[Bug 2067494] [NEW] Unrecognized parameter "append_to" when an extension tries to construct an animated icon

2024-05-29 Thread Mark Jaroski
SyncthingPanelIcon@file:///home/mark/.local/share/gnome-shell/extensions/syncth...@gnome.2nv2u.com/extension> _init@file:///home/mark/.local/share/gnome-shell/extensions/syncth...@gnome.2nv2u.com/extension.js:456

[Bug 129133] Re: mc uses predictable temp directory path

2024-05-27 Thread Mark Esler
Sounds good! The impact does sound low. Mostly I recommend CVEs if you want to make sure that downstreams apply a security patch. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/129133 Title:

[Bug 129133] Re: mc uses predictable temp directory path

2024-05-27 Thread Mark Esler
Hi @zyw o/ _If_ your project wants, I'm happy to assign and publish a CVE for this. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/129133 Title: mc uses predictable temp directory path To

[Bug 2065738] Re: Leaks wireguard keys

2024-05-23 Thread Mark Esler
*** This bug is a duplicate of bug 1987842 *** https://bugs.launchpad.net/bugs/1987842 Please refer to this issue as CVE-2022-4968. Marking this bug as a duplicate to https://bugs.launchpad.net/netplan/+bug/1987842 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-4968 **

[Bug 2066828] [NEW] do-release-upgrade fails, mantic to noble

2024-05-23 Thread Mark Berndt
Public bug reported: previous non lts upgrades have all completed. This upgrade fails and their is no specific information in the logs which I could interpret. ProblemType: Bug DistroRelease: Ubuntu 23.10 Package: ubuntu-release-upgrader-core 1:23.10.14 ProcVersionSignature: Ubuntu

[Bug 2066372] Re: Ubuntu 22.04 LTS - swaylock -v 1.5 - lock screen bypasses

2024-05-22 Thread Mark Esler
Focal (20.04) and Jammy (22.04) swaylock versions are affected https://ubuntu.com/security/CVE-2022-26530 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-26530 ** Information type changed from Private Security to Public Security -- You received this bug notification because

[Bug 2066035] [NEW] KWM Switch causes logout

2024-05-17 Thread Mark Smith
Public bug reported: I have a 2x1 KVM switch between my work laptop (win10) and my Ubuntu 24.04 (noble) desktop. When I switch from Ubuntu to the work laptop - whether I have locked the screen or not - the Ubuntu session logs me out. I had originally thought it was rebooting the desktop, but

[Bug 1721428] Re: Artful (17.10) Session logout after screen turned off

2024-05-17 Thread Mark Smith
This bug affects me on 24.04 noble too. It did not on 23.10. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1721428 Title: Artful (17.10) Session logout after screen turned off To manage

[Bug 2020212] Re: /proc//stat doesn't update after resume from hibernation

2024-05-13 Thread Mark Waterhouse
Same behaviour across CentOS 7.9.2009 on AWS ** Also affects: centos Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2020212 Title: /proc//stat doesn't

[Bug 2059847] Re: Input lag or freezes on Nvidia desktops with X11 after logging "MetaSyncRing: Sync object is not ready -- were events handled properly?"

2024-05-13 Thread Mark Erbaugh
Ubuntu LTS 22.04.4 I ran Deku's script, from message 102 above: sudo apt install -y --allow-downgrades \ gir1.2-mutter-10=42.9-0ubuntu7vv1 \ mutter-common=42.9-0ubuntu7vv1 \ libmutter-10-0=42.9-0ubuntu7vv1; That cleared things up, no lag / MetaSyncRing errors, but Ubuntu now wants to re-upgrade

[Bug 2059847] Re: Input lag or freezes on Nvidia desktops with X11 after logging "MetaSyncRing: Sync object is not ready -- were events handled properly?"

2024-05-11 Thread Mark Erbaugh
Thanks Deku. With just a very quick test (applied then rebooted), the snippet posted above seems to be working for me with Ubuntu 22.04.4 LTS. I had to add the apt option --allow-downgrades Mark -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed

[Bug 2064999] Re: Prevent soft lockups during IOMMU streaming DMA mapping by limiting nvme max_hw_sectors_kb to cache optimised size

2024-05-09 Thread Mark Nelson
Hey folks, I think we may have encountered this or a variant of this while running extremely strenuous Ceph performance tests on a very high speed cluster we designed for a customer. We have a write-up that includes a section on needing to disable iommu here:

[Bug 1948714] Re: After reboot, the password set at install time doesn't work.

