Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: bump xz and gzip #182

Merged
merged 1 commit into from
Apr 8, 2022
Merged

Conversation

frezbo
Copy link
Member

@frezbo frezbo commented Apr 8, 2022

Bump xz to 5.2.5 and gzip to 1.12

Fixes CVE-2022-1271, ZDI-CAN-16587

5.2.5 was released on 2020-03-17. A patch to fix a security vulnerability in xzgrep (CVE-2022-1271, ZDI-CAN-16587) was made public on 2022-04-07. It is a severe issue if an attacker can control the filenames that are given on the xzgrep command line.

Ref:

Signed-off-by: Noel Georgi [email protected]

@frezbo frezbo force-pushed the chore/bump-zlib-xz branch 3 times, most recently from b19070f to 05cbd0d Compare April 8, 2022 04:53
@frezbo
Copy link
Member Author

frezbo commented Apr 8, 2022

/m

@frezbo
Copy link
Member Author

frezbo commented Apr 8, 2022

/m

1 similar comment
@smira
Copy link
Member

smira commented Apr 8, 2022

/m

Bump xz to 5.2.5 and gzip to 1.12

Fixes CVE-2022-1271, ZDI-CAN-16587

```text
5.2.5 was released on 2020-03-17. A patch to fix a security vulnerability in xzgrep (CVE-2022-1271, ZDI-CAN-16587) was made public on 2022-04-07. It is a severe issue if an attacker can control the filenames that are given on the xzgrep command line.
```

Ref:
 - https://tukaani.org/xz/
 - https://www.openwall.com/lists/oss-security/2022/04/07/8

Signed-off-by: Noel Georgi <[email protected]>
@frezbo frezbo force-pushed the chore/bump-zlib-xz branch from 05cbd0d to a60a332 Compare April 8, 2022 13:43
@frezbo
Copy link
Member Author

frezbo commented Apr 8, 2022

/m

@talos-bot talos-bot merged commit a60a332 into siderolabs:master Apr 8, 2022
@frezbo frezbo deleted the chore/bump-zlib-xz branch April 8, 2022 13:56
frezbo added a commit to frezbo/pkgs that referenced this pull request Apr 11, 2022
Bump kernel to 5.15.33 stable

Also bump tools (ref: siderolabs/tools#182)

Signed-off-by: Noel Georgi <[email protected]>
frezbo added a commit to frezbo/pkgs that referenced this pull request Apr 11, 2022
Bump kernel to 5.15.33 stable

Also bump tools (ref: siderolabs/tools#182)

Signed-off-by: Noel Georgi <[email protected]>
frezbo added a commit to frezbo/pkgs that referenced this pull request Apr 11, 2022
Bump kernel to 5.15.33 stable

Also bump tools (ref: siderolabs/tools#182)

Signed-off-by: Noel Georgi <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants