Your message dated Fri, 12 Jul 2024 12:04:44 +0000
with message-id <[email protected]>
and subject line Bug#1075990: fixed in bamtools 2.5.2+dfsg-6
has caused the Debian Bug report #1075990,
regarding bamtools corrupts output data on bigendian architectures
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1075990: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1075990
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: bamtools
Version: 2.5.2+dfsg-4
Severity: normal

Dear Maintainer,

In Ubuntu the autopkgtest fails due to the buffer overflow detected[1]

with the following stack trace:
(gdb) where
#0 __pthread_kill_implementation (threadid=<optimized out>,
signo=signo@entry=6, no_tid=no_tid@entry=0) at pthread_kill.c:44
#1 0x000003fff789fd56 in __pthread_kill_internal (signo=6, threadid=<optimized
out>) at pthread_kill.c:78
#2 0x000003fff784ba90 in __GI_raise (sig=sig@entry=6) at
../sysdeps/posix/raise.c:26
#3 0x000003fff782b4cc in __GI_abort () at abort.c:79
#4 0x000003fff78921f8 in __libc_message_impl (fmt=fmt@entry=0x3fff79a428e "***
%s ***: terminated\n") at ../sysdeps/posix/libc_fatal.c:132
#5 0x000003fff792a50c in __GI___fortify_fail (msg=msg@entry=0x3fff79a424a
"buffer overflow detected") at fortify_fail.c:24
#6 0x000003fff7929d38 in __GI___chk_fail () at chk_fail.c:28
#7 0x000003fff792adae in __GI___memcpy_chk (dstpp=dstpp@entry=0x2aa000ab261,
srcpp=srcpp@entry=0x3ffffff99b4, len=len@entry=4, dstlen=dstlen@entry=3) at
memcpy_chk.c:27
#8 0x000003fff7e2b6ba in memcpy (__len=4, __src=0x3ffffff99b4,
__dest=0x2aa000ab261) at /usr/include/s390x-linux-
gnu/bits/string_fortified.h:29
#9 BamTools::SwapEndian_32p (data=0x2aa000ab261 "") at
/usr/src/bamtools-2.5.2+dfsg-5/src/api/BamAux.h:229
#10 BamTools::Internal::BamWriterPrivate::WriteAlignment (this=0x2aa000890d0,
al=...) at
/usr/src/bamtools-2.5.2+dfsg-5/src/api/internal/bam/BamWriter_p.cpp:353
#11 0x000003fff7e1445c in BamTools::Internal::BamWriterPrivate::SaveAlignment
(al=..., this=0x2aa000890d0) at
/usr/src/bamtools-2.5.2+dfsg-5/src/api/internal/bam/BamWriter_p.cpp:263
#12 BamTools::BamWriter::SaveAlignment (this=<optimized out>, alignment=...) at
/usr/src/bamtools-2.5.2+dfsg-5/src/api/BamWriter.cpp:131
#13 0x000002aa00035f08 in BamTools::RevertTool::RevertToolPrivate::Run() ()
#14 0x000002aa0003e3fe in BamTools::RevertTool::Run(int, char**) ()
#15 0x000002aa0001017a in main ()
(gdb) print i
$1 = 17

This is due to the write loop in src/api/internal/bam/BamWriter_p.cpp using
single byte instead of sizeof(uint32_t) increment to swap bytes in the integer
data.

The output file on s390x is corrupted.

[1]
https://objectstorage.prodstack5.canonical.com/swift/v1/AUTH_0f9aae918d5b4744bf7b827671c86842/autopkgtest-
oracular/oracular/s390x/b/bamtools/20240701_175546_4de2a@/log.gz


-- System Information:
Debian Release: trixie/sid
  APT prefers noble-updates
  APT policy: (500, 'noble-updates'), (500, 'noble-security'), (500, 'noble'), 
(100, 'noble-backports')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.8.0-36-generic (SMP w/32 CPU threads; PREEMPT)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE, 
TAINT_UNSIGNED_MODULE
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

--- End Message ---
--- Begin Message ---
Source: bamtools
Source-Version: 2.5.2+dfsg-6
Done: Andreas Tille <[email protected]>

We believe that the bug you reported is fixed in the latest version of
bamtools, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Andreas Tille <[email protected]> (supplier of updated bamtools package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 12 Jul 2024 13:46:23 +0200
Source: bamtools
Architecture: source
Version: 2.5.2+dfsg-6
Distribution: unstable
Urgency: medium
Maintainer: Debian Med Packaging Team 
<[email protected]>
Changed-By: Andreas Tille <[email protected]>
Closes: 1075990
Changes:
 bamtools (2.5.2+dfsg-6) unstable; urgency=medium
 .
   * Fix output data on bigendian architectures (Thanks a lot for the
     patch from Vladimir Petko <[email protected]>!)
     Closes: #1075990
   * Standards-Version: 4.7.0 (routine-update)
   * Build-Depends: s/pkg-config/pkgconf/
Checksums-Sha1:
 1e65d3c92bce3d0661b9a816009ba51ac525e5b7 2387 bamtools_2.5.2+dfsg-6.dsc
 7cc3351c7180b79fd41ffb7c49da5260689c9987 11368 
bamtools_2.5.2+dfsg-6.debian.tar.xz
 a87976c15563f90823ad518cebdcc6c8ea81dc2b 8866 
bamtools_2.5.2+dfsg-6_amd64.buildinfo
Checksums-Sha256:
 01b617ae6af45156a7052d289c8d28126f55007b1835b85d79a2004a5a36c26c 2387 
bamtools_2.5.2+dfsg-6.dsc
 e4c667cb47d93420c0473c6f674d8a138a1e64362aeca55b81341aeb7e353785 11368 
bamtools_2.5.2+dfsg-6.debian.tar.xz
 769152a8434b477265317b2e131b9928c36d80a4300d6efa65f881a32e746857 8866 
bamtools_2.5.2+dfsg-6_amd64.buildinfo
Files:
 08b33e62557aebcba23851a8693231cb 2387 science optional 
bamtools_2.5.2+dfsg-6.dsc
 c495be9488890186b00051d0a63c21a9 11368 science optional 
bamtools_2.5.2+dfsg-6.debian.tar.xz
 efb6ad0fe78fef582b78dafda212ee8b 8866 science optional 
bamtools_2.5.2+dfsg-6_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJFBAEBCgAvFiEE8fAHMgoDVUHwpmPKV4oElNHGRtEFAmaRGHQRHHRpbGxlQGRl
Ymlhbi5vcmcACgkQV4oElNHGRtEpwg//Y3q8VGHNyJegLk0+q+rU9x0bQhRJx/N5
lop+OqlVDphXUeRdrsbIN+WsLAz05Nr8D+Q9FIEmMu7EwJgFoBG1vQJCr42EbLhI
BMP4kaSTm0tyDslLlOhTOPqa6fhxMRzAAzTEIG3rDnDxXZsb7N3kl2p17kWJGmQi
MceM9Sr85NWIo+f+rmRDsVIzVX2WQgOM7mTHKuY6j1qU6t9DpnE+F6lAThNMjpFK
ZD8ttlpsQS8XlZBQgECnlW3ZPnjmctaluy3PPFmlrznxfk0K2kj2ps67HT69UT3D
x7CwaZaG1yDJt0rxMo7MAn6b7PvQI33Cckn7MRyB4OnJll6psGSTNmM84ujmp7C3
YZMwNtcjYgYpi+O7WFUFeXzxmEZoLO+HIq86DCQG3FX0ZAPxV5XaWr3KcZRzpaxd
FNE/EZR1O4hHcvPB2NGOYbhYFo3PvrAtl9sHXg6Cy4x5vC1kZIeMbOTx7s5Ac1an
l3R6zi5fkYYl0DOq40Cbp3jjfS5J4eW3pijzwFbDyOgS79C/J+pxpfpho5Y4nKLb
8LvRI4XZOg33zAauCqTPD/0+BFvRrXJggnoUCZxJOh1z2gvqG2ORDLnzmypAKSUm
iaaRfOVvSCo4ExlD9dZemXhnUnKsPs8OiDfDXuq+ekB12lt8g9uMLB4TVTaR08Aw
UAljNGFL7DQ=
=vXJJ
-----END PGP SIGNATURE-----

Attachment: pgpKi6XI4GEvA.pgp
Description: PGP signature


--- End Message ---

Reply via email to