6.8.0-49.49
linux-image-aws 6.8.0-1019.21
linux-image-gcp 6.8.0-1018.20
linux-image-generic 6.8.0-49.49
linux-image-generic-64k 6.8.0-49.49
linux-image-generic-64k-hwe-24.04 6.8.0-49.49
linux-image-generic-hwe-24.04 6.8.0-49.49
linux-image-generic-lpae 6.8.0-49.49
linux-image-gke 6.8.0-1014.18
linux-image-ibm 6.8.0-1016.16
linux-image-ibm-classic 6.8.0-1016.16
linux-image-ibm-lts-24.04 6.8.0-1016.16
linux-image-kvm 6.8.0-49.49
linux-image-nvidia 6.8.0-1018.20
linux-image-nvidia-64k 6.8.0-1018.20
linux-image-nvidia-lowlatency 6.8.0-1018.20.1
linux-image-nvidia-lowlatency-64k 6.8.0-1018.20.1
linux-image-oem-24.04 6.8.0-1017.17
linux-image-oem-24.04a 6.8.0-1017.17
linux-image-oracle 6.8.0-1016.17
linux-image-oracle-64k 6.8.0-1016.17
linux-image-raspi 6.8.0-1015.17
linux-image-virtual 6.8.0-49.49
linux-image-virtual-hwe-24.04 6.8.0-49.49
Ubuntu 22.04 LTS
linux-image-6.8.0-1018-gcp 6.8.0-1018.20~22.04.1
linux-image-6.8.0-1018-nvidia 6.8.0-1018.20~22.04.1
linux-image-6.8.0-1018-nvidia-64k 6.8.0-1018.20~22.04.1
linux-image-6.8.0-49-generic 6.8.0-49.49~22.04.1
linux-image-6.8.0-49-generic-64k 6.8.0-49.49~22.04.1
linux-image-gcp 6.8.0-1018.20~22.04.1
linux-image-generic-64k-hwe-22.04 6.8.0-49.49~22.04.1
linux-image-generic-hwe-22.04 6.8.0-49.49~22.04.1
linux-image-nvidia-6.8 6.8.0-1018.20~22.04.1
linux-image-nvidia-64k-6.8 6.8.0-1018.20~22.04.1
linux-image-nvidia-64k-hwe-22.04 6.8.0-1018.20~22.04.1
linux-image-nvidia-hwe-22.04 6.8.0-1018.20~22.04.1
linux-image-oem-22.04 6.8.0-49.49~22.04.1
linux-image-oem-22.04a 6.8.0-49.49~22.04.1
linux-image-oem-22.04b 6.8.0-49.49~22.04.1
linux-image-oem-22.04c 6.8.0-49.49~22.04.1
linux-image-oem-22.04d 6.8.0-49.49~22.04.1
linux-image-virtual-hwe-22.04 6.8.0-49.49~22.04.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7120-1
CVE-2024-43882, CVE-2024-46800
Package Information:
https://launchpad.net/ubuntu/+source/linux/6.8.0-49.49
https://launchpad.net/ubuntu/+source/linux-aws/6.8.0-1019.21
https://launchpad.net/ubuntu/+source/linux-gcp/6.8.0-1018.20
https://launchpad.net/ubuntu/+source/linux-gke/6.8.0-1014.18
https://launchpad.net/ubuntu/+source/linux-ibm/6.8.0-1016.16
https://launchpad.net/ubuntu/+source/linux-nvidia/6.8.0-1018.20
https://launchpad.net/ubuntu/+source/linux-nvidia-lowlatency/6.8.0-1018.20.1
https://launchpad.net/ubuntu/+source/linux-oem-6.8/6.8.0-1017.17
https://launchpad.net/ubuntu/+source/linux-oracle/6.8.0-1016.17
https://launchpad.net/ubuntu/+source/linux-raspi/6.8.0-1015.17
https://launchpad.net/ubuntu/+source/linux-gcp-6.8/6.8.0-1018.20~22.04.1
https://launchpad.net/ubuntu/+source/linux-hwe-6.8/6.8.0-49.49~22.04.1
https://launchpad.net/ubuntu/+source/linux-nvidia-6.8/6.8.0-1018.20~22.04.1
[USN-7089-7] Linux kernel (Low Latency) vulnerabilities
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmc9KxQFAwAAAAAACgkQZ0GeRcM5nt0i
zwf/ftMyBjdbSY1J2kE4+zKrm2jP0ykn921eDC+2IhH/zM8qmOHd1D0c0bZ7Rv/w6B3248kW44Cf
xYvICyMXRdJ3WZElC0ehYUBe4YRLWFA0GHtxx0B29sVsZm4guh+JKvH6+IBmfM10jb+Rhof7MToC
tOjkhl0/N926fHdllSnl4qfP8gft8pP0hqtc3kAu1waxAKZR0MAw7+yHmGMUFmrPJH+CpApwuVWM
lsVO4wMyjT5sh5tePXnVNLJTqkEKRnbOSm7Z+sQsmyPkLPSXqDckCCOYi5TwEky06AOUt9x++KCk
hWVcStx8Eq6IWdN2wyuSq8ub5jyZymIpxzIAkiFNhA==
=oqID
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7089-7
November 19, 2024
linux-lowlatency, linux-lowlatency-hwe-6.8 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-lowlatency: Linux low latency kernel
- linux-lowlatency-hwe-6.8: Linux low latency kernel
Details:
Chenyuan Yang discovered that the USB Gadget subsystem in the Linux
kernel did not properly check for the device to be enabled before
writing. A local attacker could possibly use this to cause a denial of
service. (CVE-2024-25741)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- MIPS architecture;
- PA-RISC architecture;
- PowerPC architecture;
- RISC-V architecture;
- S390 architecture;
- x86 architecture;
- Cryptographic API;
- Serial ATA and Parallel ATA drivers;
- Null block device driver;
- Bluetooth drivers;
- Cdrom driver;
- Clock framework and drivers;
- Hardware crypto device drivers;
- CXL (Compute Express Link) drivers;
- Cirrus firmware drivers;
- GPIO subsystem;
- GPU drivers;
- I2C subsystem;
- IIO subsystem;
- InfiniBand drivers;
- ISDN/mISDN subsystem;
- LED subsystem;
- Multiple devices driver;
- Media drivers;
- Fastrpc Driver;
- Network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- Near Field Communication (NFC) drivers;
- NVME drivers;
- NVMEM (Non Volatile Memory) drivers;
- PCI subsystem;
- Pin controllers subsystem;
- x86 platform drivers;
- S/390 drivers;
- SCSI drivers;
- Thermal drivers;
- TTY drivers;
- UFS subsystem;
- USB DSL drivers;
- USB core drivers;
- DesignWare USB3 driver;
- USB Gadget drivers;
- USB Serial drivers;
- VFIO drivers;
- VHOST drivers;
- File systems infrastructure;
- BTRFS file system;
- GFS2 file system;
- JFFS2 file system;
- JFS file system;
- Network file systems library;
- Network file system client;
- NILFS2 file system;
- NTFS3 file system;
- SMB network file system;
- Memory management;
- Netfilter;
- Tracing infrastructure;
- io_uring subsystem;
- BPF subsystem;
- Core kernel;
- Bluetooth subsystem;
- CAN network layer;
- Ceph Core library;
- Networking core;
- IPv4 networking;
- IPv6 networking;
- IUCV driver;
- MAC80211 subsystem;
- Network traffic control;
- Sun RPC protocol;
- Wireless networking;
- AMD SoC Alsa drivers;
- SoC Audio for Freescale CPUs drivers;
- MediaTek ASoC drivers;
- SoC audio core drivers;
- SOF drivers;
- Sound sequencer drivers;
(CVE-2024-42104, CVE-2024-42084, CVE-2024-42252, CVE-2024-41096,
CVE-2024-42237, CVE-2024-42140, CVE-2024-42150, CVE-2024-41031,
CVE-2024-41059, CVE-2024-41062, CVE-2024-41051, CVE-2024-41028,
CVE-2024-41090, CVE-2024-41092, CVE-2024-43855, CVE-2024-41021,
CVE-2024-42229, CVE-2024-41056, CVE-2024-41048, CVE-2024-41036,
CVE-2024-42094, CVE-2024-41089, CVE-2024-41068, CVE-2024-41039,
CVE-2024-41095, CVE-2024-41069, CVE-2024-42234, CVE-2024-42136,
CVE-2024-41025, CVE-2024-42157, CVE-2024-42248, CVE-2024-42087,
CVE-2024-41041, CVE-2024-42230, CVE-2024-42151, CVE-2024-42130,
CVE-2024-42244, CVE-2024-41079, CVE-2024-42253, CVE-2024-42092,
CVE-2024-41022, CVE-2024-42137, CVE-2024-42132, CVE-2024-42108,
CVE-2024-42155, CVE-2024-42127, CVE-2024-41060, CVE-2024-42074,
CVE-2024-41081, CVE-2024-42066, CVE-2024-42098, CVE-2024-42082,
CVE-2024-42093, CVE-2024-42245, CVE-2024-41072, CVE-2024-41052,
CVE-2024-42161, CVE-2024-42096, CVE-2024-42115, CVE-2024-41074,
CVE-2024-42120, CVE-2024-41046, CVE-2024-42239, CVE-2024-41063,
CVE-2024-42090, CVE-2024-41023, CVE-2024-42069, CVE-2024-41087,
CVE-2024-42158, CVE-2024-41067, CVE-2024-41084, CVE-2024-41077,
CVE-2024-42240, CVE-2024-42145, CVE-2024-42102, CVE-2024-41020,
CVE-2024-42231, CVE-2024-41053, CVE-2024-42131, CVE-2024-42089,
CVE-2024-41083, CVE-2024-42247, CVE-2024-42105, CVE-2024-41044,
CVE-2024-42128, CVE-2024-42271, CVE-2024-41037, CVE-2024-42114,
CVE-2024-42106, CVE-2024-41076, CVE-2024-42088, CVE-2024-41057,
CVE-2024-41091, CVE-2024-42152, CVE-2024-41070, CVE-2024-41035,
CVE-2024-41050, CVE-2024-39487, CVE-2024-42113, CVE-2024-42250,
CVE-2024-41047, CVE-2024-42149, CVE-2024-42079, CVE-2024-42091,
CVE-2024-42227, CVE-2024-42095, CVE-2024-42109, CVE-2024-41033,
CVE-2023-52888, CVE-2024-41061, CVE-2024-42223, CVE-2024-42235,
CVE-2024-41086, CVE-2024-42133, CVE-2024-41082, CVE-2024-41071,
CVE-2024-41007, CVE-2023-52887, CVE-2024-39486, CVE-2024-41075,
CVE-2024-42101, CVE-2024-42077, CVE-2024-41042, CVE-2024-42225,
CVE-2024-42126, CVE-2024-41094, CVE-2024-41085, CVE-2024-41019,
CVE-2024-41058, CVE-2024-41066, CVE-2024-42156, CVE-2024-42119,
CVE-2024-41032, CVE-2024-41088, CVE-2024-42100, CVE-2024-42142,
CVE-2024-41054, CVE-2024-42103, CVE-2024-42124, CVE-2024-41034,
CVE-2024-42251, CVE-2024-42153, CVE-2024-41045, CVE-2024-42086,
CVE-2024-42243, CVE-2024-41055, CVE-2024-41078, CVE-2024-42117,
CVE-2024-41030, CVE-2024-42068, CVE-2024-42110, CVE-2024-42147,
CVE-2024-42121, CVE-2024-41080, CVE-2024-41027, CVE-2024-43858,
CVE-2024-42085, CVE-2024-42111, CVE-2024-42238, CVE-2024-41018,
CVE-2024-42138, CVE-2024-41038, CVE-2024-42070, CVE-2024-42141,
CVE-2024-41098, CVE-2024-42118, CVE-2024-41073, CVE-2024-42144,
CVE-2024-42280, CVE-2024-41049, CVE-2024-42076, CVE-2024-41065,
CVE-2024-42063, CVE-2024-41064, CVE-2024-41017, CVE-2024-42112,
CVE-2024-42064, CVE-2024-42135, CVE-2024-42146, CVE-2024-41010,
CVE-2024-41097, CVE-2024-41012, CVE-2024-42097, CVE-2024-42067,
CVE-2024-42236, CVE-2024-42080, CVE-2024-42241, CVE-2024-42065,
CVE-2024-42232, CVE-2024-42246, CVE-2024-41093, CVE-2024-41015,
CVE-2024-42129, CVE-2024-42073, CVE-2024-41029)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.04 LTS
linux-image-6.8.0-48-lowlatency 6.8.0-48.48.3
linux-image-6.8.0-48-lowlatency-64k 6.8.0-48.48.3
linux-image-lowlatency 6.8.0-48.48.3
linux-image-lowlatency-64k 6.8.0-48.48.3
linux-image-lowlatency-64k-hwe-24.04 6.8.0-48.48.3
linux-image-lowlatency-hwe-24.04 6.8.0-48.48.3
Ubuntu 22.04 LTS
linux-image-6.8.0-48-lowlatency 6.8.0-48.48.3~22.04.1
linux-image-6.8.0-48-lowlatency-64k 6.8.0-48.48.3~22.04.1
linux-image-lowlatency-64k-hwe-22.04 6.8.0-48.48.3~22.04.1
linux-image-lowlatency-hwe-22.04 6.8.0-48.48.3~22.04.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7089-7
https://ubuntu.com/security/notices/USN-7089-6
https://ubuntu.com/security/notices/USN-7089-5
https://ubuntu.com/security/notices/USN-7089-4
https://ubuntu.com/security/notices/USN-7089-3
https://ubuntu.com/security/notices/USN-7089-2
https://ubuntu.com/security/notices/USN-7089-1
CVE-2023-52887, CVE-2023-52888, CVE-2024-25741, CVE-2024-39486,
CVE-2024-39487, CVE-2024-41007, CVE-2024-41010, CVE-2024-41012,
CVE-2024-41015, CVE-2024-41017, CVE-2024-41018, CVE-2024-41019,
CVE-2024-41020, CVE-2024-41021, CVE-2024-41022, CVE-2024-41023,
CVE-2024-41025, CVE-2024-41027, CVE-2024-41028, CVE-2024-41029,
CVE-2024-41030, CVE-2024-41031, CVE-2024-41032, CVE-2024-41033,
CVE-2024-41034, CVE-2024-41035, CVE-2024-41036, CVE-2024-41037,
CVE-2024-41038, CVE-2024-41039, CVE-2024-41041, CVE-2024-41042,
CVE-2024-41044, CVE-2024-41045, CVE-2024-41046, CVE-2024-41047,
CVE-2024-41048, CVE-2024-41049, CVE-2024-41050, CVE-2024-41051,
CVE-2024-41052, CVE-2024-41053, CVE-2024-41054, CVE-2024-41055,
CVE-2024-41056, CVE-2024-41057, CVE-2024-41058, CVE-2024-41059,
CVE-2024-41060, CVE-2024-41061, CVE-2024-41062, CVE-2024-41063,
CVE-2024-41064, CVE-2024-41065, CVE-2024-41066, CVE-2024-41067,
CVE-2024-41068, CVE-2024-41069, CVE-2024-41070, CVE-2024-41071,
CVE-2024-41072, CVE-2024-41073, CVE-2024-41074, CVE-2024-41075,
CVE-2024-41076, CVE-2024-41077, CVE-2024-41078, CVE-2024-41079,
CVE-2024-41080, CVE-2024-41081, CVE-2024-41082, CVE-2024-41083,
CVE-2024-41084, CVE-2024-41085, CVE-2024-41086, CVE-2024-41087,
CVE-2024-41088, CVE-2024-41089, CVE-2024-41090, CVE-2024-41091,
CVE-2024-41092, CVE-2024-41093, CVE-2024-41094, CVE-2024-41095,
CVE-2024-41096, CVE-2024-41097, CVE-2024-41098, CVE-2024-42063,
CVE-2024-42064, CVE-2024-42065, CVE-2024-42066, CVE-2024-42067,
CVE-2024-42068, CVE-2024-42069, CVE-2024-42070, CVE-2024-42073,
CVE-2024-42074, CVE-2024-42076, CVE-2024-42077, CVE-2024-42079,
CVE-2024-42080, CVE-2024-42082, CVE-2024-42084, CVE-2024-42085,
CVE-2024-42086, CVE-2024-42087, CVE-2024-42088, CVE-2024-42089,
CVE-2024-42090, CVE-2024-42091, CVE-2024-42092, CVE-2024-42093,
CVE-2024-42094, CVE-2024-42095, CVE-2024-42096, CVE-2024-42097,
CVE-2024-42098, CVE-2024-42100, CVE-2024-42101, CVE-2024-42102,
CVE-2024-42103, CVE-2024-42104, CVE-2024-42105, CVE-2024-42106,
CVE-2024-42108, CVE-2024-42109, CVE-2024-42110, CVE-2024-42111,
CVE-2024-42112, CVE-2024-42113, CVE-2024-42114, CVE-2024-42115,
CVE-2024-42117, CVE-2024-42118, CVE-2024-42119, CVE-2024-42120,
CVE-2024-42121, CVE-2024-42124, CVE-2024-42126, CVE-2024-42127,
CVE-2024-42128, CVE-2024-42129, CVE-2024-42130, CVE-2024-42131,
CVE-2024-42132, CVE-2024-42133, CVE-2024-42135, CVE-2024-42136,
CVE-2024-42137, CVE-2024-42138, CVE-2024-42140, CVE-2024-42141,
CVE-2024-42142, CVE-2024-42144, CVE-2024-42145, CVE-2024-42146,
CVE-2024-42147, CVE-2024-42149, CVE-2024-42150, CVE-2024-42151,
CVE-2024-42152, CVE-2024-42153, CVE-2024-42155, CVE-2024-42156,
CVE-2024-42157, CVE-2024-42158, CVE-2024-42161, CVE-2024-42223,
CVE-2024-42225, CVE-2024-42227, CVE-2024-42229, CVE-2024-42230,
CVE-2024-42231, CVE-2024-42232, CVE-2024-42234, CVE-2024-42235,
CVE-2024-42236, CVE-2024-42237, CVE-2024-42238, CVE-2024-42239,
CVE-2024-42240, CVE-2024-42241, CVE-2024-42243, CVE-2024-42244,
CVE-2024-42245, CVE-2024-42246, CVE-2024-42247, CVE-2024-42248,
CVE-2024-42250, CVE-2024-42251, CVE-2024-42252, CVE-2024-42253,
CVE-2024-42271, CVE-2024-42280, CVE-2024-43855, CVE-2024-43858
Package Information:
https://launchpad.net/ubuntu/+source/linux-lowlatency/6.8.0-48.48.3
https://launchpad.net/ubuntu/+source/linux-lowlatency-hwe-6.8/6.8.0-48.48.3~22.04.1
[USN-7117-1] needrestart and Module::ScanDeps vulnerabilities
wsF5BAABCAAjFiEEcfvxe+flLQwqLJFE8LYUYLBMS1YFAmc89y0FAwAAAAAACgkQ8LYUYLBMS1bg
PRAAgKRqybx7jNPGUrnV/sUqI2jyJtFqONfdbEfARV/hVBA81UQMKTGLmHgJ/Ma/LsMzd5Srsy8N
Ra5njGiOr/DU3kZNPUzk0h+OSoaeqadC021FD1ivBp5XOvydszwKgBVm3vfmfjrll0cL6TJbobC1
vEy8nEp7yxg6b5xxJjMjt6t21Z1fOhyMKO5L6e4K4K95exV948IsRz/Em2fVgNb08NI6jU4OPpKg
KXnDKseo/rvmi6kyAbdIpQKXb+lfCI9lkRPtbzGTxK8cs8Hhlj+QGmNf57Y99He3Krw5bPNoU/sO
jUIP0eQSdlYM4+W07SJeGOKPosSIhGZR+TUoY/I9H7EPMtBWJaH7pwS8yQ0O/hbF3Y12RqU1+TMS
IAFEFg4xz3NBRw1Xcq8+fvSb1obSAHcM7TZp9QOLAgnDMS0WbU8jXWt1pUwuyndr8adjzVXe1nBz
F03elIo0qIyJL/cOKG8KNqIqp1vV+O8/mEg/oScyxixvEfzmBdTtJSeqYBveANEyeY29vP5ip3yw
wBJQ4bKFrtB6ZhRO91kxA0nnu/yj2vuV4+9CulNlp4LoT1RB/RPeDaJjvIe+GHaGxnXgmEL+U1AA
lpVQZO237sC6K1IWicNZyQjwR6kh0Vnw0QhxsAlzOQLG3nJMCO7fIRCPx5rJ/qQ0xZydUb5fU0f3
iBs=
=RONV
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7117-1
November 19, 2024
Several security issues were fixed in needrestart and Module::ScanDeps
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in libmodule-scandeps-perl, needrestart.
