https://bugzilla.redhat.com/show_bug.cgi?id=2207628
Bug ID: 2207628
Summary: python-pandas: FTBFS in Fedora Rawhide
Product: Fedora
Version: rawhide
URL: https://koschei.fedoraproject.org/package/python-panda
s
Status: NEW
Component: python-pandas
Assignee: jonathan(a)almalinux.org
Reporter: thrnciar(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
jonathan(a)almalinux.org, mail(a)kushaldas.in,
neuro-sig(a)lists.fedoraproject.org, orion(a)nwra.com,
python-packagers-sig(a)lists.fedoraproject.org,
sergio.pasra(a)gmail.com, tomspur(a)fedoraproject.org,
wfp5p(a)worldbroken.com
Blocks: 2135404 (PYTHON3.12), 2168842 (F39FTBFS,RAWHIDEFTBFS)
Target Milestone: ---
Classification: Fedora
Description of problem:
Package python-pandas fails to build from source in Fedora Rawhide.
Version-Release number of selected component (if applicable):
1.5.3-3.fc39
Steps to Reproduce:
koji build --scratch f39 python-pandas-1.5.3-3.fc39.src.rpm
Additional info:
This package is tracked by Koschei. See:
https://koschei.fedoraproject.org/package/python-pandas
Referenced Bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=2135404
[Bug 2135404] Python 3.12
https://bugzilla.redhat.com/show_bug.cgi?id=2168842
[Bug 2168842] Fedora 39 FTBFS Tracker
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2207628
https://bugzilla.redhat.com/show_bug.cgi?id=2093358
Bug ID: 2093358
Summary: CVE-2021-46790 ntfs-3g: heap-based buffer overflow in
ntfsck
Product: Security Response
Hardware: All
OS: Linux
Status: NEW
Component: vulnerability
Keywords: Security
Severity: medium
Priority: medium
Assignee: security-response-team(a)redhat.com
Reporter: gsuckevi(a)redhat.com
CC: ddepaula(a)redhat.com,
epel-packagers-sig(a)lists.fedoraproject.org,
jferlan(a)redhat.com, kparal(a)redhat.com,
ngompa13(a)gmail.com, rjones(a)redhat.com,
spotrh(a)gmail.com, virt-maint(a)redhat.com
Target Milestone: ---
Classification: Other
ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving
buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated;
however, it is shipped by some Linux distributions.
References:
https://github.com/tuxera/ntfs-3g/issues/16http://www.openwall.com/lists/oss-security/2022/05/26/1
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2093358
https://bugzilla.redhat.com/show_bug.cgi?id=2183971
Bug ID: 2183971
Summary: golang-x-sys-0.6.0 is available
Product: Fedora
Version: rawhide
Status: NEW
Component: golang-x-sys
Keywords: FutureFeature, Triaged
Assignee: zebob.m(a)gmail.com
Reporter: upstream-release-monitoring(a)fedoraproject.org
QA Contact: extras-qa(a)fedoraproject.org
CC: denis(a)fateyev.com,
epel-packagers-sig(a)lists.fedoraproject.org,
go-sig(a)lists.fedoraproject.org,
robinlee.sysu(a)gmail.com, zebob.m(a)gmail.com
Target Milestone: ---
Classification: Fedora
Releases retrieved: 0.1.0, 0.2.0, 0.3.0, 0.4.0, 0.5.0, 0.6.0
Upstream release that is considered latest: 0.6.0
Current version/release in rawhide: 0.5.0-1.fc39
URL: https://golang.org/x/sys
Please consult the package updates policy before you issue an update to a
stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/
More information about the service that created this bug can be found at:
https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_M…
Please keep in mind that with any upstream change, there may also be packaging
changes that need to be made. Specifically, please remember that it is your
responsibility to review the new version to ensure that the licensing is still
correct and that no non-free or legally problematic items have been added
upstream.
