ALT-BU-2025-9790-1
Branch sisyphus_loongarch64 update bulletin.
Package junction updated to version 1.9-alt1.1 for branch sisyphus_loongarch64.
Closed bugs
Ошибка запуска программы Junction
Package gpupdate updated to version 0.13.3-alt1 for branch sisyphus_loongarch64.
Closed bugs
samba + gpoa(gpupdate): Стал требовать авторизации, которая ему не нужна
Package python3-module-av updated to version 14.2.0-alt2 for branch sisyphus_loongarch64.
Closed bugs
подозрительные зависимости
Package kubernetes1.32 updated to version 1.32.7-alt1 for branch sisyphus_loongarch64.
Closed vulnerabilities
BDU:2025-03638
Уязвимость языка программирования Go, связанная с неправильной проверкой синтаксической корректности ввода, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2025-05-01
CVE-2025-22868
An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
Package apache2 updated to version 2.4.65-alt1 for branch sisyphus_loongarch64.
Closed vulnerabilities
Modified: 2025-08-14
CVE-2025-54090
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue.
Package samba updated to version 4.21.7-alt3 for branch sisyphus_loongarch64.
Closed bugs
Выполнение net ads keytab create не приводит к созданию keytab-файла на КД
Package anubis updated to version 1.21.3-alt1 for branch sisyphus_loongarch64.
Closed vulnerabilities
Modified: 2025-07-29
CVE-2025-54414
Anubis is a Web AI Firewall Utility that weighs the soul of users' connections using one or more challenges in order to protect upstream resources from scraper bots. In versions 1.21.2 and below, attackers can craft malicious pass-challenge pages that cause a user to execute arbitrary JavaScript code or trigger other nonstandard schemes. An incomplete version of this fix was tagged at 1.21.2 and then the release process was aborted upon final testing. To work around this issue: block any requests to the /.within.website/x/cmd/anubis/api/pass-challenge route with the ?redir= parameter set to anything that doesn't start with the URL scheme http, https, or no scheme (local path redirect). This was fixed in version 1.21.3.