Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

avahi: add patch for CVE-2021-3468 #195331

Merged
merged 1 commit into from
Oct 10, 2022
Merged

Conversation

yorickvP
Copy link
Contributor

Description of changes

Ubuntu and debian are shipping this: https://ubuntu.com/security/CVE-2021-3468
Redhat is not. The patch has not been accepted upstream. (2022-10-10)

Things done
  • Built on platform(s)
    • x86_64-linux
    • aarch64-linux
    • x86_64-darwin
    • aarch64-darwin
  • For non-Linux: Is sandbox = true set in nix.conf? (See Nix manual)
  • Tested, as applicable:
  • Tested compilation of all packages that depend on this change using nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD". Note: all changes have to be committed, also see nixpkgs-review usage
  • Tested basic functionality of all binary files (usually in ./result/bin/)
  • 22.11 Release Notes (or backporting 22.05 Release notes)
    • (Package updates) Added a release notes entry if the change is major or breaking
    • (Module updates) Added a release notes entry if the change is significant
    • (Module addition) Added a release notes entry if adding a new NixOS module
    • (Release notes changes) Ran nixos/doc/manual/md-to-db.sh to update generated release notes
  • Fits CONTRIBUTING.md.

@github-actions
Copy link
Contributor

Backport failed for staging-22.05, because it was unable to cherry-pick the commit(s).

Please cherry-pick the changes locally.

git fetch origin staging-22.05
git worktree add -d .worktree/backport-195331-to-staging-22.05 origin/staging-22.05
cd .worktree/backport-195331-to-staging-22.05
git checkout -b backport-195331-to-staging-22.05
ancref=$(git merge-base 579766d1fda7fc2a52db4ed822f08bdbf3440cb5 039e1a05f5db32f5e9ff9dfe13501d631b7001bf)
git cherry-pick -x $ancref..039e1a05f5db32f5e9ff9dfe13501d631b7001bf

@yorickvP yorickvP added the 8.has: port to stable A PR already has a backport to the stable release. label Oct 13, 2022
@github-actions
Copy link
Contributor

Backport failed for staging-22.05, because it was unable to cherry-pick the commit(s).

Please cherry-pick the changes locally.

git fetch origin staging-22.05
git worktree add -d .worktree/backport-195331-to-staging-22.05 origin/staging-22.05
cd .worktree/backport-195331-to-staging-22.05
git checkout -b backport-195331-to-staging-22.05
ancref=$(git merge-base 579766d1fda7fc2a52db4ed822f08bdbf3440cb5 039e1a05f5db32f5e9ff9dfe13501d631b7001bf)
git cherry-pick -x $ancref..039e1a05f5db32f5e9ff9dfe13501d631b7001bf

@risicle
Copy link
Contributor

risicle commented Oct 15, 2022

In future please set the patch's name to e.g. CVE-2021-3468.patch. Some vulnerability-scanning tools are able to detect these to avoid spurious warnings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants