ALT-BU-2025-11464-1
Branch sisyphus_riscv64 update bulletin.
Package helm updated to version 3.18.6-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2025-08-21
CVE-2025-55198
Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, when parsing Chart.yaml and index.yaml files, an improper validation of type error can lead to a panic. This issue has been resolved in Helm 3.18.5. A workaround involves ensuring YAML files are formatted as Helm expects prior to processing them with Helm.
Modified: 2025-08-21
CVE-2025-55199
Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, it is possible to craft a JSON Schema file in a manner which could cause Helm to use all available memory and have an out of memory (OOM) termination. This issue has been resolved in Helm 3.18.5. A workaround involves ensuring all Helm charts that are being loaded into Helm do not have any reference of $ref pointing to /dev/zero.
Package icon-theme-qogir updated to version 2025.02.15-alt1 for branch sisyphus_riscv64.
Closed bugs
Конфликт версий
Package nginx updated to version 1.28.0-alt1 for branch sisyphus_riscv64.
Closed bugs
Модуль mod_zip к nginx
Package shellinabox updated to version 2.21-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2018-16789
libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down.
- http://packetstormsecurity.com/files/149978/Shell-In-A-Box-2.2.0-Denial-Of-Service.html
- http://seclists.org/fulldisclosure/2018/Oct/50
- https://code.google.com/archive/p/shellinabox/issues
- https://github.com/shellinabox/shellinabox/commit/4f0ecc31ac6f985e0dd3f5a52cbfc0e9251f6361
- http://packetstormsecurity.com/files/149978/Shell-In-A-Box-2.2.0-Denial-Of-Service.html
- http://seclists.org/fulldisclosure/2018/Oct/50
- https://code.google.com/archive/p/shellinabox/issues
- https://github.com/shellinabox/shellinabox/commit/4f0ecc31ac6f985e0dd3f5a52cbfc0e9251f6361
Package liquidctl updated to version 1.15.0-alt0.2 for branch sisyphus_riscv64.
Closed bugs
Нужна зависимость на пакет python3-module-hid-tools, без него не работает
Package pc-test updated to version 2.1.6-alt1 for branch sisyphus_riscv64.
Closed bugs
Процесс определения плана тестирования не отменяется при нажатии на кнопку "Отмена"
Некорректное выполнение проверок при вводе неверного пароля пользователя
Блокируется шаг "Экспресс-тест основных компонентов" на ОС с Wayland
Package kea updated to version 3.0.1-alt1 for branch sisyphus_riscv64.
Closed bugs
kea-*.service: Unknown key 'EnviromentFile' in section
kea: некорректные права на файлы kea-leases.csv
Package hplip updated to version 3.25.6-alt2 for branch sisyphus_riscv64.
Closed bugs
hplip - ошибка установки hp-plugin "plugin.run file does not match its checksum"