ALT-BU-2025-11571-1
Branch sisyphus_riscv64 update bulletin.
Package mtr updated to version 0.96-alt1 for branch sisyphus_riscv64.
Closed bugs
No such file or directory в логах установки mtr
Package podman updated to version 5.6.1-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2025-09-16
CVE-2025-9566
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1
Package curl updated to version 8.16.0-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2025-09-15
CVE-2025-10148
curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy.
Modified: 2025-09-15
CVE-2025-9086
1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with just a slash as path (`path='/'`). Since this site is not secure, the cookie *should* just be ignored. 4. A bug in the path comparison logic makes curl read outside a heap buffer boundary The bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path. The presumed and correct behavior would be to plainly ignore the second set of the cookie since it was already set as secure on a secure host so overriding it on an insecure host should not be okay.
Package hplip updated to version 3.25.6-alt3 for branch sisyphus_riscv64.
Closed bugs
hp-scan: ошибка при сохранении файла после сканирования
Package libgovarnam updated to version 1.9.1-alt2 for branch sisyphus_riscv64.
Closed bugs
govarnam: wrong soname; wrong prefix and libdir in pc-file
Package osinfo-db updated to version 20250910-alt1 for branch sisyphus_riscv64.
Closed bugs
Добавить Альт Рабочая станция 11.0 и Альт Рабочая станция К 11.0
Package calligra updated to version 25.04.3-alt1 for branch sisyphus_riscv64.
Closed bugs
Обновление пакета Calligra