Based on the information from Anitya:
https://release-monitoring.org/project/335970/
To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/golang-x-sys
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2183971
https://bugzilla.redhat.com/show_bug.cgi?id=2175600
Bug ID: 2175600
Summary: golang-x-term-0.6.0 is available
Product: Fedora
Version: rawhide
Status: NEW
Component: golang-x-term
Keywords: FutureFeature, Triaged
Assignee: zebob.m(a)gmail.com
Reporter: upstream-release-monitoring(a)fedoraproject.org
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
go-sig(a)lists.fedoraproject.org, zebob.m(a)gmail.com
Target Milestone: ---
Classification: Fedora
Releases retrieved: 0.6.0
Upstream release that is considered latest: 0.6.0
Current version/release in rawhide: 0.5.0-1.fc39
URL: https://github.com/golang/term
Please consult the package updates policy before you issue an update to a
stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/
More information about the service that created this bug can be found at:
https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_M…
Please keep in mind that with any upstream change, there may also be packaging
changes that need to be made. Specifically, please remember that it is your
responsibility to review the new version to ensure that the licensing is still
correct and that no non-free or legally problematic items have been added
upstream.
Based on the information from Anitya:
https://release-monitoring.org/project/328428/
To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/golang-x-term
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2175600
https://bugzilla.redhat.com/show_bug.cgi?id=2093348
Bug ID: 2093348
Summary: CVE-2022-30789 ntfs-3g: crafted NTFS image can cause a
heap-based buffer overflow in
ntfs_check_log_client_array
Product: Security Response
Hardware: All
OS: Linux
Status: NEW
Component: vulnerability
Keywords: Security
Severity: medium
Priority: medium
Assignee: security-response-team(a)redhat.com
Reporter: gsuckevi(a)redhat.com
CC: ddepaula(a)redhat.com,
epel-packagers-sig(a)lists.fedoraproject.org,
jferlan(a)redhat.com, kparal(a)redhat.com,
ngompa13(a)gmail.com, rjones(a)redhat.com,
spotrh(a)gmail.com, virt-maint(a)redhat.com
Target Milestone: ---
Classification: Other
A crafted NTFS image can cause a heap-based buffer overflow in
ntfs_check_log_client_array in NTFS-3G through 2021.8.22.
References:
https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xchm-ph5h-hw4xhttps://github.com/tuxera/ntfs-3g/releases
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2093348
https://bugzilla.redhat.com/show_bug.cgi?id=2093340
Bug ID: 2093340
Summary: CVE-2022-30788 ntfs-3g: crafted NTFS image can cause a
heap-based buffer overflow in ntfs_mft_rec_alloc
Product: Security Response
Hardware: All
OS: Linux
Status: NEW
Component: vulnerability
Keywords: Security
Severity: medium
Priority: medium
Assignee: security-response-team(a)redhat.com
Reporter: gsuckevi(a)redhat.com
CC: ddepaula(a)redhat.com,
epel-packagers-sig(a)lists.fedoraproject.org,
jferlan(a)redhat.com, kparal(a)redhat.com,
ngompa13(a)gmail.com, rjones(a)redhat.com,
spotrh(a)gmail.com, virt-maint(a)redhat.com
Target Milestone: ---
Classification: Other
A crafted NTFS image can cause a heap-based buffer overflow in
ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22.
References:
https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xchm-ph5h-hw4xhttps://github.com/tuxera/ntfs-3g/releases
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2093340
https://bugzilla.redhat.com/show_bug.cgi?id=2093326
Bug ID: 2093326
Summary: CVE-2022-30786 ntfs-3g: crafted NTFS image can cause a
heap-based buffer overflow in ntfs_names_full_collate
Product: Security Response
Hardware: All
OS: Linux
Status: NEW
Component: vulnerability
Keywords: Security
Severity: medium
Priority: medium
Assignee: security-response-team(a)redhat.com
Reporter: gsuckevi(a)redhat.com
CC: ddepaula(a)redhat.com,
epel-packagers-sig(a)lists.fedoraproject.org,
jferlan(a)redhat.com, kparal(a)redhat.com,
ngompa13(a)gmail.com, rjones(a)redhat.com,
spotrh(a)gmail.com, virt-maint(a)redhat.com
Target Milestone: ---
Classification: Other
A crafted NTFS image can cause a heap-based buffer overflow in
ntfs_names_full_collate in NTFS-3G through 2021.8.22.
References:
https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xchm-ph5h-hw4xhttps://github.com/tuxera/ntfs-3g/releases
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2093326
https://bugzilla.redhat.com/show_bug.cgi?id=2159621
Bug ID: 2159621
Summary: Importing xarray.tests.test_dataset fails
Product: Fedora
Version: rawhide
Status: NEW
Component: python-xarray
Assignee: quantum.analyst(a)gmail.com
Reporter: david08741(a)gmail.com
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
jonathan(a)almalinux.org,
python-packagers-sig(a)lists.fedoraproject.org,
quantum.analyst(a)gmail.com
Target Milestone: ---
Classification: Fedora
Description of problem:
Running
from xarray.tests.test_dataset import create_test_data
fails with:
missing pytest if only python3-xarray has been installed
Once python3-pytest is installed, the error is the following:
ImportError while importing test module
'/builddir/build/BUILD/xbout-0.3.4/xbout/tests/test_plot.py'.
Hint: make sure your test modules/packages have valid Python names.
Traceback:
/usr/lib64/python3.11/importlib/__init__.py:126: in import_module
return _bootstrap._gcd_import(name[level:], package, level)
xbout/tests/test_plot.py:8: in <module>
from xbout.tests.test_load import bout_xyt_example_files
xbout/tests/test_load.py:14: in <module>
from xarray.tests.test_dataset import create_test_data
/usr/lib/python3.11/site-packages/xarray/tests/test_dataset.py:11: in <module>
from pandas.core.computation.ops import UndefinedVariableError
E ImportError: cannot import name 'UndefinedVariableError' from
'pandas.core.computation.ops'
(/usr/lib64/python3.11/site-packages/pandas/core/computation/ops.py)
_________________ ERROR collecting xbout/tests/test_region.py
__________________
Version-Release number of selected component (if applicable):
2022.03.0
How reproducible:
always
Steps to Reproduce:
1. python3 -c "import xarray.tests.test_dataset"
Alternatively try to build python-xbout 0.3.4 for rawhide:
https://koji.fedoraproject.org/koji/taskinfo?taskID=95936268
Actual results:
An ImportError is raised. Presumably that is due to a change in pandas.
Expected results:
Import works
Additional info:
This seems to be fixed in 2022.12
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2159621
https://bugzilla.redhat.com/show_bug.cgi?id=2093314
Bug ID: 2093314
Summary: CVE-2022-30784 ntfs-3g: crafted NTFS image can cause
heap exhaustion in ntfs_get_attribute_value
Product: Security Response
Hardware: All
OS: Linux
Status: NEW
Component: vulnerability
Keywords: Security
Severity: medium
Priority: medium
Assignee: security-response-team(a)redhat.com
Reporter: gsuckevi(a)redhat.com
CC: ddepaula(a)redhat.com,
epel-packagers-sig(a)lists.fedoraproject.org,
jferlan(a)redhat.com, kparal(a)redhat.com,
ngompa13(a)gmail.com, rjones(a)redhat.com,
spotrh(a)gmail.com, virt-maint(a)redhat.com
Target Milestone: ---
Classification: Other
A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in
NTFS-3G through 2021.8.22.
References:
https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xchm-ph5h-hw4xhttps://github.com/tuxera/ntfs-3g/releases
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2093314
https://bugzilla.redhat.com/show_bug.cgi?id=2107386
Product Security DevOps Team <prodsec-dev(a)redhat.com> changed:
What |Removed |Added
----------------------------------------------------------------------------
Resolution|--- |ERRATA
Status|NEW |CLOSED
Last Closed| |2023-05-17 00:35:07
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2107386