ALT-BU-2023-3117-1
Branch sisyphus update bulletin.
Closed bugs
gpg2 is stuck (spinning) under fakeroot-1.29-alt1 on e2k
Package kernel-image-un-def updated to version 6.2.10-alt1 for branch sisyphus in task 318131.
Closed vulnerabilities
BDU:2023-01801
Уязвимость функции hci_conn_hash_flush() в модуле net/bluetooth/hci_conn.c операционной системы Linux, позволяющая нарушителю повысить свои привилегии
Modified: 2024-11-21
CVE-2023-28464
hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_conn_hash_flush) because of calls to hci_dev_put and hci_conn_put. There is a double free that may lead to privilege escalation.
- https://lore.kernel.org/lkml/20230309074645.74309-1-wzhmmmmm%40gmail.com/
- https://security.netapp.com/advisory/ntap-20230517-0004/
- https://www.openwall.com/lists/oss-security/2023/03/28/2
- https://www.openwall.com/lists/oss-security/2023/03/28/3
- https://lore.kernel.org/lkml/20230309074645.74309-1-wzhmmmmm%40gmail.com/
- https://www.openwall.com/lists/oss-security/2023/03/28/3
- https://www.openwall.com/lists/oss-security/2023/03/28/2
- https://security.netapp.com/advisory/ntap-20230517-0004/
Closed vulnerabilities
Modified: 2025-02-13
CVE-2023-29013
Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer for deploying microservices. There is a vulnerability in Go when parsing the HTTP headers, which impacts Traefik. HTTP header parsing could allocate substantially more memory than required to hold the parsed headers. This behavior could be exploited to cause a denial of service. This issue has been patched in versions 2.9.10 and 2.10.0-rc2.
- https://github.com/traefik/traefik/commit/4ed3964b3586565519249bbdc55eb1b961c08c49
- https://github.com/traefik/traefik/commit/4ed3964b3586565519249bbdc55eb1b961c08c49
- https://github.com/traefik/traefik/releases/tag/v2.10.0-rc2
- https://github.com/traefik/traefik/releases/tag/v2.10.0-rc2
- https://github.com/traefik/traefik/releases/tag/v2.9.10
- https://github.com/traefik/traefik/releases/tag/v2.9.10
- https://github.com/traefik/traefik/security/advisories/GHSA-7hj9-rv74-5g92
- https://github.com/traefik/traefik/security/advisories/GHSA-7hj9-rv74-5g92
- https://security.netapp.com/advisory/ntap-20230517-0008/
- https://security.netapp.com/advisory/ntap-20230517-0008/
Closed bugs
Во время сборки zstd на riscv64 не проходят некоторые тесты по таймау