2024-05-09 Thread Mark Smith
*** This bug is a duplicate of bug 1875062 *** https://bugs.launchpad.net/bugs/1875062 This bug is back in 24.04 (noble). Same issue - Set the keyboard to UK at install, but the keyboard used is US layout so special characters e.g. # & £ are transposed, and therefore doesn't work at first

[Bug 2046084] Re: HID gamepad not working when paired with blueman on bluez 5.68-0ubuntu1.1

2024-05-07 Thread Mark Esler
*** This bug is a duplicate of bug 2045931 *** https://bugs.launchpad.net/bugs/2045931 Ack, thanks for the explanation. ** Tags added: regression-security regression-update -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2046116] Re: bluetooth device connected but not recognised as output device

2024-05-07 Thread Mark Esler
@vorlon answered why in https://bugs.launchpad.net/ubuntu/+source/blueman/+bug/2046084/comments/7 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2046116 Title: bluetooth device connected but not

[Bug 2064966] Re: "accept_source_route" enabled by default in 24.04

2024-05-06 Thread Mark Esler
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2064966 Title: "accept_source_route" enabled by default in 24.04 To manage

[Bug 2046116] Re: bluetooth device connected but not recognised as output device

2024-05-06 Thread Mark Esler
@vanvugt, @vorlon, why is this marked as a regression? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2046116 Title: bluetooth device connected but not recognised as output device To manage

[Bug 2046084] Re: HID gamepad not working when paired with blueman on bluez 5.68-0ubuntu1.1

2024-05-06 Thread Mark Esler
*** This bug is a duplicate of bug 2045931 *** https://bugs.launchpad.net/bugs/2045931 This is not a security regression. This is upstreams fix to prevent https://github.com/skysafe/reblog/blob/main/cve-2024-0230/README.md If you wish to to enable legacy devices (and the vulnerability) with

[Bug 2064751] Re: [SRU] revert security-regression in Focal's libcrypto++

2024-05-03 Thread Mark Esler
** Description changed: [ Impact ] Focal's libcrypto++ 5.6.4-9 regresses elliptic curve generation. Uploading this version from Debian appears to have been a mistake. This is a security regression, but was not published through the security pocket. As far as I am aware,

[Bug 2064751] Re: [SRU] revert security-regression in Focal's libcrypto++

2024-05-03 Thread Mark Esler
** Description changed: [ Impact ] Focal's libcrypto++ 5.6.4-9 regresses elliptic curve generation. Uploading this version from Debian appears to have been a mistake. This is a security regression, but was not published through the security pocket. As far as I am aware,

[Bug 2064751] [NEW] [SRU] revert security-regression in Focal's libcrypto++

2024-05-03 Thread Mark Esler
Public bug reported: [ Impact ] Focal's libcrypto++ 5.6.4-9 regresses elliptic curve generation. Uploading this version from Debian appears to have been a mistake. This is a security regression, but was not published through the security pocket. As far as I am aware, Debian only packaged

[Bug 2064751] Re: [SRU] revert security-regression in Focal's libcrypto++

2024-05-03 Thread Mark Esler
** Attachment added: "main.cpp" https://bugs.launchpad.net/ubuntu/+source/libcrypto++/+bug/2064751/+attachment/5774479/+files/main.cpp -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2064751 Title:

[Bug 2064751] Re: [SRU] revert security-regression in Focal's libcrypto++

2024-05-03 Thread Mark Esler
** Patch added: "libcrypto++_5.6.4-9ubuntu1.debdiff" https://bugs.launchpad.net/ubuntu/+source/libcrypto++/+bug/2064751/+attachment/5774481/+files/libcrypto++_5.6.4-9ubuntu1.debdiff ** Also affects: libcrypto++ (Ubuntu Focal) Importance: Undecided Status: New -- You received this

[Bug 2059734] Re: Tar fails to extract archives that include folders with certain permissions on armhf

2024-05-01 Thread Mark Elvers
If you compile tar from scratch within the Docker container, then you do not see the error. ``` wget https://ftp.gnu.org/gnu/tar/tar-1.35.tar.gz tar -xzf tar-1.35.tar.gz ``` Ignore the errors from the tar process :-) ``` apt install build-essential libacl1-dev -y cd tar-1.35

[Bug 2059734] Re: Tar fails to extract archives that include folders with certain permissions on armhf

2024-05-01 Thread Mark Elvers
This also affects ppc64le Docker images. These commands work fine on x86_64, arm64 and s390 but fail on POWER9. ``` docker run -it --rm ubuntu:noble apt-get -y update apt install -y wget cd /tmp wget a-tar-file-of-your-choice.tar.gz tar -xzf a-tar-file-of-your-choice.tar.gz ``` Error message:

[Bug 2040137] Re: exposing the EFI shell in Secure Boot mode can lead to security bypass

2024-04-28 Thread Mark Esler
This has been addressed in the LXD snaps 5.21/stable (https://github.com/canonical/lxd-pkg-snap/commit/764ee08b) and 5.0/edge (https://github.com/canonical/lxd-pkg-snap/commit/bfe4270e). All LXD software before version 4 are not affected. Jammy, Mantic, and Noble do not have debs. Focal's deb is

[Bug 2062667] Re: Fails on (and should be removed from) raspi desktop

2024-04-27 Thread Mark Esler
This impacts all arm64 installs, not just raspberry pi. The MIR for qrtr and protection-domain-mapper [0] was requested late in the Mantic cycle and was only approved by Security since it was promised to only be used for x13s hardware enablement. Hopefully Qualcomm IPC is only enabled for x13s

[Bug 2063961] [NEW] Microsoft 365 account keeps disconnecting

2024-04-27 Thread Mark Smith
Public bug reported: When I use the new (24.04) settings and 'Online Accounts' to connect to Microsoft 365, it authenticates, works well for about 5 minutes and then disconnects. I have to remove that account and redo it every time I want to use it. ProblemType: Bug DistroRelease: Ubuntu 24.04

[Bug 2063308] Re: lenovo p1g5 suspend issues with docking stations

2024-04-25 Thread Mark Pearson
Can we get the system config details please - CPU, GPU in particular. Also confirm if WWAN is enabled Which dock is being used? Can you confirm if AMT is enabled or not in the BIOS? We've seen issues with AMT enabled with the TBT dock, especially with networking. Will look to reproduce the

[Bug 2063227] [NEW] Feh crashes on double finger tapping

2024-04-23 Thread Mark
Public bug reported: 1. No LSB modules are available. Description:Ubuntu 24.04 LTS Release:24.04 2. feh: Installed: 3.10.1-1build3 Candidate: 3.10.1-1build3 Version table: *** 3.10.1-1build3 500 500 http://us.archive.ubuntu.com/ubuntu noble/universe amd64 Packages

[Bug 1990655] Re: MIR: libgit2, http-parser

2024-04-23 Thread Mark Esler
http-parser has been deprecated [0] for llhttp [1] in libgit2 \o/ [0] https://github.com/libgit2/libgit2/issues/6074 [1] https://github.com/libgit2/libgit2/pull/6713 ** Bug watch added: github.com/libgit2/libgit2/issues #6074 https://github.com/libgit2/libgit2/issues/6074 -- You received

[Bug 2063160] Re: Security Update required

2024-04-22 Thread Mark Esler
Thank you! This was mistriaged as not affecting Ubuntu, which has been corrected: https://git.launchpad.net/ubuntu-cve- tracker/commit/?id=83e00d6f10a8f7a234751a97f87a62c88d0143cb I have messaged Debian Security to track this as well. ** CVE added:

[Bug 2063014] Re: CVE-2023-50246 and CVE-2023-50268

2024-04-22 Thread Mark Esler
** Changed in: jq (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2063014 Title: CVE-2023-50246 and CVE-2023-50268 To manage notifications about this bug

[Bug 2063014] Re: CVE-2023-50246 and CVE-2023-50268

2024-04-22 Thread Mark Esler
CVE-2023-50246 only affects jq >= 1.7 until 1.7.1. That issue was introduced with cf4b48c7ba30cb30e116b523cff036ea481459f6. Mantic (23.10) has jq version 1.6-3 and Noble (24.04) has 1.7.1-3build1. This is why unaffected versions are labeled as "Not vulnerable (code not present)" on

[Bug 2004516] Re: [MIR] libyuv (transitive dependency of libheif)

2024-04-17 Thread Mark Esler
I reviewed libyuv 0.0~git202401110.af6ac82-1 as checked into noble. This shouldn't be considered a full audit but rather a quick gauge of maintainability. libyuv is an open source project that includes YUV scaling and conversion functionality. - CVE History: - none - open bug reports are not

[Bug 2061750] Re: [MIR] python-s3transfer as indirect dependency of simplestreams (simplestreams -> python-boto3 -> python-s3transfer)

2024-04-17 Thread Mark Esler
** Tags added: sec-4083 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2061750 Title: [MIR] python-s3transfer as indirect dependency of simplestreams (simplestreams -> python-boto3 ->

[Bug 2061751] Re: [MIR] python-botocore as indirect dependency of simplestreams (simplestreams -> python-boto3 -> python-s3transfer -> python-botocore)

2024-04-17 Thread Mark Esler
** Tags added: sec-4084 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2061751 Title: [MIR] python-botocore as indirect dependency of simplestreams (simplestreams -> python-boto3 ->

[Bug 2061217] Re: [MIR] python-boto3 as a dependency of simplestreams

2024-04-17 Thread Mark Esler
** Tags added: sec-4082 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2061217 Title: [MIR] python-boto3 as a dependency of simplestreams To manage notifications about this bug go to:

[Bug 2061924] Re: grip missing from (pre)noble (2024-04-16)

2024-04-17 Thread Mark Eichin
Thanks! That's the detail I was hoping for. (In the meantime I found that "pandoc --from gfm --to html" did just as good a job and swapped over to it, so I am no longer personally concerned about the package itself.) -- You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 2061924] [NEW] grip missing from (pre)noble (2024-04-16)

2024-04-16 Thread Mark Eichin
Public bug reported: $ apt-cache show grip N: Unable to locate package grip E: No packages found Jammy/22.04 had grip_4.2.0-3_all.deb "Preview GitHub Markdown files like Readme locally". (Not the ancient gnome cd player/ripper app.) Didn't see any bugs here about the package being dropped. No

[Bug 2061217] Re: [MIR] python-boto3 as a dependency of simplestreams

2024-04-16 Thread Mark Esler
Hello, the MIR process says any MIRs assigned to the security team after the Beta Freeze deadline need to be discussed with the Director of Security Engineering: For a MIR to be considered for a release, it must be assigned to the Security team (by the MIR team) before Beta Freeze. This

Re: [Bug 1875062] Re: [20.04] Keyboard layout changes during installation before typing username/password

2024-04-15 Thread Mark Smith
Dag, Can you confirm you mean 24.04 and not 22.04, please? On Mon, 15 Apr 2024 at 17:25, Dag Bjerkeli <1875...@bugs.launchpad.net> wrote: > I've just tested this, and can confirm that there is a bug regarding > keyboard layout in 22.04 beta. As this time the error also appears when > you select

[Bug 1875062] Re: [20.04] Keyboard layout changes during installation before typing username/password

2024-04-13 Thread Mark Smith
Hi guys, I'm sorry to say that this bug is back in 24.04 Beta. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1875062 Title: [20.04] Keyboard layout changes during installation before typing

[Bug 2060564] Re: miscomputation of ECP::ScalarMultiply() using 5.6.4-9

2024-04-12 Thread Mark Esler
There is a strong chance that https://bugs.launchpad.net/ubuntu/+source/libcrypto++/+bug/1893934 is related to the incomplete CVE-2019-14318 patch regression. I plan to propose an SRU to effectively downgrade this regressed package to 5.6.4-8. Please see

[Bug 2004516] Re: [MIR] libyuv (transitive dependency of libheif)

2024-04-11 Thread Mark Esler
When is Security review absolutely needed by? Is April 17th, the day before Final Freeze okay? Would that give Foundation's enough time to promote to main? There may not be enough time for Security to complete a review by Final Freeze, but we are looking for someone to take this asap. -- You

[Bug 2030880] Re: [MIR] libemail-mime-perl (libmail-dmarc-perl dependency)

2024-04-10 Thread Mark Esler
Setting to In Progress per https://bugs.launchpad.net/ubuntu/+source/libmail-dmarc- perl/+bug/2023971/comments/28 ** Changed in: libemail-mime-perl (Ubuntu) Status: Won't Fix => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed

[Bug 2004516] Re: [MIR] libyuv (transitive dependency of libheif)

2024-04-09 Thread Mark Esler
** Tags added: sec-4053 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2004516 Title: [MIR] libyuv (transitive dependency of libheif) To manage notifications about this bug go to:

[Bug 2060035] Re: [MIR] msgraph

2024-04-09 Thread Mark Esler
** Tags added: sec-4054 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2060035 Title: [MIR] msgraph To manage notifications about this bug go to:

[Bug 2060564] Re: miscomputation of ECP::ScalarMultiply() using 5.6.4-9

2024-04-08 Thread Mark Esler
Debian `libcrypto++` 5.6.4-9 introduced a security patch for CVE-2019-14318. According to a post in 2019 , https://github.com/weidai11/cryptopp/issues/869, the CVE-2019-14318 patch for 5.6.4 was incomplete. A comment in a later 2020 issue mentions that the 2019 8.3 patch was broken:

[Bug 2060564] Re: miscomputation of ECP::ScalarMultiply() using 5.6.4-9

2024-04-08 Thread Mark Esler
With fresh amd64 VMs using the latest Ubuntu point releases, I was able to reproduce your report on Ubuntu Focal 20.04.06 (`libcrypto++` version 5.6.4-9build1). Both Bionic 18.04.06 (`libcrypto++` version 5.6.4-8) and Jammy 22.04.04 (`libcrypto++` version 8.6.0-2ubuntu1) had the expected result.

[Bug 2060564] [NEW] miscomputation of ECP::ScalarMultiply() using 5.6.4-9

2024-04-08 Thread Mark Esler
*** This bug is a security vulnerability *** Public security bug reported: This issue was reported to the Security team over email and originally posted to https://github.com/weidai11/cryptopp/issues/1269 > I typically never use Crypto++, but I had to yesterday, and I then > experienced a

[Bug 2054127] Re: grub-efi crashes upon `exit`

2024-04-06 Thread Mark Esler
A fix has been released to Noble proposed and the CVE has been published. https://launchpad.net/ubuntu/+source/grub2/2.12-1ubuntu7 ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 2048781] Re: [MIR] authd

2024-03-27 Thread Mark Esler
I believe this issue can be set to In Progress and is ready for promotion to main. @didrocks, @slyon: please ping me if anything is needed from Security. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2048781] Re: [MIR] authd

2024-03-27 Thread Mark Esler
I am posting this Security MIR on behalf of Sudhakar Verma (@sudhackar) since he is out of the office. --- I reviewed authd 0.2.1 as checked into noble. This shouldn't be considered a full audit but rather a quick gauge of maintainability. authd is a service that builds cloud based

[Bug 2051850] Re: [MIR] trace-cmd

2024-03-26 Thread Mark Esler
I reviewed trace-cmd 3.2-1 as checked into noble. This shouldn't be considered a full audit but rather a quick gauge of maintainability. > TRACE-CMD: The front-end application to Ftrace. The back-end application to KernelShark. - CVE History - none - Build-Depends - most are for docs -

[Bug 2051916] Re: [MIR] promote libtraceevent as a trace-cmd dependency

2024-03-26 Thread Mark Esler
I reviewed libtraceevent 1:1.8.2-1 as checked into noble. This shouldn't be considered a full audit but rather a quick gauge of maintainability. > libtraceevent - Linux kernel trace event library - CVE History: - none - Build-Depends? - nothing concerning - most dependencies are for

[Bug 2030880] Re: [MIR] libemail-mime-perl (libmail-dmarc-perl dependency)

2024-03-25 Thread Mark Esler
Per MIR Team's #3 requirement, the described issue was patched on May 20th 2020 (although the GH bug remains open). There are three commits: a fix, a test, and documentation. These landed in upstream version 1.947. Please see https://github.com/rjbs/Email- MIME/issues/66#issuecomment-2019041975

[Bug 2059048] [NEW] adduser allows no password when PAM's pwquality is restrictively set

2024-03-25 Thread Mark Esler
Public bug reported: If pam_pwqaulity is restrictively set a user can still be created by adduser without a password. e.g., ``` eslerm@mino:~$ cat /etc/pam.d/common-password |grep pwquality password requisite pam_pwquality.so retry=3 minlen=8 maxrepeat=3 ucredit=-1 lcredit=-1 dcredit=-1

[Bug 2059049] [NEW] adduser allows no password when PAM's pwquality is restrictively set

2024-03-25 Thread Mark Esler
Public bug reported: If pam_pwqaulity is restrictively set a user can still be created by adduser without a password. e.g., ``` eslerm@mino:~$ cat /etc/pam.d/common-password |grep pwquality password requisite pam_pwquality.so retry=3 minlen=8 maxrepeat=3 ucredit=-1 lcredit=-1 dcredit=-1

[Bug 2054480] Re: [MIR] nbd-client

2024-03-25 Thread Mark Esler
Thanks Wouter It appears nbd-client existed in main at some point http://old- releases.ubuntu.com/ubuntu/pool/main/n/nbd/ (thanks Seth). Between this MIR and tree's LP#2056099 I am concerned that Security is being bypassed as NN approaches. That's not to say anything is wrong with how nbd-client

[Bug 2056099] Re: [MIR] tree

2024-03-25 Thread Mark Esler
Security is not asking to review this for NN, but this might have odd code. ``` /* Should probably use strdup(), but we like our xmalloc() */ #define scopy(x)strcpy(xmalloc(strlen(x)+1),(x)) ``` -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 2054480] Re: [MIR] nbd-client

2024-03-22 Thread Mark Esler
Was -server code ever reviewed by a MIR? The client contains many ioctl calls. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2054480 Title: [MIR] nbd-client To manage notifications about this bug

[Bug 2037082] Re: UBSAN: array-index-out-of-bounds with kernel 6.5 on Mantic

2024-03-22 Thread Mark Kendall
I had this problem with Ubuntu 24.04 with VirtualBox 7.0.14-dfsg-4 on my computer Fixed it for now by installing Oracle test 7.0.15 test build https://www.virtualbox.org/download/testcase/VirtualBox-7.0.15-162366-Linux_amd64.run from https://www.virtualbox.org/wiki/Testbuilds -- You received

[Bug 2052652] Re: [MIR] gnome-snapshot

2024-03-18 Thread Mark Esler
There are unnecessary crates being vendored. I filed an upstream issue: https://gitlab.gnome.org/GNOME/snapshot/-/issues/137 This causes a bandwidth strain on mirrors or wherever the source package is needed. To be clear, this is not a Security issue and does not impact Security's review (since

[Bug 1977614] Re: [MIR] fdk-aac-free

2024-03-15 Thread Mark Esler
The upstream chain for fdk-aac-free is precarious. The Debian package fdk-aac-free watches https://gitlab.freedesktop.org/wtaymans/fdk-aac-stripped/ This version specifically removes the HE (High Efficiency) and HEv2 profiles which have patent concerns (see README.fedora). This version does not

[Bug 2015538] Re: [MIR] dbus-broker

2024-03-15 Thread Mark Esler
Thank you @seb128. I was asked to get your feedback before completing the Security review. Get well soon! Security team ACK for promoting dbus-broker to main, under the condition that src:dbus' binary packages are split as described by @paelzer in comment #19. -- You received this bug

[Bug 2052809] Re: [MIR] bpftrace

2024-03-15 Thread Mark Esler
I reviewed bpftrace 0.20.1 as checked into noble. This shouldn't be considered a full audit but rather a quick gauge of maintainability. > bpftrace is a high-level tracing language for Linux enhanced Berkeley Packet Filter (eBPF) available in recent Linux kernels (4.x). bpftrace uses LLVM as a

[Bug 2052809] Re: [MIR] bpftrace

2024-03-15 Thread Mark Esler
Assigning to Security early, so that this is not blocked for 24.04. After Feature Freeze, if the MIR Team has requirements for a package, but is reasonably sure that the owning-team will accomplish them, please assign MIRs to the Security team immediately. ** Changed in: bpftrace (Ubuntu)

[Bug 2052813] Re: [MIR] bpfcc

2024-03-15 Thread Mark Esler
I reviewed bpfcc 0.29.1+ds-1ubuntu2 as checked into noble. This shouldn't be considered a full audit but rather a quick gauge of maintainability. - CVE History - no CVEs tracked in UCT, initially - searching for "bcc" CVEs finds false-positives - Build-Depends - nothing concerning -

[Bug 2015538] Re: [MIR] dbus-broker

2024-03-14 Thread Mark Esler
@seb128, could you please review the recent discussion? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2015538 Title: [MIR] dbus-broker To manage notifications about this bug go to:

[Bug 2024284] Re: SEGV vulnerability in command-line parser

2024-03-11 Thread Mark Esler
Apologize for not responding earlier! This slipped through my emails. > I know Canonical is also Root CNA, why are you redirecting to another CNA? Canonical is a CNA, not a Root CNA. I don't see how an _unprivileged_ attacker could leverage this bug to be a vulnerability. A clear proof of

[Bug 2056495] [NEW] Ubiquity crashes a few seconds into the install process

2024-03-07 Thread Mark Dixon
Public bug reported: I'm following the instructions at: https://mutschler.dev/linux/ubuntu-btrfs-20-04/#create-filesystems-for-root-and-efi-system-partitions. All goes well until I attempt to work with the installer ("ubiquity --no-bootloader" command). I can select language (English), keyboard

[Bug 1231178] Re: Altec Lansing speakers remote control not working

2024-03-04 Thread Mark Esler
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1231178 Title: Altec Lansing speakers remote control not working To manage notifications

[Bug 927225] Re: Yukon Optima 88E8059 fails to come up as a network interface when system is powered on without AC or network cable

2024-03-04 Thread Mark Esler
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/927225 Title: Yukon Optima 88E8059 fails to come up as a network interface when system is

[Bug 1884207] Re: Wifi Enterprice Login Page does not appear at connect

2024-03-04 Thread Mark Esler
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1884207 Title: Wifi Enterprice Login Page does not appear at connect To manage

[Bug 1696859] Re: package linux-image-4.10.0-22-generic (not installed) failed to install/upgrade: subprocess new pre-installation script returned error exit status 128

2024-03-04 Thread Mark Esler
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1696859 Title: package linux-image-4.10.0-22-generic (not installed) failed to

[Bug 1919150] Re: My keyboard stop working

2024-03-04 Thread Mark Esler
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1919150 Title: My keyboard stop working To manage notifications about this bug go to:

[Bug 1904391] Re: Touchpad and Keyboard not detectable in the new kernel

2024-03-04 Thread Mark Esler
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1904391 Title: Touchpad and Keyboard not detectable in the new kernel To manage

[Bug 2055450] Re: Uploading package to server with self-signed certificate on https fails despite adding cert to trust-store

2024-03-01 Thread Mark Cunningham
Update: after a lot of discussion with Mitch Burton on the Landscape team, he was able to demonstrate this working with a self-signed certificate. We think that this may actually not be strictly an issue with the self-signed SSL, but rather that the name in the cert is not an FQDN, and instead is

[Bug 2051850] Re: [MIR] trace-cmd

2024-02-29 Thread Mark Esler
** Tags added: sec-3932 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2051850 Title: [MIR] trace-cmd To manage notifications about this bug go to:

[Bug 2051916] Re: [MIR] promote libtraceevent as a trace-cmd dependency

2024-02-29 Thread Mark Esler
** Tags added: sec-3931 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2051916 Title: [MIR] promote libtraceevent as a trace-cmd dependency To manage notifications about this bug go to:

[Bug 2055450] [NEW] Uploading package to server with self-signed certificate on https fails despite adding cert to trust-store

2024-02-29 Thread Mark Cunningham
Public bug reported: On Ubuntu 22.04 with dput version 1.1.0ubuntu2.1, and python3 3.10.x, customers using a self-signed SSL for https are getting the following: File "/usr/bin/dput", line 37, in sys.exit(load_entry_point('dput==1.1.0+ubuntu2.1', 'console_scripts', 'execute-dput')())

Re: [Bug 2043524] Re: audio disappeared after upgrade to Ubuntu 23.10

2024-02-29 Thread Mark Bixler
I eventually figured out that the control bar for my external speaker had been turned off somehow in the process. I turned it on and it has worked fine since. On Thursday, February 29, 2024 at 07:46:16 AM EST, Pablo Fontoura <2043...@bugs.launchpad.net> wrote: Same thing  here. Fresh

[Bug 2052813] Re: [MIR] bpfcc

2024-02-28 Thread Mark Esler
Some of the bpf tools do not work on mantic. e.g. `/usr/sbin/tcptop-bpfcc` from `bpfcc-tools` does not work, but `/usr/sbin/tcptop` from `libbpfcc` does (on mantic) Kernel configs and pahole version used to build mantic's kernel should be okay

[Bug 2052652] Re: [MIR] gnome-snapshot

2024-02-28 Thread Mark Esler
** Changed in: gnome-snapshot (Ubuntu) Assignee: (unassigned) => Ubuntu Security Team (ubuntu-security) ** Tags added: sec-3916 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2052652 Title:

[Bug 2048781] Re: [MIR] authd

2024-02-28 Thread Mark Esler
A centralized vendor-linter is the best longterm option. Toolchains needs more resources before they can provide a solution (FR-6859). -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2048781 Title:

[Bug 2052813] Re: [MIR] bpfcc

2024-02-27 Thread Mark Esler
Máté, could you please see if the rational can be broadened for FO147? I suspect that libbpf-tools is also important. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2052813 Title: [MIR] bpfcc To

[Bug 2052813] Re: [MIR] bpfcc

2024-02-27 Thread Mark Esler
Promoting bpfcc-tools and bpftrace is driving promotion of bpfcc based on FO147. Also, bpftrace's /usr/sbin/*.bt files re-implement bpfcc-tools with bpftrace. Assigning to Security for MIR, with root-use scope kept in mind. Only code for libbpfcc and bpfcc-tools will be reviewed. ** Changed in:

[Bug 2052809] Re: [MIR] bpftrace

2024-02-26 Thread Mark Esler
** Tags added: sec-3898 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2052809 Title: [MIR] bpftrace To manage notifications about this bug go to:

[Bug 2052813] Re: [MIR] bpfcc

2024-02-26 Thread Mark Esler
** Tags added: sec-3897 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2052813 Title: [MIR] bpfcc To manage notifications about this bug go to:

[Bug 2054977] [NEW] systemd-networkd fails to renew DHCP v4 lease when renew attempt times out

2024-02-25 Thread mark
Public bug reported: I'm seeing exactly what this gist describes: https://gist.github.com/raggi/1f8d0b9f45c5b62e7131b03e6e2ffe68 Summary: 1. Configure a machine with a DHCPv4 lease on a network with a DHCPv4 server. 2. Place machine under unusual load sufficient to cause a timeout on netlink

[Bug 2048781] Re: [MIR] authd

2024-02-25 Thread Mark Esler
Thanks @didrocks! I added a comment to the upstream cargo issue based on advice from toolchains and ~Rust [0]. This issue is also raised in ubuntu-mir [1]. I'll mention this at the next MIR meeting. [0] https://github.com/rust-lang/cargo/issues/11929#issuecomment-1960081509 [1]

[Bug 1976498] Re: DING causes gvfsd 'Too many files open' error and fills syslog

2022-06-01 Thread Mark Smith
Changed from ding to nautilus after reading about nautilus gvfsd-trash bug ** Package changed: ding (Ubuntu) => nautilus (Ubuntu) ** Summary changed: - DING causes gvfsd 'Too many files open' error and fills syslog + nautilus causes gvfsd-trash 'Too many files open' error and fills syslog **

[Bug 1976498] Re: DING causes gvfsd 'Too many files open' error and fills syslog

2022-06-01 Thread Mark Smith
Further reading would suggest that it's a bug in Nautilus and the way that gvfsd deals with trash: https://www.reddit.com/r/gnome/comments/l0gg32/a_helpul_tip_for_those_with_gvfsdtrash_hogging/ It runs out that I don't have ding installed, and also no references to gvfsd. Yet, if I do as the

[Bug 1976498] [NEW] DING causes gvfsd 'Too many files open' error and fills syslog

2022-06-01 Thread Mark Smith
Public bug reported: My syslog is filled (to >30GB) regularly with these messages. I seem to have this thing called DING going on, which maybe causing it? Jun 1 11:41:49 marks-linux-box gvfsd[123068]: (process:123068): GLib-GIO-WARNING **: 10:41:49.625: fail: Error accepting connection: Too

[Bug 1946660] Re: Ubuntu port of v4l2loopback doesn't behave the same as official port (v0.12.5)

2022-05-24 Thread Mark Tompkins
The issue persists into 22.04 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1946660 Title: Ubuntu port of v4l2loopback doesn't behave the same as official port (v0.12.5) To manage notifications

[Bug 1975644] [NEW] package ca-certificates 20211016 failed to install/upgrade: installed ca-certificates package post-installation script subprocess returned error exit status 1

2022-05-24 Thread Mark Weaver
Public bug reported: upgrade from focal->jammy requested me to report this issue ProblemType: Package DistroRelease: Ubuntu 22.04 Package: ca-certificates 20211016 ProcVersionSignature: Ubuntu 5.4.0-113.127-generic 5.4.181 Uname: Linux 5.4.0-113-generic x86_64 ApportVersion: 2.20.11-0ubuntu82.1

[Bug 1975487] [NEW] zsys not installed during Kinetic ISO install with ZFS option

2022-05-23 Thread Mark Smith
Public bug reported: After following the instructions at: http://iso.qa.ubuntu.com/qatracker/milestones/433/builds/248685/testcases/1716/results on the 20220523 daily build of Kinetic, I used the command zsysctl show and was met with the message: ~$ zsysctl show Command 'zsysctl' not found,

Re: [Bug 1975409] Re: package php8.1-xdebug 3.1.2+2.9.8+2.8.1+2.5.5-4 failed to install/upgrade: installed php8.1-xdebug package post-installation script subprocess returned error exit status 2

2022-05-22 Thread Mark Thompson
Hi, Thanks That has  cleared the the issue with x-debug. The php.ini files still have the modifications in them I made. Still wondering how this happened after what appeared a clean upgrade? Regards, Mark. On 22/05/2022 11:41, Manfred Hampl wrote: > "/usr/sbin/phpenmod: 31: .: can

[Bug 1975409] [NEW] package php8.1-xdebug 3.1.2+2.9.8+2.8.1+2.5.5-4 failed to install/upgrade: installed php8.1-xdebug package post-installation script subprocess returned error exit status 2

2022-05-22 Thread Mark Thompson
Public bug reported: xdebug still appears to work, just means everything I tried to install using apt appears to fail. In addition php 8.1 does not appear to have some standard extensions installed. so composer would not work until I added to the php.ini for example extension=pdo and the one for

  1   2   3   4   5   6   7   8   9   10   >