Bug#1040710: please consider packaging util-linux 2.39 for logger fix

2023-07-10 Thread Marc Haber
On Mon, Jul 10, 2023 at 11:56:01AM +0200, Chris Hofstaedtler wrote:
> * Marc Haber  [230709 20:30]:
> > logger in util-linux 2.38 has a bug that leads to sending uninitialized
> > data to a socket, see https://github.com/util-linux/util-linux/issues/2336
> > 
> > This might be the root cause for adduser's autopkgtests failing on s390x
> > keeping adduser out of testing. In addition, a program should never send
> > uninitialized data.
> 
> By accident I reproduced the same problem on riscv64, so its clearly
> not specific to s390x. Thanks for finding the upstream bug.

Thank you very much for the quick reaction. Praise where praise belongs
to, the upstream bug was discovered by Enrik Berkan on Usenet.

Greetings
Marc

-- 
-
Marc Haber | "I don't trust Computers. They | Mailadresse im Header
Leimen, Germany|  lose things."Winona Ryder | Fon: *49 6224 1600402
Nordisch by Nature |  How to make an American Quilt | Fax: *49 6224 1600421



Bug#1040710: please consider packaging util-linux 2.39 for logger fix

2023-07-10 Thread Chris Hofstaedtler
Hi Marc,

* Marc Haber  [230709 20:30]:
> logger in util-linux 2.38 has a bug that leads to sending uninitialized
> data to a socket, see https://github.com/util-linux/util-linux/issues/2336
> 
> This might be the root cause for adduser's autopkgtests failing on s390x
> keeping adduser out of testing. In addition, a program should never send
> uninitialized data.

By accident I reproduced the same problem on riscv64, so its clearly
not specific to s390x. Thanks for finding the upstream bug.

> The issue in logger is fixed in util-linux 2.39.

I've uploaded 2.38.1-6 with the patch from upstream applied.

Getting 2.39.1 in is a lot more work, so I hope this is an
acceptable stop gap.

Best,
Chris



Bug#1040710: please consider packaging util-linux 2.39 for logger fix

2023-07-09 Thread Marc Haber
Package: util-linux
Version: 2.38.1-5+b1
Severity: normal

Hi,

logger in util-linux 2.38 has a bug that leads to sending uninitialized
data to a socket, see https://github.com/util-linux/util-linux/issues/2336

This might be the root cause for adduser's autopkgtests failing on s390x
keeping adduser out of testing. In addition, a program should never send
uninitialized data.

The issue in logger is fixed in util-linux 2.39.

Please consider packaging the new version.

Thanks in advance!

Greetings
Marc