Software Description:
- libmodule-scandeps-perl: module to recursively scan Perl code for
dependencies
- needrestart: check which daemons need to be restarted after library
upgrades
Details:
Qualys discovered that needrestart passed unsanitized data to a library
(libmodule-scandeps-perl) which expects safe input. A local attacker could
possibly use this issue to execute arbitrary code as root.
(CVE-2024-11003)
Qualys discovered that the library libmodule-scandeps-perl incorrectly
parsed perl code. This could allow a local attacker to execute arbitrary
shell commands. (CVE-2024-10224)
Qualys discovered that needrestart incorrectly used the PYTHONPATH
environment variable to spawn a new Python interpreter. A local attacker
could possibly use this issue to execute arbitrary code as root.
(CVE-2024-48990)
Qualys discovered that needrestart incorrectly checked the path to the
Python interpreter. A local attacker could possibly use this issue to win
a race condition and execute arbitrary code as root. (CVE-2024-48991)
Qualys discovered that needrestart incorrectly used the RUBYLIB
environment variable to spawn a new Ruby interpreter. A local attacker
could possibly use this issue to execute arbitrary code as root.
(CVE-2024-48992)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
libmodule-scandeps-perl 1.35-1ubuntu0.24.10.1
needrestart 3.6-8ubuntu4.2
Ubuntu 24.04 LTS
libmodule-scandeps-perl 1.35-1ubuntu0.24.04.1
needrestart 3.6-7ubuntu4.3
Ubuntu 22.04 LTS
libmodule-scandeps-perl 1.31-1ubuntu0.1
needrestart 3.5-5ubuntu2.2
Ubuntu 20.04 LTS
libmodule-scandeps-perl 1.27-1ubuntu0.1~esm1
Available with Ubuntu Pro
needrestart 3.4-6ubuntu0.1+esm1
Available with Ubuntu Pro
Ubuntu 18.04 LTS
libmodule-scandeps-perl 1.24-1ubuntu0.1~esm1
Available with Ubuntu Pro
needrestart 3.1-1ubuntu0.1+esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
libmodule-scandeps-perl 1.20-1ubuntu0.1~esm1
Available with Ubuntu Pro
needrestart 2.6-1ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7117-1
CVE-2024-10224, CVE-2024-11003, CVE-2024-48990, CVE-2024-48991,
CVE-2024-48992
Package Information:
https://launchpad.net/ubuntu/+source/libmodule-scandeps-perl/1.35-1ubuntu0.24.10.1
https://launchpad.net/ubuntu/+source/needrestart/3.6-8ubuntu4.2
https://launchpad.net/ubuntu/+source/libmodule-scandeps-perl/1.35-1ubuntu0.24.04.1
https://launchpad.net/ubuntu/+source/needrestart/3.6-7ubuntu4.3
https://launchpad.net/ubuntu/+source/libmodule-scandeps-perl/1.31-1ubuntu0.1
https://launchpad.net/ubuntu/+source/needrestart/3.5-5ubuntu2.2
Orphaned packages looking for new maintainers
The following packages are orphaned and will be retired when they
are orphaned for six weeks, unless someone adopts them. If you know for sure
that the package should be retired, please do so now with a proper reason:
https://fedoraproject.org/wiki/How_to_remove_a_package_at_end_of_life
Note: If you received this mail directly you (co)maintain one of the affected
packages or a package that depends on one. Please adopt the affected package or
retire your depending package to avoid broken dependencies, otherwise your
package will be retired when the affected package gets retired.
Request package ownership via the *Take* button in the left column on
https://src.fedoraproject.org/rpms/<pkgname>
Full report available at:
https://a.gtmx.me/orphans/orphans.txt
grep it for your FAS username and follow the dependency chain.
For human readable dependency chains,
see https://packager-dashboard.fedoraproject.org/
For all orphaned packages,
see https://packager-dashboard.fedoraproject.org/orphan
Package (co)maintainers Status Change
================================================================================
alevt orphan 0 weeks ago
aprsd orphan 0 weeks ago
aterm orphan 2 weeks ago
deepin-editor @deepinde-sig, cheeselee, 0 weeks ago
orphan, zsun
deepin-file-manager @deepinde-sig, cheeselee, 0 weeks ago
orphan, zsun
deepin-terminal @deepinde-sig, cheeselee, 0 weeks ago
felixonmars, orphan, zsun
gimp-lqr-plugin ignatenkobrain, orphan 4 weeks ago
grub-customizer cheese, orphan 1 weeks ago
http-parser duck, mrunge, orphan, patches, 2 weeks ago
sgallagh, vascom
hyprcursor orphan 1 weeks ago
hypridle orphan 1 weeks ago
hyprlock orphan 1 weeks ago
hyprpaper orphan 1 weeks ago
hyprpicker orphan 1 weeks ago
ioc-writer orphan 3 weeks ago
java-dirq orphan 2 weeks ago
libdirq orphan 2 weeks ago
maxima jamatos, orphan 5 weeks ago
memtester orphan 0 weeks ago
mmlib @neuro-sig, orphan 2 weeks ago
mozjs102 orphan 0 weeks ago
perl-Alien-CFITSIO orphan 3 weeks ago
perl-Authen-Credential orphan 2 weeks ago
perl-Config-Generator orphan 2 weeks ago
perl-Config-Validator orphan 2 weeks ago
perl-Directory-Queue orphan 2 weeks ago
perl-Messaging-Message orphan 2 weeks ago
perl-Net-STOMP-Client orphan 2 weeks ago
perl-No-Worries orphan 2 weeks ago
perl-String-Similarity orphan 2 weeks ago
php-doctrine-common orphan, remi 0 weeks ago
php-doctrine-persistence orphan 0 weeks ago
prelude-lml orphan 3 weeks ago
prelude-manager orphan 3 weeks ago
prewikka orphan 3 weeks ago
python-astor orphan 2 weeks ago
python-auth-credential orphan 2 weeks ago
python-dirq orphan 2 weeks ago
python-genty @python-packagers-sig, orphan 4 weeks ago
python-http-server-mock mhayden, orphan, pwouters, 1 weeks ago
rominf
python-messaging orphan 2 weeks ago
python-opentelemetry mhayden, orphan, pwouters, 1 weeks ago
rominf
python-opentelemetry-contrib mhayden, orphan, pwouters, 1 weeks ago
rominf
python-opentelemetry- mhayden, orphan, pwouters, 1 weeks ago
propagator-aws-xray rominf
python-opentelemetry-resource- mhayden, orphan, pwouters, 1 weeks ago
detector-azure rominf
python-opentelemetry-sdk- mhayden, orphan, pwouters, 1 weeks ago
extension-aws rominf
python-psycogreen orphan 3 weeks ago
python-pytz-deprecation-shim orphan 5 weeks ago
python-simplegeneric @python-packagers-sig, 4 weeks ago
ignatenkobrain, jcaratzas,
orphan, tomspur
python-simplevisor orphan 2 weeks ago
python-singledispatch @python-packagers-sig, 3 weeks ago
jcaratzas, orphan
python-sshpubkeys orphan 5 weeks ago
python-torchtext orphan 1 weeks ago
qodem orphan 3 weeks ago
rubygem-acts_as_list jaruga, orphan 3 weeks ago
rubygem-awesome_print orphan 3 weeks ago
rubygem-clockwork orphan 5 weeks ago
rubygem-factory_bot orphan 3 weeks ago
rubygem-goocanvas1 orphan 5 weeks ago
rubygem-hashr orphan 5 weeks ago
rubygem-http-accept orphan 5 weeks ago
rubygem-middleware orphan 5 weeks ago
rubygem-mimemagic orphan 3 weeks ago
rubygem-nesty orphan 5 weeks ago
rubygem-pundit orphan 5 weeks ago
rubygem-rainbow orphan 5 weeks ago
rubygem-sd_notify orphan 5 weeks ago
rust-eza @rust-sig, orphan 2 weeks ago
stompclt orphan 2 weeks ago
xastir orphan 0 weeks ago
xdemorse orphan 0 weeks ago
xonsh @python-packagers-sig, orphan 4 weeks ago
xpsk31 orphan 0 weeks ago
The following packages require above mentioned packages:
Depending on: deepin-terminal (1), status change: 2024-11-18 (0 weeks ago)
deepin-file-manager (maintained by: @deepinde-sig, cheeselee, orphan, zsun)
deepin-file-manager-6.0.56-3.fc42.x86_64 requires deepin-terminal = 6.0.14-3.fc42
Depending on: http-parser (8), status change: 2024-10-30 (2 weeks ago)
AusweisApp2 (maintained by: belegdol)
AusweisApp2-2.2.2-1.fc42.src requires http-parser-devel = 2.9.4-12.fc41
AusweisApp2-2.2.2-1.fc42.x86_64 requires libhttp_parser.so.2()(64bit)
flamethrower (maintained by: @dns-sig, pemensik)
flamethrower-0.11.0-28.fc41.src requires http-parser-devel = 2.9.4-12.fc41
flamethrower-0.11.0-28.fc41.x86_64 requires libhttp_parser.so.2()(64bit)
jabberd (maintained by: dmaphy)
jabberd-2.6.1-28.fc41.src requires http-parser-devel = 2.9.4-12.fc41
jabberd-2.6.1-28.fc41.x86_64 requires libhttp_parser.so.2()(64bit)
julia (maintained by: nalimilan)
julia-1.11.0-13.rc3.fc42.src requires http-parser-devel = 2.9.4-12.fc41
slurm (maintained by: @epel-packagers-sig, neil, salimma)
slurm-24.05.2-2.fc42.src requires http-parser-devel = 2.9.4-12.fc41
slurm-slurmrestd-24.05.2-2.fc42.x86_64 requires libhttp_parser.so.2()(64bit)
cantor (maintained by: @kde-sig, @r-maint-sig, rdieter, than)
cantor-24.08.3-1.fc42.x86_64 requires libjulia.so.1.11()(64bit), libjulia.so.1.11(JL_LIBJULIA_1.11)(64bit)
vim-syntastic (maintained by: mhjacks)
vim-syntastic-julia-3.10.0-24.fc42.noarch requires julia = 1.11.0-13.rc3.fc42
LabPlot (maintained by: @kde-sig, @scitech_sig, cicku, topazus)
LabPlot-2.11.1-4.fc42.src requires cantor-devel = 24.08.3-1.fc42
LabPlot-2.11.1-4.fc42.x86_64 requires libcantorlibs.so.28()(64bit)
Depending on: hyprcursor (2), status change: 2024-11-10 (1 weeks ago)
hyprland (maintained by: nightishaman)
hyprland-0.45.1-1.fc42.src requires pkgconfig(hyprcursor) = 0.1.10
hyprland-0.45.1-1.fc42.x86_64 requires hyprcursor(x86-64) = 0.1.10-1.fc42, libhyprcursor.so.0()(64bit)
hyprland-devel-0.45.1-1.fc42.x86_64 requires pkgconfig(hyprcursor) = 0.1.10
nwg-dock-hyprland (maintained by: @go-sig, nightishaman)
nwg-dock-hyprland-0.3.3-1.fc42.x86_64 requires hyprland = 0.45.1-1.fc42
Depending on: maxima (1), status change: 2024-10-12 (5 weeks ago)
wxMaxima (maintained by: jamatos, rdieter)
wxMaxima-24.02.1-2.fc41.x86_64 requires maxima = 5.47.0-3.fc41
Depending on: mmlib (1), status change: 2024-11-02 (2 weeks ago)
eegview (maintained by: @neuro-sig, aekoroglu, ankursinha)
eegview-1.1-8.fc41.src requires mmlib-devel = 1.4.2-13.fc41
eegview-1.1-8.fc41.x86_64 requires libmmlib.so.1()(64bit), libmmlib.so.1(MMLIB_1.0)(64bit)
Depending on: mozjs102 (1), status change: 2024-11-14 (0 weeks ago)
erlang-js (maintained by: peter)
erlang-js-1.9.3-9.fc41.src requires mozjs102-devel = 102.15.1-8.fc42
erlang-js-1.9.3-9.fc41.x86_64 requires libmozjs-102.so.0()(64bit), libmozjs-102.so.0(mozjs_102)(64bit)
Depending on: perl-Alien-CFITSIO (1), status change: 2024-10-23 (3 weeks ago)
perl-Astro-FITS-CFITSIO (maintained by: @scitech_sig, orion)
perl-Astro-FITS-CFITSIO-1.18-5.fc41.src requires perl(Alien::CFITSIO) = 4.4.0.1
Depending on: perl-Authen-Credential (1), status change: 2024-10-30 (2 weeks ago)
stompclt (maintained by: orphan)
stompclt-1.8-8.fc41.noarch requires perl(Authen::Credential) = 1.2
Depending on: perl-Config-Validator (2), status change: 2024-10-30 (2 weeks ago)
perl-Config-Generator (maintained by: orphan)
perl-Config-Generator-1.1-9.fc41.noarch requires perl(Config::Validator) = 1.4
perl-Config-Generator-1.1-9.fc41.src requires perl(Config::Validator) = 1.4
stompclt (maintained by: orphan)
stompclt-1.8-8.fc41.noarch requires perl(Config::Validator) = 1.4
Depending on: perl-Directory-Queue (3), status change: 2024-10-30 (2 weeks ago)
perl-Messaging-Message (maintained by: orphan)
perl-Messaging-Message-1.7-9.fc41.src requires perl(Directory::Queue) = 2.2
stompclt (maintained by: orphan)
stompclt-1.8-8.fc41.noarch requires perl(Directory::Queue) = 2.2, perl(Messaging::Message) = 1.7, perl(Messaging::Message::Queue) = 1.7, perl(Net::STOMP::Client) = 2.5
perl-Net-STOMP-Client (maintained by: orphan)
perl-Net-STOMP-Client-2.5-9.fc41.src requires perl(Messaging::Message) = 1.7
Depending on: perl-Messaging-Message (2), status change: 2024-10-30 (2 weeks ago)
perl-Net-STOMP-Client (maintained by: orphan)
perl-Net-STOMP-Client-2.5-9.fc41.src requires perl(Messaging::Message) = 1.7
stompclt (maintained by: orphan)
stompclt-1.8-8.fc41.noarch requires perl(Messaging::Message) = 1.7, perl(Messaging::Message::Queue) = 1.7, perl(Net::STOMP::Client) = 2.5
Depending on: perl-Net-STOMP-Client (1), status change: 2024-10-30 (2 weeks ago)
stompclt (maintained by: orphan)
stompclt-1.8-8.fc41.noarch requires perl(Net::STOMP::Client) = 2.5
Depending on: perl-No-Worries (8), status change: 2024-10-30 (2 weeks ago)
perl-Authen-Credential (maintained by: orphan)
perl-Authen-Credential-1.2-9.fc41.noarch requires perl(No::Worries::Die) = 1.7
perl-Authen-Credential-1.2-9.fc41.src requires perl(No::Worries::Die) = 1.7
perl-Config-Generator (maintained by: orphan)
perl-Config-Generator-1.1-9.fc41.noarch requires perl(Config::Validator) = 1.4, perl(No::Worries) = 1.7, perl(No::Worries::Die) = 1.7, perl(No::Worries::Dir) = 1.7, perl(No::Worries::Export) = 1.7, perl(No::Worries::File) = 1.7, perl(No::Worries::Log) = 1.7, perl(No::Worries::Proc) = 1.7, perl(No::Worries::Stat) = 1.7, perl(No::Worries::String) = 1.7, perl(No::Worries::Warn) = 1.7
perl-Config-Generator-1.1-9.fc41.src requires perl(Config::Validator) = 1.4, perl(No::Worries) = 1.7
perl-Config-Validator (maintained by: orphan)
perl-Config-Validator-1.4-9.fc41.noarch requires perl(No::Worries::Die) = 1.7, perl(No::Worries::Export) = 1.7
perl-Config-Validator-1.4-9.fc41.src requires perl(No::Worries) = 1.7
perl-Directory-Queue (maintained by: orphan)
perl-Directory-Queue-2.2-7.fc41.noarch requires perl(No::Worries) = 1.7, perl(No::Worries::Die) = 1.7, perl(No::Worries::Export) = 1.7, perl(No::Worries::File) = 1.7, perl(No::Worries::Stat) = 1.7, perl(No::Worries::Warn) = 1.7
perl-Directory-Queue-2.2-7.fc41.src requires perl(No::Worries) = 1.7
perl-Messaging-Message (maintained by: orphan)
perl-Messaging-Message-1.7-9.fc41.noarch requires perl(No::Worries::Die) = 1.7, perl(No::Worries::Export) = 1.7
perl-Messaging-Message-1.7-9.fc41.src requires perl(Directory::Queue) = 2.2, perl(No::Worries) = 1.7
perl-Net-STOMP-Client (maintained by: orphan)
perl-Net-STOMP-Client-2.5-9.fc41.noarch requires perl(No::Worries::Die) = 1.7, perl(No::Worries::Export) = 1.7, perl(No::Worries::File) = 1.7, perl(No::Worries::Log) = 1.7
perl-Net-STOMP-Client-2.5-9.fc41.src requires perl(Messaging::Message) = 1.7, perl(No::Worries) = 1.7
python-simplevisor (maintained by: orphan)
python-simplevisor-1.3-12.fc41.src requires perl(No::Worries) = 1.7, perl(No::Worries::Die) = 1.7, perl(No::Worries::Log) = 1.7, perl(No::Worries::PidFile) = 1.7, perl(No::Worries::Proc) = 1.7, perl(No::Worries::Syslog) = 1.7, perl(No::Worries::Warn) = 1.7
python3-simplevisor-1.3-12.fc41.noarch requires perl(No::Worries) = 1.7, perl(No::Worries::Die) = 1.7, perl(No::Worries::Log) = 1.7, perl(No::Worries::PidFile) = 1.7, perl(No::Worries::Proc) = 1.7, perl(No::Worries::Syslog) = 1.7, perl(No::Worries::Warn) = 1.7
stompclt (maintained by: orphan)
stompclt-1.8-8.fc41.noarch requires perl(Authen::Credential) = 1.2, perl(Config::Validator) = 1.4, perl(Directory::Queue) = 2.2, perl(Messaging::Message) = 1.7, perl(Messaging::Message::Queue) = 1.7, perl(Net::STOMP::Client) = 2.5, perl(No::Worries) = 1.7, perl(No::Worries::Die) = 1.7, perl(No::Worries::File) = 1.7, perl(No::Worries::Log) = 1.7, perl(No::Worries::PidFile) = 1.7, perl(No::Worries::Proc) = 1.7, perl(No::Worries::Syslog) = 1.7, perl(No::Worries::Warn) = 1.7
Depending on: perl-String-Similarity (1), status change: 2024-10-30 (2 weeks ago)
publican (maintained by: jfearn, rlandmann)
publican-4.3.2-31.fc42.noarch requires perl(String::Similarity) = 1.04
publican-4.3.2-31.fc42.src requires perl(String::Similarity) = 1.04
Depending on: php-doctrine-persistence (9), status change: 2024-11-18 (0 weeks ago)
php-doctrine-common (maintained by: orphan, remi)
php-doctrine-common-1:2.13.3-13.fc41.noarch requires php-composer(doctrine/annotations) = 1.14.3, php-composer(doctrine/cache) = 1.13.0, php-composer(doctrine/persistence) = 1.3.8
php-doctrine-datafixtures (maintained by: remi, siwinski)
php-doctrine-datafixtures-1.6.5-2.fc39.noarch requires php-composer(doctrine/persistence) = 1.3.8
php-doctrine-datafixtures-1.6.5-2.fc39.src requires php-composer(doctrine/persistence) = 1.3.8, php-symfony4-cache = 4.4.50-8.fc41
php-symfony4 (maintained by: remi, siwinski)
php-symfony4-doctrine-bridge-4.4.50-8.fc41.noarch requires php-composer(doctrine/persistence) = 1.3.8
php-symfony4-framework-bundle-4.4.50-8.fc41.noarch requires php-composer(doctrine/cache) = 1.13.0
php-symfony4-common-4.4.50-8.fc41.noarch requires php-composer(symfony/polyfill-php80) = 1.28.0
php-symfony4-config-4.4.50-8.fc41.noarch requires php-composer(symfony/polyfill-php81) = 1.28.0
php-symfony4-console-4.4.50-8.fc41.noarch requires php-composer(symfony/polyfill-php73) = 1.28.0
php-symfony4-http-client-4.4.50-8.fc41.noarch requires php-composer(symfony/polyfill-php73) = 1.28.0
php-symfony4-http-kernel-4.4.50-8.fc41.noarch requires php-composer(symfony/polyfill-php73) = 1.28.0
php-symfony4-mime-4.4.50-8.fc41.noarch requires php-composer(symfony/polyfill-mbstring) = 1.28.0
php-symfony4-var-dumper-4.4.50-8.fc41.noarch requires php-composer(symfony/polyfill-php72) = 1.28.0
php-symfony4-web-link-4.4.50-8.fc41.noarch requires php-composer(symfony/polyfill-php72) = 1.28.0
php-symfony4-twig-bridge-4.4.50-8.fc41.noarch requires php-composer(twig/twig) = 1.44.7
php-symfony4-twig-bundle-4.4.50-8.fc41.noarch requires php-composer(twig/twig) = 1.44.7
php-symfony4-web-profiler-bundle-4.4.50-8.fc41.noarch requires php-composer(twig/twig) = 1.44.7
php-doctrine-annotations (maintained by: remi, siwinski)
php-doctrine-annotations-1.14.3-2.fc39.src requires php-composer(doctrine/cache) = 1.13.0, php-composer(symfony/cache) = 4.4.50
php-doctrine-cache (maintained by: remi, siwinski)
php-doctrine-cache-1.13.0-4.fc39.src requires php-composer(symfony/cache) = 4.4.50, php-composer(symfony/var-exporter) = 4.4.50
php-doctrine-doctrine-cache-bundle (maintained by: remi, siwinski)
php-doctrine-doctrine-cache-bundle-1.4.0-11.fc41.noarch requires php-composer(doctrine/cache) = 1.13.0, php-composer(symfony/doctrine-bridge) = 4.4.50
php-symfony-polyfill (maintained by: siwinski)
php-symfony-polyfill-1.28.0-1.fc40.src requires php-symfony4-intl = 4.4.50-8.fc41, php-symfony4-var-dumper = 4.4.50-8.fc41
php-twig (maintained by: siwinski)
php-twig-1.44.7-6.fc41.src requires php-composer(symfony/debug) = 4.4.50
php-doctrine-persistence (maintained by: orphan)
php-doctrine-persistence-1.3.8-10.fc41.noarch requires php-composer(doctrine/annotations) = 1.14.3, php-composer(doctrine/cache) = 1.13.0
php-doctrine-persistence-1.3.8-10.fc41.src requires php-composer(doctrine/annotations) = 1.14.3, php-composer(doctrine/cache) = 1.13.0
Depending on: prelude-lml (1), status change: 2024-10-23 (3 weeks ago)
prelude-lml-rules (maintained by: totol)
prelude-lml-rules-5.2.0-9.fc40.x86_64 requires prelude-lml = 5.2.0-21.fc41
Depending on: prewikka (1), status change: 2024-10-23 (3 weeks ago)
prewikka-updatedb (maintained by: totol)
python3-prewikka-updatedb-5.2.0-14.fc41.noarch requires python3-prewikka = 5.2.0-18.fc41
Depending on: python-http-server-mock (4), status change: 2024-11-10 (1 weeks ago)
python-opentelemetry-contrib (maintained by: mhayden, orphan, pwouters, rominf)
python-opentelemetry-contrib-2:1.27.0-2.fc42.src requires python3dist(http-server-mock) = 1.7
python-sentry-sdk (maintained by: edward-evans-aiven, italomga, nickfarrell, orange-kao, pwouters, rominf, rommell)
python-sentry-sdk-2.17.0-3.fc42.src requires python3dist(opentelemetry-distro) = 0.48~b0
python3-sentry-sdk+opentelemetry-2.17.0-3.fc42.noarch requires python3.13dist(opentelemetry-distro) = 0.48~b0
python3-sentry-sdk+opentelemetry-experimental-2.17.0-3.fc42.noarch requires python3.13dist(opentelemetry-distro) = 0.48~b0
matrix-synapse (maintained by: @epel-packagers-sig, dcallagh, jonathanspw, v02460)
matrix-synapse-1.118.0-1.fc42.src requires python3dist(sentry-sdk) = 2.17
matrix-synapse+sentry-1.118.0-1.fc42.x86_64 requires python3.13dist(sentry-sdk) = 2.17
plasma-drkonqi (maintained by: @kde-sig, mkyral)
plasma-drkonqi-6.2.3-1.fc42.i686 requires python3dist(sentry-sdk) = 2.17
plasma-drkonqi-6.2.3-1.fc42.x86_64 requires python3dist(sentry-sdk) = 2.17
Depending on: python-opentelemetry (9), status change: 2024-11-09 (1 weeks ago)
python-elastic-transport (maintained by: aekoroglu)
python-elastic-transport-8.13.1-1.fc41.src requires python3dist(opentelemetry-api) = 1.27, python3dist(opentelemetry-sdk) = 1.27
python-opentelemetry-contrib (maintained by: mhayden, orphan, pwouters, rominf)
python-opentelemetry-contrib-2:1.27.0-2.fc42.src requires python3dist(elasticsearch) = 8.14, python3dist(opentelemetry-api) = 1.27, python3dist(opentelemetry-propagator-aws-xray) = 1.0.2, python3dist(opentelemetry-sdk) = 1.27, python3dist(opentelemetry-semantic-conventions) = 0.48~b0, python3dist(opentelemetry-test-utils) = 0.48~b0
python3-opentelemetry-distro-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-sdk) = 1.27
python3-opentelemetry-distro+otlp-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-exporter-otlp) = 1.27
python3-opentelemetry-exporter-richconsole-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-sdk) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27
python3-opentelemetry-instrumentation-aiohttp-client-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-aiohttp-server-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-aiopg-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27
python3-opentelemetry-instrumentation-asgi-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-asyncio-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-asyncpg-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-aws-lambda-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-propagator-aws-xray) = 1.0.2, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-boto-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-boto3sqs-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-botocore-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-propagator-aws-xray) = 1.0.2, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-celery-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-dbapi-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-django-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-elasticsearch-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-fastapi-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-flask-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-httpx-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-jinja2-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27
python3-opentelemetry-instrumentation-kafka-python-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-logging-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27
python3-opentelemetry-instrumentation-mysql-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27
python3-opentelemetry-instrumentation-mysqlclient-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27
python3-opentelemetry-instrumentation-pika-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27
python3-opentelemetry-instrumentation-psycopg-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27
python3-opentelemetry-instrumentation-psycopg2-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27
python3-opentelemetry-instrumentation-pymemcache-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-pymongo-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-pymysql-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27
python3-opentelemetry-instrumentation-pyramid-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-redis-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-requests-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-sqlalchemy-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-sqlite3-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27
python3-opentelemetry-instrumentation-system-metrics-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27
python3-opentelemetry-instrumentation-threading-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27
python3-opentelemetry-instrumentation-tornado-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-urllib-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-urllib3-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-instrumentation-wsgi-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-semantic-conventions) = 0.48~b0
python3-opentelemetry-processor-baggage-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-sdk) = 1.27
python3-opentelemetry-propagator-ot-trace-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-api) = 1.27, python3.13dist(opentelemetry-sdk) = 1.27
python3-opentelemetry-instrumentation-elasticsearch+instruments-2:0.48~b0-2.fc42.noarch requires python3.13dist(elasticsearch) = 8.14
python-opentelemetry-propagator-aws-xray (maintained by: mhayden, orphan, pwouters, rominf)
python-opentelemetry-propagator-aws-xray-1.0.2-1.fc41.src requires python3dist(opentelemetry-api) = 1.27, python3dist(opentelemetry-sdk) = 1.27
python3-opentelemetry-propagator-aws-xray-1.0.2-1.fc41.noarch requires python3.13dist(opentelemetry-api) = 1.27
python-opentelemetry-resource-detector-azure (maintained by: mhayden, orphan, pwouters, rominf)
python-opentelemetry-resource-detector-azure-0.1.5-4.fc41.src requires python3dist(opentelemetry-sdk) = 1.27
python3-opentelemetry-resource-detector-azure-0.1.5-4.fc41.noarch requires python3.13dist(opentelemetry-sdk) = 1.27
python-opentelemetry-sdk-extension-aws (maintained by: mhayden, orphan, pwouters, rominf)
python-opentelemetry-sdk-extension-aws-2.0.2-1.fc41.src requires python3dist(opentelemetry-sdk) = 1.27
python3-opentelemetry-sdk-extension-aws-2.0.2-1.fc41.noarch requires python3.13dist(opentelemetry-sdk) = 1.27
python-elasticsearch (maintained by: aekoroglu, stevetraylen)
python-elasticsearch-8.14.0-2.fc41.src requires python3dist(elastic-transport) = 8.13.1
python3-elasticsearch-8.14.0-2.fc41.noarch requires python3.13dist(elastic-transport) = 8.13.1
python-sentry-sdk (maintained by: edward-evans-aiven, italomga, nickfarrell, orange-kao, pwouters, rominf, rommell)
python-sentry-sdk-2.17.0-3.fc42.src requires python3dist(opentelemetry-distro) = 0.48~b0
python3-sentry-sdk+opentelemetry-2.17.0-3.fc42.noarch requires python3.13dist(opentelemetry-distro) = 0.48~b0
python3-sentry-sdk+opentelemetry-experimental-2.17.0-3.fc42.noarch requires python3.13dist(opentelemetry-distro) = 0.48~b0
matrix-synapse (maintained by: @epel-packagers-sig, dcallagh, jonathanspw, v02460)
matrix-synapse-1.118.0-1.fc42.src requires python3dist(sentry-sdk) = 2.17
matrix-synapse+sentry-1.118.0-1.fc42.x86_64 requires python3.13dist(sentry-sdk) = 2.17
plasma-drkonqi (maintained by: @kde-sig, mkyral)
plasma-drkonqi-6.2.3-1.fc42.i686 requires python3dist(sentry-sdk) = 2.17
plasma-drkonqi-6.2.3-1.fc42.x86_64 requires python3dist(sentry-sdk) = 2.17
Depending on: python-opentelemetry-contrib (3), status change: 2024-11-09 (1 weeks ago)
python-sentry-sdk (maintained by: edward-evans-aiven, italomga, nickfarrell, orange-kao, pwouters, rominf, rommell)
python-sentry-sdk-2.17.0-3.fc42.src requires python3dist(opentelemetry-distro) = 0.48~b0
python3-sentry-sdk+opentelemetry-2.17.0-3.fc42.noarch requires python3.13dist(opentelemetry-distro) = 0.48~b0
python3-sentry-sdk+opentelemetry-experimental-2.17.0-3.fc42.noarch requires python3.13dist(opentelemetry-distro) = 0.48~b0
matrix-synapse (maintained by: @epel-packagers-sig, dcallagh, jonathanspw, v02460)
matrix-synapse-1.118.0-1.fc42.src requires python3dist(sentry-sdk) = 2.17
matrix-synapse+sentry-1.118.0-1.fc42.x86_64 requires python3.13dist(sentry-sdk) = 2.17
plasma-drkonqi (maintained by: @kde-sig, mkyral)
plasma-drkonqi-6.2.3-1.fc42.i686 requires python3dist(sentry-sdk) = 2.17
plasma-drkonqi-6.2.3-1.fc42.x86_64 requires python3dist(sentry-sdk) = 2.17
Depending on: python-opentelemetry-propagator-aws-xray (4), status change: 2024-11-09 (1 weeks ago)
python-opentelemetry-contrib (maintained by: mhayden, orphan, pwouters, rominf)
python-opentelemetry-contrib-2:1.27.0-2.fc42.src requires python3dist(opentelemetry-propagator-aws-xray) = 1.0.2
python3-opentelemetry-instrumentation-aws-lambda-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-propagator-aws-xray) = 1.0.2
python3-opentelemetry-instrumentation-botocore-2:0.48~b0-2.fc42.noarch requires python3.13dist(opentelemetry-propagator-aws-xray) = 1.0.2
python-sentry-sdk (maintained by: edward-evans-aiven, italomga, nickfarrell, orange-kao, pwouters, rominf, rommell)
python-sentry-sdk-2.17.0-3.fc42.src requires python3dist(opentelemetry-distro) = 0.48~b0
python3-sentry-sdk+opentelemetry-2.17.0-3.fc42.noarch requires python3.13dist(opentelemetry-distro) = 0.48~b0
python3-sentry-sdk+opentelemetry-experimental-2.17.0-3.fc42.noarch requires python3.13dist(opentelemetry-distro) = 0.48~b0
matrix-synapse (maintained by: @epel-packagers-sig, dcallagh, jonathanspw, v02460)
matrix-synapse-1.118.0-1.fc42.src requires python3dist(sentry-sdk) = 2.17
matrix-synapse+sentry-1.118.0-1.fc42.x86_64 requires python3.13dist(sentry-sdk) = 2.17
plasma-drkonqi (maintained by: @kde-sig, mkyral)
plasma-drkonqi-6.2.3-1.fc42.i686 requires python3dist(sentry-sdk) = 2.17
plasma-drkonqi-6.2.3-1.fc42.x86_64 requires python3dist(sentry-sdk) = 2.17
Affected (co)maintainers
@deepinde-sig: deepin-editor, deepin-terminal, deepin-file-manager
@dns-sig: http-parser
@epel-packagers-sig: python-opentelemetry-contrib, python-opentelemetry-propagator-aws-xray, python-http-server-mock, python-opentelemetry, http-parser
@go-sig: hyprcursor
@kde-sig: python-opentelemetry-contrib, python-opentelemetry-propagator-aws-xray, python-http-server-mock, python-opentelemetry, http-parser
@neuro-sig: mmlib
@python-packagers-sig: python-genty, xonsh, python-singledispatch, python-simplegeneric
@r-maint-sig: http-parser
@rust-sig: rust-eza
@scitech_sig: perl-Alien-CFITSIO, http-parser
aekoroglu: python-opentelemetry, mmlib
ankursinha: mmlib
belegdol: http-parser
cheese: grub-customizer
cheeselee: deepin-editor, deepin-terminal, deepin-file-manager
cicku: http-parser
dcallagh: python-opentelemetry, python-opentelemetry-propagator-aws-xray, python-http-server-mock, python-opentelemetry-contrib
dmaphy: http-parser
duck: http-parser
edward-evans-aiven: python-opentelemetry, python-opentelemetry-propagator-aws-xray, python-http-server-mock, python-opentelemetry-contrib
felixonmars: deepin-terminal
ignatenkobrain: gimp-lqr-plugin, python-simplegeneric
italomga: python-opentelemetry, python-opentelemetry-propagator-aws-xray, python-http-server-mock, python-opentelemetry-contrib
jamatos: maxima
jaruga: rubygem-acts_as_list
jcaratzas: python-singledispatch, python-simplegeneric
jfearn: perl-String-Similarity
jonathanspw: python-opentelemetry, python-opentelemetry-propagator-aws-xray, python-http-server-mock, python-opentelemetry-contrib
mhayden: python-opentelemetry-resource-detector-azure, python-opentelemetry-sdk-extension-aws, python-opentelemetry-contrib, python-opentelemetry-propagator-aws-xray, python-http-server-mock, python-opentelemetry
mhjacks: http-parser
mkyral: python-opentelemetry, python-opentelemetry-propagator-aws-xray, python-http-server-mock, python-opentelemetry-contrib
mrunge: http-parser
nalimilan: http-parser
neil: http-parser
nickfarrell: python-opentelemetry, python-opentelemetry-propagator-aws-xray, python-http-server-mock, python-opentelemetry-contrib
nightishaman: hyprcursor
orange-kao: python-opentelemetry, python-opentelemetry-propagator-aws-xray, python-http-server-mock, python-opentelemetry-contrib
orion: perl-Alien-CFITSIO
patches: http-parser
pemensik: http-parser
peter: mozjs102
pwouters: python-opentelemetry-resource-detector-azure, python-opentelemetry-sdk-extension-aws, python-opentelemetry-contrib, python-opentelemetry-propagator-aws-xray, python-http-server-mock, python-opentelemetry
rdieter: maxima, http-parser
remi: php-doctrine-persistence, php-doctrine-common
rlandmann: perl-String-Similarity
rominf: python-opentelemetry-resource-detector-azure, python-opentelemetry-sdk-extension-aws, python-opentelemetry-contrib, python-opentelemetry-propagator-aws-xray, python-http-server-mock, python-opentelemetry
rommell: python-opentelemetry, python-opentelemetry-propagator-aws-xray, python-http-server-mock, python-opentelemetry-contrib
salimma: http-parser
sgallagh: http-parser
siwinski: php-doctrine-persistence
stevetraylen: python-opentelemetry
than: http-parser
tomspur: python-simplegeneric
topazus: http-parser
totol: prewikka, prelude-lml
v02460: python-opentelemetry, python-opentelemetry-propagator-aws-xray, python-http-server-mock, python-opentelemetry-contrib
vascom: http-parser
zsun: deepin-editor, deepin-terminal, deepin-file-manager
Orphans (73): alevt aprsd aterm deepin-editor deepin-file-manager
deepin-terminal gimp-lqr-plugin grub-customizer http-parser
hyprcursor hypridle hyprlock hyprpaper hyprpicker ioc-writer
java-dirq libdirq maxima memtester mmlib mozjs102
perl-Alien-CFITSIO perl-Authen-Credential perl-Config-Generator
perl-Config-Validator perl-Directory-Queue perl-Messaging-Message
perl-Net-STOMP-Client perl-No-Worries perl-String-Similarity
php-doctrine-common php-doctrine-persistence prelude-lml
prelude-manager prewikka python-astor python-auth-credential
python-dirq python-genty python-http-server-mock python-messaging
python-opentelemetry python-opentelemetry-contrib
python-opentelemetry-propagator-aws-xray
python-opentelemetry-resource-detector-azure
python-opentelemetry-sdk-extension-aws python-psycogreen
python-pytz-deprecation-shim python-simplegeneric
python-simplevisor python-singledispatch python-sshpubkeys
python-torchtext qodem rubygem-acts_as_list rubygem-awesome_print
rubygem-clockwork rubygem-factory_bot rubygem-goocanvas1
rubygem-hashr rubygem-http-accept rubygem-middleware
rubygem-mimemagic rubygem-nesty rubygem-pundit rubygem-rainbow
rubygem-sd_notify rust-eza stompclt xastir xdemorse xonsh xpsk31
Orphans (dependend on) (21): deepin-terminal http-parser hyprcursor
maxima mmlib mozjs102 perl-Alien-CFITSIO perl-Authen-Credential
perl-Config-Validator perl-Directory-Queue perl-Messaging-Message
perl-Net-STOMP-Client perl-No-Worries perl-String-Similarity
php-doctrine-persistence prelude-lml prewikka
python-http-server-mock python-opentelemetry
python-opentelemetry-contrib
python-opentelemetry-propagator-aws-xray
Orphans (rawhide) for at least 6 weeks (dependend on) (0):
Orphans (rawhide) (not depended on) (52): alevt aprsd aterm
deepin-editor deepin-file-manager gimp-lqr-plugin grub-customizer
hypridle hyprlock hyprpaper hyprpicker ioc-writer java-dirq
libdirq memtester perl-Config-Generator php-doctrine-common
prelude-manager python-astor python-auth-credential python-dirq
python-genty python-messaging
python-opentelemetry-resource-detector-azure
python-opentelemetry-sdk-extension-aws python-psycogreen
python-pytz-deprecation-shim python-simplegeneric
python-simplevisor python-singledispatch python-sshpubkeys
python-torchtext qodem rubygem-acts_as_list rubygem-awesome_print
rubygem-clockwork rubygem-factory_bot rubygem-goocanvas1
rubygem-hashr rubygem-http-accept rubygem-middleware
rubygem-mimemagic rubygem-nesty rubygem-pundit rubygem-rainbow
rubygem-sd_notify rust-eza stompclt xastir xdemorse xonsh xpsk31
Orphans (rawhide) for at least 6 weeks (not dependend on) (0):
Depending packages (rawhide) (44): AusweisApp2 LabPlot cantor
deepin-file-manager eegview erlang-js flamethrower hyprland
jabberd julia matrix-synapse nwg-dock-hyprland
perl-Astro-FITS-CFITSIO perl-Authen-Credential
perl-Config-Generator perl-Config-Validator perl-Directory-Queue
perl-Messaging-Message perl-Net-STOMP-Client
php-doctrine-annotations php-doctrine-cache php-doctrine-common
php-doctrine-datafixtures php-doctrine-doctrine-cache-bundle
php-doctrine-persistence php-symfony-polyfill php-symfony4
php-twig plasma-drkonqi prelude-lml-rules prewikka-updatedb
publican python-elastic-transport python-elasticsearch
python-opentelemetry-contrib
python-opentelemetry-propagator-aws-xray
python-opentelemetry-resource-detector-azure
python-opentelemetry-sdk-extension-aws python-sentry-sdk
python-simplevisor slurm stompclt vim-syntastic wxMaxima
Packages depending on packages orphaned (rawhide) for more than 6
weeks (0):
--
The script creating this output is run and developed by Fedora
Release Engineering. Please report issues at its pagure instance:
https://pagure.io/releng/
The sources of this script can be found at:
https://pagure.io/releng/blob/main/f/scripts/find_unblocked_orphans.py
Report finished at 2024-11-19 18:05:13 UTC
[USN-7115-1] Waitress vulnerabilities
wsF5BAABCAAjFiEELOLXZEFYQHcSWEHiyfW2m9Ldu6sFAmc8wikFAwAAAAAACgkQyfW2m9Ldu6s3
4A//f0QDjUNRx0jrYtT5Vo3qkNotYU9PeshzhAZkS8S04s2Gb+TPl1If1P85FhN1rgTieBUM6o+H
2ytYLQs/jtVKcrCaNTTnq6abLeYTG9AQfMGtRWGRiW1nE9f+9ps05bft+Ydy48b5OzQLxNIXjIz6
FKZkehMrBx+vGksaWWdaFNdkGVSdsNqrVJ2qSFSifDPYIQAsVaXaz0oZ82kC9yM0aR/M2ANe4oVW
R+NlueNMlMZMSjmaXS1mfLtOTn+8ZXUhWXTNxL/LWDwAHXOFdUl+D7pZsKpDs/ch5G80VhhvNJgM
eOtFHJXHi0qbalQNCRmbmzwlz2fktijdkWBOvbUAswncpxk4uyGc7/vagUtz/owsXeAqGWIriJll
jCQzFL/nrJZfCxPtL3moPH+hjBA/llTK3/5d/2OSnfCvfHru5UlX2mn6PCfBXBRSjhyGiSetAxSr
ka8z5fnPz5ef9ioVxfeWh6/EPpSLPVjG9YGo0YtE1tYkOwYakv8wLa39Uo4262aAFvf+Gt4slQc/
2M5Xy+JZBLLtp9C8Z9D/ByxQSVYCEAQkRqCxKuiVwhfNRW04OZWpaNLg1JC2BfyfqcIbUt8DjNrr
bClCY726SeIlhVynig3PlTqQSg1FPG2hTTDJXgpIOAMzbvmiC3h7symAnemx7q5U8wY7FwgKVH4E
wB0=
=hacd
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7115-1
November 19, 2024
Waitress vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in Waitress.
Software Description:
- waitress: production-quality pure-Python WSGI server
Details:
It was discovered that Waitress could process follow up requests when
receiving a specially crafted message. An attacker could use this issue to
have the server process inconsistent client requests. (CVE-2024-49768)
Dylan Jay discovered that Waitress could be lead to write to an unexisting
socket after closing the remote connection. An attacker could use this
issue to increase resource utilization leading to a denial of service.
(CVE-2024-49769)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
python3-waitress 3.0.0-1ubuntu0.1
Ubuntu 24.04 LTS
python3-waitress 2.1.2-2ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 22.04 LTS
python3-waitress 1.4.4-1.1ubuntu1.1
Ubuntu 20.04 LTS
python3-waitress 1.4.1-1ubuntu0.2
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7115-1
CVE-2024-49768, CVE-2024-49769
Package Information:
https://launchpad.net/ubuntu/+source/waitress/3.0.0-1ubuntu0.1
https://launchpad.net/ubuntu/+source/waitress/1.4.4-1.1ubuntu1.1
https://launchpad.net/ubuntu/+source/waitress/1.4.1-1ubuntu0.2
The Debian Project mourns the loss of Jérémy Bobbio (Lunar)
The Debian Project https://www.debian.org/
The Debian Project mourns the loss of Jérémy Bobbio (Lunar)
press@debian.org
November 19th, 2024 https://www.debian.org/News/2024/20241119
------------------------------------------------------------------------
The Debian Project sadly shares the news of the passing of Jérémy Bobbio
(Lunar) on Friday, November 8, 2024.
