ALT-BU-2025-11035-1
Branch sisyphus_riscv64 update bulletin.
Package systray-x updated to version 0.9.11-alt5 for branch sisyphus_riscv64.
Closed bugs
systray-x несовместимо с thunderbird
Package openssh updated to version 9.6p1-alt4 for branch sisyphus_riscv64.
Closed bugs
Настройка OpenSSH доступа по Рутокен MFA
Package pcre2 updated to version 10.46-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2025-09-09
CVE-2025-58050
The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the handling of the (*scs:...) (Scan SubString) verb when combined with (*ACCEPT) in src/pcre2_match.c. This vulnerability may potentially lead to information disclosure if the out-of-bounds data read during the memcmp affects the final match result in a way observable by the attacker. This issue has been resolved in version 10.46.
- https://github.com/PCRE2Project/pcre2/commit/a141712e5967d448c7ce13090ab530c8e3d82254
- https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.46
- https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-c2gv-xgf5-5cc2
- https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-c2gv-xgf5-5cc2
Package openexr updated to version 3.3.5-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2025-08-13
CVE-2025-48071
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.2 through 3.3.0, there is a heap-based buffer overflow during a write operation when decompressing ZIPS-packed deep scan-line EXR files with a maliciously forged chunk header. This is fixed in version 3.3.3.
Package udisks2 updated to version 2.10.90-alt3 for branch sisyphus_riscv64.
Closed bugs
Опции для улучшения безопасности для сменных носителей