https://bugzilla.redhat.com/show_bug.cgi?id=2236392
Bug ID: 2236392
Summary: CVE-2023-39615 mingw-libxml2: libxml2: crafted xml can
cause global buffer overflow [fedora-all]
Product: Fedora
Version: 38
Status: NEW
Component: mingw-libxml2
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: rjones(a)redhat.com
Reporter: trathi(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
rjones(a)redhat.com
Target Milestone: ---
Classification: Fedora
More information about this security flaw is available in the following bug:
http://bugzilla.redhat.com/show_bug.cgi?id=2235864
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2236392
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2235983
Bug ID: 2235983
Summary: [abrt] hugo: runtime.raise(): hugo killed by SIGABRT
Product: Fedora
Version: 38
Hardware: x86_64
Status: NEW
Whiteboard: abrt_hash:73e47833aab30b963406f7b741e90d77cfc89f12;VAR
IANT_ID=workstation;
Component: hugo
Assignee: athoscribeiro(a)gmail.com
Reporter: alex(a)alexyzhang.dev
QA Contact: extras-qa(a)fedoraproject.org
CC: athoscribeiro(a)gmail.com,
epel-packagers-sig(a)lists.fedoraproject.org,
go-sig(a)lists.fedoraproject.org,
quantum.analyst(a)gmail.com, redhat(a)flyn.org
Target Milestone: ---
Classification: Fedora
Description of problem:
I changed the pagination configuration of my site while running hugo server.
Version-Release number of selected component:
hugo-0.101.0-4.fc38
Additional info:
reporter: libreport-2.17.11
type: CCpp
reason: hugo killed by SIGABRT
journald_cursor:
s=1457795fb62047009215084b85d84a12;i=a1267c;b=1e3b359226a34c258148272593a177fc;m=6985f0c46;t=6041d522d12c2;x=7f710a23e3aa4168
executable: /usr/bin/hugo
cmdline: hugo server
cgroup:
0::/user.slice/user-1000.slice/user@1000.service/app.slice/app-org.gnome.Terminal.slice/vte-spawn-4a2f3700-532f-4c53-ae0a-b78bd772731e.scope
rootdir: /
uid: 1000
kernel: 6.4.12-200.fc38.x86_64
package: hugo-0.101.0-4.fc38
runlevel: N 5
backtrace_rating: 3
crash_function: runtime.raise
comment: I changed the pagination configuration of my site while running
hugo server.
Truncated backtrace:
Thread no. 1 (21 frames)
#0 runtime.raise at /usr/lib/golang/src/runtime/sys_linux_amd64.s:159
#1 runtime.dieFromSignal at /usr/lib/golang/src/runtime/signal_unix.go:870
#2 runtime.sigfwdgo at /usr/lib/golang/src/runtime/signal_unix.go:1086
#3 runtime.sigtrampgo at /usr/lib/golang/src/runtime/signal_unix.go:432
#4 runtime.sigtramp at /usr/lib/golang/src/runtime/sys_linux_amd64.s:359
#6 runtime.raise at /usr/lib/golang/src/runtime/sys_linux_amd64.s:159
#7 runtime.dieFromSignal at /usr/lib/golang/src/runtime/signal_unix.go:870
#8 runtime.crash at /usr/lib/golang/src/runtime/signal_unix.go:962
#9 runtime.fatalpanic at /usr/lib/golang/src/runtime/panic.go:1170
#10 runtime.gopanic at /usr/lib/golang/src/runtime/panic.go:987
#11 runtime.chansend at /usr/lib/golang/src/runtime/chan.go:206
#12 runtime.selectnbsend at /usr/lib/golang/src/runtime/chan.go:694
#13 github.com/gohugoio/hugo/deps.(*globalErrHandler).SendError at
/usr/src/debug/hugo-0.101.0-4.fc38.x86_64/_build/src/github.com/gohugoio/hugo/deps/deps.go:121
#14 github.com/gohugoio/hugo/hugolib.(*HugoSites).Build at
/usr/src/debug/hugo-0.101.0-4.fc38.x86_64/_build/src/github.com/gohugoio/hugo/hugolib/hugo_sites_build.go:151
#15 github.com/gohugoio/hugo/commands.(*commandeer).buildSites at
/usr/src/debug/hugo-0.101.0-4.fc38.x86_64/_build/src/github.com/gohugoio/hugo/commands/hugo.go:737
#16 github.com/gohugoio/hugo/commands.(*commandeer).fullRebuild.func1 at
/usr/src/debug/hugo-0.101.0-4.fc38.x86_64/_build/src/github.com/gohugoio/hugo/commands/hugo.go:826
#17 runtime.goexit at /usr/lib/golang/src/runtime/asm_amd64.s:1594
#18 ??
#19 ??
#20 ??
#21 ??
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2235983
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2235652
Bug ID: 2235652
Summary: [abrt] xapps: memcpy(): xapp-sn-watcher killed by
SIGSEGV
Product: Fedora
Version: 38
Hardware: x86_64
Status: NEW
Whiteboard: abrt_hash:73a255339ba399a3e13d02ab3ece36961f42c91e;VAR
IANT_ID=workstation;
Component: xapps
Assignee: leigh123linux(a)googlemail.com
Reporter: nick(a)venenga.com
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
leigh123linux(a)googlemail.com, riehecky(a)fnal.gov
Target Milestone: ---
Classification: Fedora
Version-Release number of selected component:
xapps-2.6.1-1.fc38
Additional info:
reporter: libreport-2.17.11
package: xapps-2.6.1-1.fc38
type: CCpp
kernel: 6.3.11-200.fc38.x86_64
runlevel: N 5
executable: /usr/libexec/xapps/xapp-sn-watcher
cmdline: /usr/libexec/xapps/xapp-sn-watcher
rootdir: /
journald_cursor:
s=db9d76de648044c68f6c16556a0c1aea;i=804b7;b=0108284c9e044748a6923a9f44df8862;m=3d70bc6095;t=6006a0385d739;x=49860429736dc03a
backtrace_rating: 4
reason: xapp-sn-watcher killed by SIGSEGV
uid: 1000
crash_function: memcpy
Truncated backtrace:
Thread no. 1 (17 frames)
#0 memcpy at /usr/include/bits/string_fortified.h:29
#1 md5_sum_update at ../glib/gchecksum.c:380
#2 g_checksum_update at ../glib/gchecksum.c:1608
#3 g_compute_checksum_for_data at ../glib/gchecksum.c:1802
#4 get_icon_surface at ../xapp-sn-watcher/sn-item.c:371
#5 get_all_properties_callback at ../xapp-sn-watcher/sn-item.c:852
#6 g_task_return_now at ../gio/gtask.c:1309
#7 g_task_return at ../gio/gtask.c:1378
#9 reply_cb at ../gio/gdbusproxy.c:2571
#10 g_task_return_now at ../gio/gtask.c:1309
#11 g_task_return at ../gio/gtask.c:1378
#13 g_dbus_connection_call_done at ../gio/gdbusconnection.c:5887
#14 g_task_return_now at ../gio/gtask.c:1309
#15 complete_in_idle_cb at ../gio/gtask.c:1323
#19 g_main_context_iterate.isra.0 at ../glib/gmain.c:4276
#20 g_main_context_iteration at ../glib/gmain.c:4343
#21 g_application_run at ../gio/gapplication.c:2573
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2235652
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2235178
Bug ID: 2235178
Summary: Boost.Log shared library apparently dead-locks when
libssp-0.dll dependency is not in the default path
Product: Fedora
Version: 38
Status: NEW
Component: mingw-boost
Assignee: fedora(a)tsailer.ch
Reporter: hedayatv(a)gmail.com
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
fedora(a)tsailer.ch, rjones(a)redhat.com
Target Milestone: ---
Classification: Fedora
Description of problem:
TBH, I'm not sure if it is the right component to report for. Anyway, if I
compile a simple Boot.Log program with F38's MingGW64, I can run the program
with WINEPATH set to mingw's sysroot bin directory:
export WINEPATH=/usr/x86_64-w64-mingw32/sys-root/mingw/bin
wine test.exe
It runs fine. However, if I want to deploy the program, I put all .dll
dependencies including boost dlls into a dir (e.g. myapp). However, the program
doesn't successfully run and it hangs (apparently, is a deadlock.as also
reported by wine about a locked thread).
Now, if I only remove libssp-0.dll from the dir, it works fine again:
cd myapp
export WINEPATH=/usr/x86_64-w64-mingw32/sys-root/mingw/bin
rm libssp-0.dll
wine test.exe
I'm not sure, but looks like that whenever libssp-0.dll is loaded anywhere
except the default path, it cause deadlock.
Version-Release number of selected component (if applicable):
mingw64-boost-1.78.0-4.fc38.noarch
How reproducible:
100%
Steps to Reproduce:
1. Create the following file as test.cpp:
#include <boost/log/trivial.hpp>
int main(int, char*[])
{
BOOST_LOG_TRIVIAL(trace) << "A trace severity message";
BOOST_LOG_TRIVIAL(debug) << "A debug severity message";
BOOST_LOG_TRIVIAL(info) << "An informational severity message";
BOOST_LOG_TRIVIAL(warning) << "A warning severity message";
BOOST_LOG_TRIVIAL(error) << "An error severity message";
BOOST_LOG_TRIVIAL(fatal) << "A fatal severity message";
return 0;
}
2. Compile with:
$ x86_64-w64-mingw32-g++ test.cpp -lboost_log-mt-x64 -DBOOST_ALL_DYN_LINK
3. Run:
$ export WINEPATH=/usr/x86_64-w64-mingw32/sys-root/mingw/bin
$ wine a.exe
4. It runs successfully. Now, run:
$ unset WINEPATH
$ cp /usr/x86_64-w64-mingw32/sys-root/mingw/bin/*.dll .
$ wine a.exe
Actual results:
In step 4, you'll see the app hangs and you should kill it to terminate:
$ wine a.exe
002c:fixme:winediag:LdrInitializeThunk wine-staging 8.14 is a testing version
containing experimental patches.
002c:fixme:winediag:LdrInitializeThunk Please mention your exact version when
filing bug reports on winehq.org.
0088:fixme:wineusb:query_id Unhandled ID query type 0x5.
0088:fixme:hid:handle_IRP_MN_QUERY_ID Unhandled type 00000005
0088:fixme:hid:handle_IRP_MN_QUERY_ID Unhandled type 00000005
0088:fixme:hid:handle_IRP_MN_QUERY_ID Unhandled type 00000005
0088:fixme:hid:handle_IRP_MN_QUERY_ID Unhandled type 00000005
MESA-INTEL: warning: Haswell Vulkan support is incomplete
MESA-INTEL: warning: Haswell Vulkan support is incomplete
0114:err:sync:RtlpWaitForCriticalSection section 00000001CCDFD010 "?" wait
timed out in thread 0114, blocked by 0000, retrying (60 sec)
If you only remove libssp-0.dll from current directory and export WINEPATH to
point to the installed one, it works fine again.
Expected results:
$ wine a.exe
002c:fixme:winediag:LdrInitializeThunk wine-staging 8.14 is a testing version
containing experimental patches.
002c:fixme:winediag:LdrInitializeThunk Please mention your exact version when
filing bug reports on winehq.org.
0088:fixme:wineusb:query_id Unhandled ID query type 0x5.
0088:fixme:hid:handle_IRP_MN_QUERY_ID Unhandled type 00000005
0088:fixme:hid:handle_IRP_MN_QUERY_ID Unhandled type 00000005
0088:fixme:hid:handle_IRP_MN_QUERY_ID Unhandled type 00000005
0088:fixme:hid:handle_IRP_MN_QUERY_ID Unhandled type 00000005
MESA-INTEL: warning: Haswell Vulkan support is incomplete
MESA-INTEL: warning: Haswell Vulkan support is incomplete
[2023-08-27 18:47:12.922807] [0x00000114] [trace] A trace severity message
[2023-08-27 18:47:12.930604] [0x00000114] [debug] A debug severity message
[2023-08-27 18:47:12.939153] [0x00000114] [info] An informational severity
message
[2023-08-27 18:47:12.947407] [0x00000114] [warning] A warning severity message
[2023-08-27 18:47:12.956964] [0x00000114] [error] An error severity message
[2023-08-27 18:47:12.966910] [0x00000114] [fatal] A fatal severity message
$
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2235178
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…