Lunar was well recognized and respected in several areas of the Linux
and Free/Libre Open Source Software (FLOSS) communities; he was equally
well known as a staunch proponent of individual and collective freedoms.
Lunar was dedicated to and always present in the formulation and
discussion of Reproducible Builds [1]. For many people their
introduction to this system of checks and balances in software came
directly from his mouth at numerous conferences, talks, and mailing
lists.
1: https://reproducible-builds.org/
Lunar was also a valiant proponent of and an outspoken ambassador over
concerns of surveillance and censorship and privacy protection,
prompting him to work in and develop relationships and software inside
of the Tor Project [2]. Lunar was instrumental in helping the network
develop tools, establish relays, and address legal concerns for
operators and administrators.
2: https://torproject.org/
Lunar's passing leaves a hole in many communities. We will carry on, we
will all continue to expand in the areas that were important to him, and
we will continue that work in his legacy. Lunar you will be missed!
Tributes and remembrances were expressed around the world at the news of
Lunar's passing; here we share some of those reflections:
"His work on Reproducible Builds, alongside some other folks on this
list, was transformational for Debian and, dare I say, ahead of its time
for an industry that is slowly discovering the immense threat that
supply chain attacks present (most recently with XZ)."
— Faidon Liambotis
"I always watched and paid attention to his level of detail on what
others would have considered trivial, but through understanding and
explanation from him those minor details transformed into a critical
understanding. A true mentor."
— Donald Norwood
"Lunar was an incredible person, and I miss them deeply, despite getting
to see them only every now and then. Creative, thoughtful, smart, and
kind but not indiscriminately so. Prickly when prickliness was called
for, but also willing to extend a hand or grace as needed. I'll miss
their sharp wit, incisive observations, and provocations to be a better
person.
The people who work on free software and adjacent projects form a better
community for having had Lunar among us. I continue to try to live up to
the standards Lunar set."
— dkg
"I basically remember one of the last conversations I had with Lunar, a
few months ago, when he told me how proud he was not only of having
started Nos Oignons and contributed to the ignition of Reproducible
Builds, but specifically about the fact that both initiatives were now
thriving without being dependent on him. He was likely thinking about a
future world without him, but also realizing how impactful his activism
had been on the past and present world."
— Stefano Zacchiroli
"I remember quite some moments but funnily the moment I most often think
about is meeting him on campus in Portland at DebConf14 when he just
came back from buying a big box of vegan donuts to share. He was so
happy about that! On a more serious note I do think his impact on Tor,
Debian & Reproducible Builds can hardly be overestimated and then
there's a wide area of "offline stuff" he also deeply cared about, and
yet he always stayed humble and helpful. I'm incredible thankful for all
his work and having been able to share some work and good times
together."
— Holger Levsen
About Debian
------------
The Debian Project is an association of Free Software developers who
volunteer their time and effort in order to produce a completely free
operating system known as Debian.
Contact Information
-------------------
For further information, please visit the Debian web pages at
https://www.debian.org/ or send mail to <press@debian.org>.
[USN-7116-1] Python vulnerability
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmc8qesACgkQZWnYVadE
vpPlfw/9E+1fNs14AUmjqQt/7DXA5tCMjlrj67ESlhvQwJ+J9ntg1FDCcSR+93ck
sDMTDM3A43uLz0g8GceOx0tRE7lvDHORKcOXo/eCYsTpAZuHOZtwqZR26maL6/+N
6qE4T0EXEF6FtYYZRLnXg4TTQHOJaCdSbf9rBuhI/1cR19v8X8vhcD2mRG4/Ei34
vguoWlSPrgrP2O+9vJQw3k80izuD8znpMQ1b9NnT3vTET3YtB4m17/wvRMx86d5N
8qUzNcBYw6u5gpp3lMdVK2Zg7FnLi063dpFW5uwSgkFem5spaQZNOdTbrCUtrKto
YZFTycONizOF0F90h3Vt7OzBP+YejWVUG7tNu8gMsaK+vAndq0Y++J6AnJupE6QW
6DzgDup9fMJ+H5S5yMrIZXE92s8hFP0jOFaasEHHIlHtP7uRJ5tgKFbccOOOMo+k
DgoV17UqZY0z96b8A54NH1jH3T3JWZQGmelLpY8gtRhKUiMfuNZxtNZTZ/QoG9wH
582NUTkq/s6B6alTrz63vuF4XpDeiOsNPEWbCFYesexIpP4QGgRQEKlh2m6csksC
VuhEnr5kFltANi7mt4pibj2l17MrJ6t5VRQv0NMM+LiUU0vCSRBzpxMnc4qLs54z
xPQl7CbsbPFtQKnkMWhJGIG0KieST592dj5pKCFT5sVS6x2wWO4=
=pNvo
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7116-1
November 19, 2024
python3.10, python3.12, python3.8 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Python could be made to run programs when activating virtual environments.
Software Description:
- python3.12: An interactive high-level object-oriented language
- python3.10: An interactive high-level object-oriented language
- python3.8: An interactive high-level object-oriented language
Details:
It was discovered that Python incorrectly handled quoting path names when
using the venv module. A local attacker able to control virtual
environments could possibly use this issue to execute arbitrary code when
the virtual environment is activated.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
python3.12 3.12.7-1ubuntu1
python3.12-minimal 3.12.7-1ubuntu1
Ubuntu 24.04 LTS
python3.12 3.12.3-1ubuntu0.3
python3.12-minimal 3.12.3-1ubuntu0.3
Ubuntu 22.04 LTS
python3.10 3.10.12-1~22.04.7
python3.10-minimal 3.10.12-1~22.04.7
Ubuntu 20.04 LTS
python3.8 3.8.10-0ubuntu1~20.04.13
python3.8-minimal 3.8.10-0ubuntu1~20.04.13
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7116-1
CVE-2024-9287
Package Information:
https://launchpad.net/ubuntu/+source/python3.12/3.12.7-1ubuntu1
https://launchpad.net/ubuntu/+source/python3.12/3.12.3-1ubuntu0.3
https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.7
https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.13
[USN-7015-5] Python vulnerabilities
Ubuntu Security Notice USN-7015-5
November 19, 2024
python2.7 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in Python.
Software Description:
- python2.7: An interactive high-level object-oriented language
Details:
USN-7015-1 fixed several vulnerabilities in Python. This update provides
the corresponding update for CVE-2024-6232 and CVE-2024-6923 for python2.7
in Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
and Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered that the Python email module incorrectly quoted newlines
for email headers. A remote attacker could possibly use this issue to
perform header injection. (CVE-2024-6923)
It was discovered that the Python http.cookies module incorrectly handled
parsing cookies that contained backslashes for quoted characters. A remote
attacker could possibly use this issue to cause Python to consume
resources, leading to a denial of service. (CVE-2024-7592)
It was discovered that the Python zipfile module incorrectly handled
certain malformed zip files. A remote attacker could possibly use this
issue to cause Python to stop responding, resulting in a denial of
service. (CVE-2024-8088)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
python2.7 2.7.18-13ubuntu1.3
python2.7-minimal 2.7.18-13ubuntu1.3
Ubuntu 20.04 LTS
python2.7 2.7.18-1~20.04.5
python2.7-minimal 2.7.18-1~20.04.5
Ubuntu 18.04 LTS
python2.7 2.7.17-1~18.04ubuntu1.13+esm7
Available with Ubuntu Pro
python2.7-minimal 2.7.17-1~18.04ubuntu1.13+esm7
Available with Ubuntu Pro
Ubuntu 16.04 LTS
python2.7 2.7.12-1ubuntu0~16.04.18+esm12
Available with Ubuntu Pro
python2.7-minimal 2.7.12-1ubuntu0~16.04.18+esm12
Available with Ubuntu Pro
Ubuntu 14.04 LTS
python2.7 2.7.6-8ubuntu0.6+esm21
Available with Ubuntu Pro
python2.7-minimal 2.7.6-8ubuntu0.6+esm21
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7015-5
https://ubuntu.com/security/notices/USN-7015-4
https://ubuntu.com/security/notices/USN-7015-3
https://ubuntu.com/security/notices/USN-7015-2
https://ubuntu.com/security/notices/USN-7015-1
CVE-2024-6232, CVE-2024-6923
Package Information:
https://launchpad.net/ubuntu/+source/python2.7/2.7.18-13ubuntu1.3
https://launchpad.net/ubuntu/+source/python2.7/2.7.18-1~20.04.5
[arch-announce] Providing a license for package sources
In [RFC 40](https://rfc.archlinux.page/0040-license-package-sources/) we agreed to change all package sources to be licensed under the very liberal [0BSD](https://spdx.org/licenses/0BSD.html) license. **This change will not limit what you can do with package sources**. Check out [the RFC](https://rfc.archlinux.page/0040-license-package-sources/) for more on the rationale and prior discussion.
Before we make this change, we will provide contributors with a way to voice any objections they might have. Starting on 2024-11-19, over the course of a week, contributors will receive a single notification email listing all their contributions.
- If you receive an email and agree to this change, there is no action required from your side.
- If you do not agree, please reply to the email and we'll find a solution together.
If you contributed to Arch Linux packages before but didn't receive an email, please contact us at package-sources-licensing@archlinux.org.
URL: https://archlinux.org/news/providing-a-license-for-package-sources/