https://bugzilla.redhat.com/show_bug.cgi?id=2333940
Bug ID: 2333940
Summary: CVE-2024-40896 mingw-libxml2: XXE vulnerability
[fedora-41]
Product: Fedora
Version: 41
Status: NEW
Whiteboard: {"flaws": ["f9ca14de-19d5-4ead-b24d-1d328f5f2111"]}
Component: mingw-libxml2
Keywords: Security, SecurityTracking
Severity: urgent
Priority: urgent
Assignee: rjones(a)redhat.com
Reporter: ahanwate(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
rjones(a)redhat.com
Blocks: 2333871
Target Milestone: ---
Classification: Fedora
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2333871
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2333940
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2333294
Bug ID: 2333294
Summary: [abrt] cinnamon-settings-daemon: check_volume_queue():
csd-automount killed by SIGSEGV
Product: Fedora
Version: 41
Hardware: x86_64
Status: NEW
Whiteboard: abrt_hash:4a75dc1aad38c50f524204176712820d14e85209;VAR
IANT_ID=;
Component: cinnamon-settings-daemon
Assignee: leigh123linux(a)googlemail.com
Reporter: vehre(a)gmx.de
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
leigh123linux(a)googlemail.com
Target Milestone: ---
Classification: Fedora
Description of problem:
Pluging in a mobile phone and not selecting a file transfer mode.
Version-Release number of selected component:
cinnamon-settings-daemon-6.2.0-2.fc41
Additional info:
reporter: libreport-2.17.15
crash_function: check_volume_queue
journald_cursor:
s=2b7ddbd89dd347578c36eb1efeb6a87e;i=1510be3;b=398bb05afe584466bdf38a9854d82d94;m=17bcdf3cd;t=6299c6c3c23ab;x=162ecb609421f6b5
package: cinnamon-settings-daemon-6.2.0-2.fc41
uid: 1000
comment: Pluging in a mobile phone and not selecting a file transfer
mode.
executable: /usr/libexec/csd-automount
runlevel: N 5
reason: csd-automount killed by SIGSEGV
cgroup: 0::/user.slice/user-1000.slice/session-2.scope
rootdir: /
kernel: 6.12.4-200.fc41.x86_64
type: CCpp
backtrace_rating: 4
cmdline: /usr/bin/csd-automount
Truncated backtrace:
Thread no. 1 (9 frames)
#0 check_volume_queue at ../plugins/automount/csd-automount-manager.c:186
#1 screensaver_signal_callback at
../plugins/automount/csd-automount-manager.c:351
#4 signal_emit_unlocked_R.isra.0 at ../gobject/gsignal.c:3887
#5 signal_emit_valist_unlocked at ../gobject/gsignal.c:3519
#8 on_signal_received at ../gio/gdbusproxy.c:874
#9 emit_signal_instance_in_idle_cb at ../gio/gdbusconnection.c:4189
#12 g_main_context_dispatch_unlocked at ../glib/gmain.c:4208
#13 g_main_context_iterate_unlocked.isra.0 at ../glib/gmain.c:4273
#15 gtk_main at ../gtk/gtkmain.c:1329
Potential duplicate: bug 2232900
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2333294
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2333254
Bug ID: 2333254
Summary: CVE-2024-45338 golang-x-net: Non-linear parsing of
case-insensitive content in golang.org/x/net/html
[fedora-41]
Product: Fedora
Version: 41
Status: NEW
Whiteboard: {"flaws": ["a4463782-1469-4be2-a943-3bbbf3a20606"]}
Component: golang-x-net
Keywords: Security, SecurityTracking
Severity: high
Priority: high
Assignee: mark.e.fuller(a)gmx.de
Reporter: ahanwate(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
go-sig(a)lists.fedoraproject.org, mark.e.fuller(a)gmx.de
Blocks: 2333122
Target Milestone: ---
Classification: Fedora
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2333122
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2333254
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2332736
Bug ID: 2332736
Summary: [abrt] meld: get_chunk():
diffutil.py:273:get_chunk:IndexError: list index out
of range
Product: Fedora
Version: 41
Hardware: x86_64
Status: NEW
Whiteboard: abrt_hash:2d2c6d9f8bc542cfa5acb2a72440a22d8793a5c0;VAR
IANT_ID=workstation;
Component: meld
Assignee: dmaphy(a)fedoraproject.org
Reporter: alex(a)alexyzhang.dev
QA Contact: extras-qa(a)fedoraproject.org
CC: dmaphy(a)fedoraproject.org,
epel-packagers-sig(a)lists.fedoraproject.org,
lkundrak(a)v3.sk, michel(a)michel-slm.name
Target Milestone: ---
Classification: Fedora
Description of problem:
I was merging two Markdown files.
