[Bug 1597017] Re: mount rules grant excessive permissions

2024-09-16 Thread Launchpad Bug Tracker
This bug was fixed in the package apparmor - 2.13.3-7ubuntu5.4 --- apparmor (2.13.3-7ubuntu5.4) focal-security; urgency=medium * SECURITY UPDATE: Excessive permissions with mount rules (LP: #1597017) - d/p/CVE-2016-1585/parser-Fix-expansion-of-variables-in-unix-rules-addr.patch

[Bug 1597017] Re: mount rules grant excessive permissions

2024-09-16 Thread Launchpad Bug Tracker
This bug was fixed in the package apparmor - 3.0.4-2ubuntu2.4 --- apparmor (3.0.4-2ubuntu2.4) jammy-security; urgency=medium * SECURITY UPDATE: Excessive permissions with mount rules (LP: #1597017) - d/p/CVE-2016-1585/Merge-Fix-mount-rules-encoding.patch: fix mount rules e

[Bug 1597017] Re: mount rules grant excessive permissions

2024-09-16 Thread Mauricio Faria de Oliveira
Autopkgtests preventing migration look good now. All have passed and cleared up in update_excuses (only libreoffice/jammy/armhf running; expecting it to pass based on previous history and results from same package/version in other architectures). Proceeding with release to Jammy and Focal. -- Y

[Bug 1597017] Re: mount rules grant excessive permissions

2024-09-16 Thread Mauricio Faria de Oliveira
** Description changed: + [Impact] + + * The mount rules in apparmor grant excessive permissions. +See Original Report below. + + [Test Plan] + + * https://wiki.ubuntu.com/Process/Merges/TestPlans/AppArmor +See comment 26 for context. + + [Other Info] + SRU Team; the packages for

[Bug 1597017] Re: mount rules grant excessive permissions

2024-09-16 Thread Mauricio Faria de Oliveira
Thanks, Rodrigo! There are outdated autopkgtests (i.e., ran against reverse-test-deps that now have newer versions in -updates), which I triggered reruns for. Once that looks good (hopefully during my shift today, or maybe tomorrow), I'll take a look for release. Details: --- jammy: https://ubu

[Bug 1597017] Re: mount rules grant excessive permissions

2024-09-16 Thread Rodrigo Figueiredo Zaiden
Testing Documentation: This update was tested following the guidelines available at: https://wiki.ubuntu.com/Process/Merges/TestPlans/AppArmor In summary, they are: - AppArmor cache files verification; - Basic Ubuntu login tests: network, browser, apt; - LXC, LXD, Docker basic operations and appa

[Bug 1597017] Re: mount rules grant excessive permissions

2024-09-06 Thread Rodrigo Figueiredo Zaiden
** Tags removed: verification-needed-focal verification-needed-jammy ** Tags added: verification-done-focal verification-done-jammy ** Tags removed: verification-needed ** Tags added: verification-done -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscr

[Bug 1597017] Re: mount rules grant excessive permissions

2024-09-03 Thread Steve Beattie
Actual fixed versions for this issue are still sitting in focal-proposed and jammy-proposed. However, we did a no-change rebuild ofthe current versions in the respective updates pockets to the security pocket, so that the version in proposed could be published first in the updates pocket, but leavi

[Bug 1597017] Re: mount rules grant excessive permissions

2024-09-03 Thread Launchpad Bug Tracker
This bug was fixed in the package apparmor - 2.13.3-7ubuntu5.3build2 --- apparmor (2.13.3-7ubuntu5.3build2) focal-security; urgency=medium * No-change re-build upload for the focal-security pocket as part of the preparation for addressing CVE-2016-1585 (LP: #1597017) -- Steve

[Bug 1597017] Re: mount rules grant excessive permissions

2024-09-03 Thread Launchpad Bug Tracker
This bug was fixed in the package apparmor - 3.0.4-2ubuntu2.3build2 --- apparmor (3.0.4-2ubuntu2.3build2) jammy-security; urgency=medium * No-change re-build upload for the jammy-security pocket as part of the preparation for addressing CVE-2016-1585 (LP: #1597017) -- Steve Be

[Bug 1597017] Re: mount rules grant excessive permissions

2024-08-15 Thread Wesley Hershberger
Hi, gentle ping on this; is there an ETA for this to land in 22.04? Let me know if I can help with testing. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1597017 Title: mount rules grant excessive p

[Bug 1597017] Re: mount rules grant excessive permissions

2024-06-14 Thread Simon Déziel
I've been running this update on Jammy since 2024-04-18 with no visible side effect: $ zgrep -w1 apparmor /var/log/apt/history.log.2.gz Start-Date: 2024-04-18 12:48:18 Commandline: apt install apparmor/jammy-proposed Requested-By: sdeziel (1000) Upgrade: apparmor:amd64 (3.0.4-2ubuntu2.3, 3.0.4-2

[Bug 1597017] Re: mount rules grant excessive permissions

2024-04-09 Thread Brian Murray
Hello John, or anyone else affected, Accepted apparmor into jammy-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/apparmor/3.0.4-2ubuntu2.4 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See https://

[Bug 1597017] Re: mount rules grant excessive permissions

2024-04-03 Thread John Johansen
It is in the SRU queue and the current ETA is April 15 to land in the proposed pocket (archive proposed not security proposed ppa), there is a caveat that the recent xz backdoor has caused some "fun" on the archive side and could potentially cause some delays. -- You received this bug notificatio

[Bug 1597017] Re: mount rules grant excessive permissions

2024-04-02 Thread Achraf Merzouki
Hello, A gentle ping on this issue, it still shows up on jammy security report and looks like 2ubuntu2.3 here https://changelogs.ubuntu.com/changelogs/pool/main/a/apparmor/apparmor_3.0.4-2ubuntu2.3/changelog doesn't have the fix. @jjohansen can we please advise on when the fix will be backported

[Bug 1597017] Re: mount rules grant excessive permissions

2024-03-29 Thread Steve Beattie
** Description changed: + SRU Team; the packages for focal-proposed and jammy-proposed are + intended as security updates prepared by the Ubuntu Security team (and + have built in a ppa with only the security pockets enabled). However, + because the fix makes mount rules in apparmor policy be trea

[Bug 1597017] Re: mount rules grant excessive permissions

2024-03-29 Thread Marc Deslauriers
FYI This is now in the jammy and focal upload queues to go to -proposed. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1597017 Title: mount rules grant excessive permissions To manage notifications

[Bug 1597017] Re: mount rules grant excessive permissions

2024-03-06 Thread Steve Beattie
** Also affects: apparmor (Ubuntu) Importance: Undecided Status: New ** Also affects: apparmor (Ubuntu Jammy) Importance: Undecided Status: New ** Also affects: apparmor (Ubuntu Focal) Importance: Undecided Status: New ** Changed in: apparmor (Ubuntu) Status: