This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-40ee18b2e7 2024-06-02 03:36:56.060441 -------------------------------------------------------------------------------- Name : rust-copydeps Product : Fedora 39 Version : 5.0.1 Release : 8.fc39 URL : Summary : Find and copy all the .so / .dll files needed by an executable Description : Find and copy all the .so / .dll files needed by an executable. -------------------------------------------------------------------------------- Update Information: This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html -------------------------------------------------------------------------------- ChangeLog: * Thu May 23 2024 Fabio Valentini - 5.0.1-8 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces * Fri Jan 26 2024 Fedora Release Engineering - 5.0.1-7 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-40ee18b2e7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ce2936b568 2024-05-26 01:25:15.719720 -------------------------------------------------------------------------------- Name : rust-uu_fmt Product : Fedora 40 Version : 0.0.23 Release : 3.fc40 URL : Summary : fmt ~ (uutils) reformat each paragraph of input Description : fmt ~ (uutils) reformat each paragraph of input. -------------------------------------------------------------------------------- Update Information: This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html -------------------------------------------------------------------------------- ChangeLog: * Thu May 23 2024 Fabio Valentini - 0.0.23-3 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces -------------------------------------------------------------------------------- This update can be installed with the"dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ce2936b568' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ce2936b568 2024-05-26 01:25:15.719720 -------------------------------------------------------------------------------- Name : rust-sarif-fmt Product : Fedora 40 Version : 0.4.2 Release : 3.fc40 URL : Summary : View (pretty print) SARIF files in terminal Description : View (pretty print) SARIF files in terminal. -------------------------------------------------------------------------------- Update Information: This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html -------------------------------------------------------------------------------- ChangeLog: * Thu May 23 2024 Fabio Valentini - 0.4.2-3 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces -------------------------------------------------------------------------------- This update can be installed with the "dnf"update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ce2936b568' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ce2936b568 2024-05-26 01:25:15.719720 -------------------------------------------------------------------------------- Name : rust-pretty-bytes Product : Fedora 40 Version : 0.2.0 Release : 6.fc40 URL : Summary : Convert bytes to a human readable string Description : Convert bytes to a human readable string. -------------------------------------------------------------------------------- Update Information: This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html -------------------------------------------------------------------------------- ChangeLog: * Thu May 23 2024 Fabio Valentini - 0.2.0-6 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces -------------------------------------------------------------------------------- This update can be installed with the "dnf" updateprogram. Use su -c 'dnf upgrade --advisory FEDORA-2024-ce2936b568' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
x86: mishandling of debug exceptions [XSA-260, CVE-2018-8897] x86 vHPET interrupt injection errors [XSA-261] (#1576089) qemu may drive Xen into unbounded loop [XSA-262]. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-98684f429b 2018-05-16 13:44:39.068860 --------------------------------------------------------------------------------Name : xen Product : Fedora 27 Version : 4.9.2 Release : 3.fc27 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor --------------------------------------------------------------------------------Update Information: x86: mishandling of debug exceptions [XSA-260, CVE-2018-8897] x86 vHPET interrupt injection errors [XSA-261] (#1576089) qemu may drive Xen into unbounded loop [XSA-262] --------------------------------------------------------------------------------ChangeLog: * Wed May 9 2018 Michael Young - 4.9.2-3 - x86: mishandling of debug exceptions [XSA-260, CVE-2018-8897] (with extra patch so it applies cleanly) - x86 vHPET interrupt injection errors [XSA-261] (#1576089) - qemu may drive Xen into unbounded loop [XSA-262] * Wed Apr 25 2018 Michael Young - 4.9.2-2 - Information leak via crafted user-supplied CDROM [XSA-258] (#1571867) - x86: PV guest may crash Xen with XPTI [XSA-259] (#1571878) * Wed Apr 4 2018 Michael Young - 4.9.2-1 - update to 4.9.2 adjust xen.use.fedora.ipxe.patch remove patches for issues now fixed upstream * Tue Feb 27 2018 Michael Young - 4.9.1-5 - add Xen page-table isolation (XPTI) mitigation and Branch Target Injection (BTI) mitigation for XSA-254 - DoS via non-preemptable L3/L4 pagetable freeing [XSA-252, CVE-2018-7540] (#1549568) - grant table v2 -> v1 transition may crash Xen [XSA-255, CVE-2018-7541] (#1549570) - x86 PVHguest without LAPIC may DoS the host [XSA-256, CVE-2018-7542] (#1549572) * Tue Dec 12 2017 Michael Young - 4.9.1-4 - another patch related to the [XSA-240, CVE-2017-15595] issue - xen: various flaws (#1525018) x86 PV guests may gain access to internally used page [XSA-248, CVE-2017-17566] broken x86 shadow mode refcount overflow check [XSA-249, CVE-2017-17563] improper x86 shadow mode refcount error handling [XSA-250, CVE-2017-17564] improper bug check in x86 log-dirty handling [XSA-251, CVE-2017-17565] * Sat Dec 2 2017 Richard W.M. Jones - 4.9.1-3 - OCaml 4.06.0 rebuild. * Tue Nov 28 2017 Michael Young - 4.9.1-2 - xen: various flaws (#1518214) x86: infinite loop due to missing PoD error checking [XSA-246, CVE-2017-17044] Missing p2m error checking in PoD code [XSA-247, CVE-2017-17045] * Thu Nov 23 2017 Michael Young - 4.9.1-1 - update to 4.9.1 (#1515818) adjust xen.use.fedora.ipxe.patch and qemu.git-fec5e8c92becad223df9d972770522f64aafdb72.patch remove patches for issues now fixed upstream and parts of xen.gcc7.fix.patch update xen.hypervisor.config - update Source0 location * Wed Nov 15 2017 Michael Young - 4.9.0-14 - fix an issue in patch for [XSA-240, CVE-2017-15595] that might be a security issue - fix for [XSA-243, CVE-2017-15592] could cause hypervisor crash (DOS) * Thu Oct 26 2017 Michael Young - 4.9.0-13 - pin count / page reference race in grant table code [XSA-236, CVE-2017-15597] (#1506693) * Thu Oct 12 2017 Michael Young - 4.9.0-12 - xen: various flaws (#1501391) multiple MSI mapping issues on x86 [XSA-237, CVE-2017-15590] DMOP map/unmap missing argument checks [XSA-238, CVE-2017-15591] hypervisor stack leak in x86 I/O intercept code [XSA-239, CVE-2017-15589] Unlimited recursion in linear pagetable de-typing [XSA-240, CVE-2017-15595] Stale TLB entry due to page type release race [XSA-241, CVE-2017-15588] page type reference leak on x86 [XSA-242, CVE-2017-15593] x86: Incorrect handling of self-linear shadowmappings with translated guests [XSA-243, CVE-2017-15592] x86: Incorrect handling of IST settings during CPU hotplug [XSA-244, CVE-2017-15594] --------------------------------------------------------------------------------References: [ 1 ] Bug #1571880 - CVE-2018-10982 xsa261 xen: x86 vHPET interrupt injection errors (XSA-261) https://bugzilla.redhat.com/show_bug.cgi?id=1571880 [ 2 ] Bug #1571881 - CVE-2018-10981 xsa262 xen: qemu may drive Xen into unbounded loop (XSA-262) https://bugzilla.redhat.com/show_bug.cgi?id=1571881 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-98684f429b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
updated to 8u45-b14 with hope to fix rhbz#1123870 This update adds debugging information to all the Java code included in the JDK, make it easier to debug the code.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-8251 2015-05-15 09:47:21 -------------------------------------------------------------------------------- Name : java-1.8.0-openjdk Product : Fedora 20 Version : 1.8.0.45 Release : 38.b14.fc20 URL : https://openjdk.org/ Summary : OpenJDK Runtime Environment Description : The OpenJDK runtime environment. -------------------------------------------------------------------------------- Update Information: updated to 8u45-b14 with hope to fix rhbz#1123870 This update adds debugging information to all the Java code included in the JDK, make it easier to debug the code. -------------------------------------------------------------------------------- ChangeLog: * Wed May 13 2015 Jiri Vanek - 1:1.8.0.45-35.b14 - updated to 8u45-b14 with hope to fix rhbz#1123870 * Thu Apr 16 2015 Omair Majid - 1:1.8.0.45-32.b13 - Build all java code with -g - Test at build-time to ensure debugging information is included - Resolves: rhbz#1150932 * Fri Apr 10 2015 Jiri Vanek - 1:1.8.0.45-31.b13 - repacked sources - added Patch204: zero-interpreter-fix.patch * Tue Apr 7 2015 Jiri Vanek - 1:1.8.0.45-30.b13 - updated to security u45 - deleted hotspot-build-j-directive.patch - adapted generate_source_tarball.sh, removeSunEcProvider-RH1154143.patch, repackReproduciblePolycies.sh * Thu Feb 12 2015 Jiri Vanek - 1:1.8.0.25-4.b12 - policies repacked to stop spamming yum update - added and used source20 repackReproduciblePolycies.sh - added mehanism to force priority size * Mon Jan 12 2015 Severin Gehwolf - 1:1.8.0.31-1.b13 - Update to January CPU patch update. * Fri Nov 7 2014 Jiri Vanek - 1:1.8.0.25-4.b12 - updated arm64 tarball to jdk8-jdk8u40-b12-aarch64-1263.tar.xz * Mon Nov 3 2014 Jiri Vanek -1:1.8.0.25-3.b12 - updated aarch64 tarball to u40b12 * Fri Oct 24 2014 Jiri Vanek - 1:1.8.0.25-2.b18 - added patch12,removeSunEcProvider-RH1154143 - Add check for src.zip completeness. See RH1130490 (by
#136455 workaround to prevent gdb from failing and getting stuck when hitting certain DWARF-2 symbols.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-427 2004-11-12 --------------------------------------------------------------------- Product : Fedora Core 3 Name : gdb Version : 6.1post Release : 1.20040607.43 Summary : A GNU source-level debugger for C, C++ and other languages. Description : GDB, the GNU debugger, allows you to debug programs written in C, C++, and other languages, by executing them in a controlled fashion and printing their data. --------------------------------------------------------------------- #136455 workaround to prevent gdb from failing and getting stuck when hitting certain DWARF-2 symbols. --------------------------------------------------------------------- * Tue Oct 26 2004 Andrew Cagney 1.200400607.43 - Hack around broken PT_FPSCR defined in headers. - Import latest s390 fixes. - Disable sigstep.exp - s390 has problems. - Use PC's symtab when looking for a symbol. - Work around DW_OP_piece. * Fri Oct 22 2004 Andrew Cagney 1.200400607.42 - For 64-bit PPC, convert _dl_debug_state descriptor into a code address. - Fix --ignore option. --------------------------------------------------------------------- This update can be downloaded from: f2378ff5d82d43098fc741f5b4efe4a2 SRPMS/gdb-6.1post-1.20040607.43.src.rpm 5d9d8ecab4c0b70bd308d3ceb30c8026 x86_64/gdb-6.1post-1.20040607.43.x86_64.rpm 8b02a26c1fb8e85ad43e77735eade9e7 x86_64/debug/gdb-debuginfo-6.1post-1.20040607.43.x86_64.rpm 094cb2c74acc9b8b9be0b361dd79abeb i386/gdb-6.1post-1.20040607.43.i386.rpm 49c48b93df53d8f67589d988e925f27e i386/debug/gdb-debuginfo-6.1post-1.20040607.43.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- -- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.