Version-Release number of selected component:
meld-3.22.2-5.fc41
Additional info:
reporter: libreport-2.17.15
kernel: 6.11.11-300.fc41.x86_64
cmdline: /usr/bin/python3 /usr/bin/meld
2024-12-03-fall-2024-fuzzing-lab.md hackmd.md
cgroup:
0::/user.slice/user-1000.slice/user@1000.service/app.slice/run-re084c5dc808a476fa742d385ee709f60.scope
uid: 1000
reason: diffutil.py:273:get_chunk:IndexError: list index out of range
executable: /usr/bin/meld
type: Python3
package: meld-3.22.2-5.fc41
runlevel: N 5
exception_type: IndexError
crash_function: get_chunk
interpreter: python3-3.13.0-1.fc41.x86_64
comment: I was merging two Markdown files.
Truncated backtrace:
diffutil.py:273:get_chunk:IndexError: list index out of range
Traceback (most recent call last):
File "/usr/lib/python3.13/site-packages/meld/filediff.py", line 802, in
on_linkmap_scroll_event
self.next_diff(event.direction, use_viewport=True)
~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.13/site-packages/meld/filediff.py", line 829, in
next_diff
if not self._is_chunk_in_area(target, pane, text_area):
~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.13/site-packages/meld/filediff.py", line 810, in
_is_chunk_in_area
chunk = self.linediffer.get_chunk(chunk_id, pane)
File "/usr/lib/python3.13/site-packages/meld/matchers/diffutil.py", line 273,
in get_chunk
chunk = self._merge_cache[index][sequence]
~~~~~~~~~~~~~~~~~^^^^^^^
IndexError: list index out of range
Local variables in innermost frame:
self: <diffutil.Differ object at 0x7f057a8dc640 (meld+matchers+diffutil+Differ
at 0x55f91c2c67a0)>
index: 59
from_pane: 1
to_pane: None
sequence: 0
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2332736
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2332552
Bug ID: 2332552
Summary: External monitors can show hidden content before
screen is unlocked
Product: Fedora
Version: 41
Hardware: x86_64
OS: Linux
Status: NEW
Component: cinnamon
Keywords: Desktop, Security
Severity: high
Assignee: leigh123linux(a)googlemail.com
Reporter: rostigm(a)gmail.com
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
leigh123linux(a)googlemail.com, miketwebster(a)gmail.com
Target Milestone: ---
Classification: Fedora
Connecting a screen locked laptop to a docking station with additional external
monitors may expose content of those external monitors before unlocked if the
screen was previously locked without docking station connected. Some of those
external monitors could sometimes stop working and start showing an error
message about the input signal until its power is disconnected and connected
again.
In my case the docking station is Dell WD19, connected to HP EliteBook 840 G11
by a Type-C cable. My two external monitors are Dell P2425HE connected to the
docking station by DP cables.
Reproducible: Always
Steps to Reproduce:
1. Lock screen of your laptop (Ctrl+Alt+L) when it's NOT connected to any
docking station
2. Connect a docking station with two external monitors by Type-C cable
3. Make any mouse move
Actual Results:
The embedded monitor of the laptop remains to be locked but one or two external
monitors may show their hidden content before the screen is unlocked. Sometimes
one of the two external monitors may stop working and show an error about the
signal parameters until the power cable of that external monitor is
disconnected and connected again.
Expected Results:
All external monitors should hide their content until the screen is not
unlocked.
This works as expected only if the screen locking was done when external
monitors are connected.
I consider this bug as a security issue. Don't know if this is something Fedora
specific or general for all Cinnamon builds.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2332552
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…