[Bug 1352007] Re: avconv crashed with SIGSEGV in paint_mouse_pointer()

2021-09-30 Thread Steve Beattie
** Information type changed from Private to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1352007 Title: avconv crashed with SIGSEGV in paint_mouse_pointer() To manage notifications about th

[Bug 1368481] Re: avconv assert failure: avconv: /build/buildd/libav-11~beta1/libavcodec/put_bits.h:139: put_bits: Assertion `n <= 31 && value < (1U << n)' failed.

2021-09-30 Thread Steve Beattie
** Information type changed from Private to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1368481 Title: avconv assert failure: avconv: /build/buildd/libav-11~beta1/libavcodec/put_bits.h:13

[Bug 980943] Re: ffmpeg crashed with SIGSEGV in __libc_start_main()

2021-09-30 Thread Steve Beattie
** Attachment removed: "CoreDump.gz" https://bugs.launchpad.net/ubuntu/+source/libav/+bug/980943/+attachment/3059934/+files/CoreDump.gz ** Information type changed from Private to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscrib

[Bug 1928648] Re: expiring trust anchor compatibility issue

2021-09-30 Thread Steve Beattie
Ack from the Ubuntu Security team for both gnutls28 3.5.18-1ubuntu1.5 and 3.4.10-4ubuntu1.9 to go to bionic-security and xenial-security respectively. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928

[Bug 1943960] Re: s390x BPF JIT vulnerabilities

2021-09-22 Thread Steve Beattie
** Description changed: [Impact] s390 BPF JIT vulnerabilities allow the eBPF verifier to be bypassed, leading to possible local privilege escalation. [Mitigation] Disable unprivileged eBPF. sysctl -w kernel.unprivileged_bpf_disabled=1 [Potential regression] BPF programs might

[Bug 1943960] Re: s390x BPF JIT vulnerabilities

2021-09-22 Thread Steve Beattie
Commits to address this are upstream in Linus' tree; they are: 1511df6f5e9e ("s390/bpf: Fix branch shortening during codegen pass") 6e61dc9da0b7 ("s390/bpf: Fix 64-bit subtraction of the -0x8000 constant") db7bee653859 ("s390/bpf: Fix optimizing out zero-extensions") -- You received th

[Bug 1929105] Re: CVE-2021-3326: The iconv app in glibc when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion & aborts

2021-09-17 Thread Steve Beattie
** Bug watch added: Sourceware.org Bugzilla #27256 https://sourceware.org/bugzilla/show_bug.cgi?id=27256 ** Also affects: glibc via https://sourceware.org/bugzilla/show_bug.cgi?id=27256 Importance: Unknown Status: Unknown -- You received this bug notification because you are a me

[Bug 1863299] Re: linux-aws fails to late load microcode, works with generic

2021-09-14 Thread Steve Beattie
Is this worth addressing in the cloud kernels or should we stick to early microcode loads only? ** Changed in: linux-aws (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.

[Bug 1939946] Re: bug

2021-09-14 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1942673] Re: glibc AddressSanitizer:DEADLYSIGNAL

2021-09-14 Thread Steve Beattie
** Information type changed from Private Security to Public Security ** Package changed: glibc (Ubuntu) => pcre2 (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1942673 Title: glibc AddressS

[Bug 1942661] Re: package libitm1:amd64 10.3.0-1ubuntu1~20.04 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting configuration

2021-09-14 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1942714] Re: package grub-pc 2.02-2ubuntu8.23 failed to install/upgrade: installed grub-pc package post-installation script subprocess returned error exit status 128

2021-09-14 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1942914] Re: latte-dock crashed with SIGABRT in qt_message_fatal()

2021-09-14 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1942927]

2021-09-14 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 1942927] Re: claws-mail package outdated (security risk)

2021-09-14 Thread Steve Beattie
Looks like https://git.claws- mail.org/?p=claws.git;a=commit;h=ac286a71ed78429e16c612161251b9ea90ccd431 is the upstream commit to address the issue. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/194292

[Bug 1942923] Re: CVE-2021-38604: sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference

2021-09-14 Thread Steve Beattie
** Changed in: glibc (Ubuntu) Status: New => Confirmed ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1942923 Title: CVE-2

[Bug 1942927] Re: claws-mail package outdated (security risk)

2021-09-14 Thread Steve Beattie
** Also affects: sylpheed (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1942927 Title: claws-mail package outdated (security risk) To manage not

[Bug 1943063] Re: package bcfg2 (not installed) failed to install/upgrade: subprocess installed post-installation script returned error exit status 128

2021-09-14 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1943056] Re: package bcfg2-server (not installed) failed to install/upgrade: 子进程 已安装 post-installation 脚本 返回错误状态 1

2021-09-14 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1943192] Re: package phpmyadmin 4:4.9.5+dfsg1-2 failed to install/upgrade: installed phpmyadmin package post-installation script subprocess returned error exit status 1

2021-09-14 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1943328] Re: display 1920x1080 not showing in setting

2021-09-14 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1943252] Re: crashed towards the end of Initial install

2021-09-14 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1943439] Re: package grub-common 2.04-1ubuntu26.13 failed to install/upgrade: subproces van pakket grub-common werd script post-installation geïnstalleerd gaf de foutwaarde 1 terug

2021-09-14 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1943417] Re: Xorg freeze

2021-09-14 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1928888] Re: test_utils_testsuite from ubuntu_qrt_apparmor linux ADT test failure with linux/5.11.0-18.19

2021-09-07 Thread Steve Beattie
** Changed in: linux (Ubuntu) Status: Incomplete => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/192 Title: test_utils_testsuite from ubuntu_qrt_apparmor linux ADT test failure

[Bug 1928888] Re: test_utils_testsuite from ubuntu_qrt_apparmor linux ADT test failure with linux/5.11.0-18.19

2021-08-26 Thread Steve Beattie
This is due to apparmor in hirsute missing the fix for https://gitlab.com/apparmor/apparmor/-/merge_requests/656 which breaks the apparmor python utils testsuite; the fix for this has landed in impish's apparmor package. We are unlikely to SRU a fix for this in hirsute, so have worked around it in

[Bug 1938893] Re: Network perpherals not detected

2021-08-25 Thread Steve Beattie
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1938893 Title: Network perpherals not detected To manage notifications about this bug go to:

[Bug 1940132] Re: speech-dispatcher crashed with SIGABRT in __vfprintf_internal()

2021-08-25 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1940133] Re: gnome-shell crashed with SIGSEGV in __strlen_avx2()

2021-08-25 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1940135] Re: gvfsd-fuse crashed with SIGABRT in __vfprintf_internal()

2021-08-25 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1940202] Re: touchpad

2021-08-25 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1940333] Re: package kerneloops 0.12+git20140509-6ubuntu3 failed to install/upgrade: el subproceso instalado paquete kerneloops script post-installation devolvió el código de salida de error 1

2021-08-25 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1940643] Re: atualização da versão 21.10

2021-08-25 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1941606] Re: i can not login my on account

2021-08-25 Thread Steve Beattie
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see https://wiki.ubuntu.

[Bug 1929105] Re: CVE-2021-3326: The iconv app in glibc when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion & aborts

2021-08-25 Thread Steve Beattie
Groovy has reached end of supported status, and as such will not be fixed. ** Changed in: glibc (Ubuntu Groovy) Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1929105 T

[Bug 1928989] Re: expiring trust anchor compatibility issue

2021-08-19 Thread Steve Beattie
The Ubuntu Security Team is okay with publishig the xenial openssl in proposed (1.0.2g-1ubuntu4.20) to xenial-security and updates. I didn't see any symbol changes or dependency changes in the binaries that would have indicated that building against xenial-updates was a problem. Thanks! -- You r

[Bug 1933980] Re: NVIDIA CVE-2021-{1093|1094|1094}

2021-08-10 Thread Steve Beattie
** Changed in: linux (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1933980 Title: NVIDIA CVE-2021-{1093|1094|1094} To manage notifications about this bug go t

[Bug 1936468] Re: lenove

2021-08-10 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1936468] Re: lenove

2021-08-10 Thread Steve Beattie
This seems to have been the failure in the grub-install attempt: Jul 16 06:19:37 ubuntu grub-installer: info: Installing grub on '/dev/nvme0n1' Jul 16 06:19:37 ubuntu grub-installer: info: grub-install does not support --no-floppy Jul 16 06:19:37 ubuntu grub-installer: info: Running chroot /targe

[Bug 1939265] Re: Having graphic driver error.

2021-08-10 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1939299] Re: Could not determine the upgrade

2021-08-10 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1939330] Re: package ubuntu-advantage-tools 27.2.2~16.04.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2021-08-10 Thread Steve Beattie
*** This bug is a duplicate of bug 1938290 *** https://bugs.launchpad.net/bugs/1938290 Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a

[Bug 1939391] Re: package muffin-common 4.4.3-1ubuntu0.1 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting a removal

2021-08-10 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1935899] Re: package nvidia-dkms-460 460.80-0ubuntu0.20.10.2 failed to install/upgrade: installed nvidia-dkms-460 package post-installation script subprocess returned error exit status 1

2021-07-29 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1938130] Re: streamtuner2 crashed with AttributeError in drop(): 'GdkWaylandDragContext' object has no attribute 'targets'

2021-07-29 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1938223] Re: package nvidia-340 (not installed) failed to install/upgrade: trying to overwrite '/usr/bin/nvidia-bug-report.sh', which is also in package nvidia-utils-460 460.91.03-0ubuntu0.20.04.

2021-07-29 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1938290] Re: package ubuntu-advantage-tools 27.2.2~16.04.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2021-07-29 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1796402] Re: systemd: reexec state injection: fgets() on overlong lines leads to line splitting

2021-07-28 Thread Steve Beattie
This was fixed in Ubuntu packages in https://ubuntu.com/security/notices/USN-3816-1 ; adjusting the state to reflect that a fix was released. Thanks. ** Changed in: systemd (Ubuntu) Status: Invalid => Fix Released -- You received this bug notification because you are a member of Ubuntu B

[Bug 1928989] Re: expiring trust anchor compatibility issue

2021-07-21 Thread Steve Beattie
Assigning the verification and publication to xenial-security to myself. Thanks. ** Changed in: openssl (Ubuntu Xenial) Assignee: (unassigned) => Steve Beattie (sbeattie) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. ht

[Bug 1907284] Re: [MIR] u-boot-menu

2021-07-16 Thread Steve Beattie
Łukasz, the Ubuntu Security Team is indeed okay with promoting this to main for focal as well. Thanks. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1907284 Title: [MIR] u-boot-menu To manage notif

[Bug 1926250] Re: CVE-2021-31826: Session recovery feature contains a null pointer deference

2021-07-02 Thread Steve Beattie
ed in: shibboleth-sp (Ubuntu) Status: New => In Progress ** Changed in: shibboleth-sp (Ubuntu) Assignee: (unassigned) => Steve Beattie (sbeattie) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/b

[Bug 1932331] Re: ubuntu_qrt_apparmor: i18n test fails on arm64 Hirsute / Impish

2021-06-30 Thread Steve Beattie
The root issue is likely something in the utf-8 handling code in glibc on arm64 hirsute and impish; the reproducer is: bash -c 'i=210; echo -n $(printf "\\$(printf "%03o" $i)") | od -An -t uC' 210 138 running valgrind in a default environemnt (so LANG=en_US.UTF-8) turned up ==46656== ERROR S

[Bug 1932331] Re: ubuntu_qrt_apparmor: i18n test fails on arm64 Hirsute / Impish

2021-06-30 Thread Steve Beattie
Georgia's patch was committed in the upstream apparmor project in https://gitlab.com/apparmor/apparmor/-/commit/458a981b6242e8b1cce1599ca95d89dcd10f60e7 in https://gitlab.com/apparmor/apparmor/-/merge_requests/765 and was cherrypicked to the apparmor-3.0 branch amongst others in https://gitlab.com/

[Bug 1932331] Re: ubuntu_qrt_apparmor: i18n test fails on arm64 Hirsute / Impish

2021-06-29 Thread Steve Beattie
** Also affects: apparmor (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1932331 Title: ubuntu_qrt_apparmor: i18n test fails on arm64 Hirsute / Im

[Bug 1917509] Re: Call for testing: grub2 security updates

2021-06-26 Thread Steve Beattie
These have all been published to the security pockets for bionic and newer, closing out this bug.b ** Changed in: grub2 (Ubuntu) Status: Confirmed => Fix Released ** Changed in: grub2-signed (Ubuntu) Status: Confirmed => Fix Released ** Changed in: grub2-unsigned (Ubuntu) St

[Bug 1929179] Re: [SRU] ceph 15.2.12

2021-06-24 Thread Steve Beattie
** Changed in: ceph (Ubuntu Focal) Assignee: (unassigned) => Steve Beattie (sbeattie) ** Changed in: ceph (Ubuntu Groovy) Assignee: (unassigned) => Steve Beattie (sbeattie) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

Re: [Bug 1911893] Re: latest microcode is not working properly on intel core i9

2021-06-22 Thread Steve Beattie
s for the Ubuntu 20.04.3 release media. -- Steve Beattie -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1911893 Title: latest microcode is not working properly on intel core i9 To manage notification

Re: [Bug 1911893] Re: latest microcode is not working properly on intel core i9

2021-06-22 Thread Steve Beattie
al-security/focal-updates is 3.20210608.0ubuntu0.20.04.1: https://launchpad.net/ubuntu/+source/intel-microcode -- Steve Beattie -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1911893 Title: lates

[Bug 1930921] Re: Apache 2.4.41 corrupts files from samba share

2021-06-08 Thread Steve Beattie
** Changed in: apache2 (Ubuntu) Status: New => Confirmed ** Changed in: samba (Ubuntu) Status: New => Confirmed ** Changed in: linux (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubunt

[Bug 1923527] Re: Null Pointer Dereference in function Reserve in p7zip when input craft rar file

2021-06-08 Thread Steve Beattie
Thanks, given the public commits, I'm making this issue public. ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1923527 Title: Nul

[Bug 1929105] Re: CVE-2021-3326: The iconv app in glibc when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion & aborts

2021-06-08 Thread Steve Beattie
This is fixed in hirsute and newer via glibc 2.33. ** Changed in: glibc (Ubuntu) Importance: Undecided => Low ** Also affects: glibc (Ubuntu Bionic) Importance: Undecided Status: New ** Also affects: glibc (Ubuntu Focal) Importance: Undecided Status: New ** Also affects:

[Bug 1928620] Re: segmentation fault(core dumped)

2021-06-08 Thread Steve Beattie
** Changed in: codeblocks (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1928620 Title: segmentation fault(core dumped) To manage notifications abou

[Bug 1929540] Re: package aidl (not installed) failed to install/upgrade: trying to overwrite '/usr/bin/aidl', which is also in package google-android-build-tools-installer 23.0.3+r1

2021-06-08 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1931251] Re: package nvidia-kernel-common-390 390.143-0ubuntu0.20.04.1 failed to install/upgrade: installed nvidia-kernel-common-390 package post-installation script subprocess returned error exi

2021-06-08 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1152187] Re: [MIR] systemd

2021-05-27 Thread Steve Beattie
Yes, the systemd-container package will end up in main, likely for the current package in bionic-updates, and thus will be reflected that way in rmadison etc. For the record, ack from the Ubuntu Security Team on promoting the systemd-container binary from universe to main in bionic. Thanks. --

[Bug 1921211] Re: Taking a memory dump of user mode process on Xenial hosts causes bugcheck/kernel panic and core dump

2021-05-18 Thread Steve Beattie
This was fixed with linux 4.4.0-211.243 in Ubuntu 16.04 ESM (Infra). ** Changed in: linux (Ubuntu Xenial) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/192

[Bug 1879341] Re: test_350_retpolined_modules from ubuntu_qrt_kernel_security failed on F-OEM-5.6

2021-05-18 Thread Steve Beattie
** Changed in: linux-oem-5.6 (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1879341 Title: test_350_retpolined_modules from ubuntu_qrt_kernel_security failed

[Bug 1928877] [NEW] Please remove rhc from the archive

2021-05-18 Thread Steve Beattie
Public bug reported: The ruby based command line tools for interacting with openshift have been deprecated to the point that the upstream project has been archived on github: https://github.com/openshift/rhc The replacement is https://github.com/openshift/oc/ which alas does not appear to

[Bug 1927755] Re: Fix for CVE-2020-28007 causes build failure when DMARC is enabled

2021-05-18 Thread Steve Beattie
** Changed in: exim4 (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1927755 Title: Fix for CVE-2020-28007 causes build failure when DMARC is enabled To manag

[Bug 1926926] Re: CVE-2021-27928 et al affects MariaDB in Ubuntu

2021-05-18 Thread Steve Beattie
** Changed in: mariadb-10.5 (Ubuntu Impish) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1926926 Title: CVE-2021-27928 et al affects MariaDB in Ubuntu To manage not

[Bug 1928694] Re: [Cezanne/Renoire]: Replace some fixes from linux-oem-5.10 with those landing upstream

2021-05-18 Thread Steve Beattie
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928694 Title: [Cezanne/Renoire]: Replace some fixes from linux-oem-5.10 with those landin

[Bug 1927409] Re: Race between two functions

2021-05-11 Thread Steve Beattie
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1927409 Title: Race between two functions To manage notifications about this bug g

[Bug 1879339] Re: test_310_config_security_perf_events_restrict / test_400_refcount_config in ubuntu_qrt_kernel_security failed on F-OEM-5.6

2021-05-10 Thread Steve Beattie
Sorry for the lag on this issue. Timo, while the added hooks are useful, they don't for the time being obviate the need for the larger hammer of the sysctl, so we'd still like to keep the referred to patch available, until we are forced to make a choice if and when upstream drops the sysctl entire

[Bug 1879341] Re: test_350_retpolined_modules from ubuntu_qrt_kernel_security failed on F-OEM-5.6

2021-05-10 Thread Steve Beattie
Hi, this looks like a legit issue with the linux-oem-5.6 da903x- regulator module, which appears to have been addressed in f16861b12fa0 ("regulator: rename da903x to da903x-regulator") (v5.8-rc6), which points out that kmod gets confused before that commit. You can verify this with e.g.: $ modi

[Bug 1927078] Re: Don't allow useradd to use fully numeric names

2021-05-10 Thread Steve Beattie
The Ubuntu Security team is +1 on disallowing purely numeric usernames, as they are too easily confused with UIDs. I think our preference would be to disallow leading numeric digits entirely so that for example, 0x0 and 0o0 would be blocked as well, to try to prevent both user and programmatic con

[Bug 1755310] Re: MIR libzstd

2021-04-22 Thread Steve Beattie
Ack from the Ubuntu Security team for moving libztsd into main in xenial. (There is a third CVE believed to be affecting libzstd/xenial as well, CVE-2019-11922) ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2019-11922 -- You received this bug notification because you are a member

[Bug 1925411] [NEW] apparmor adt test failure blocking tcpdump migration

2021-04-21 Thread Steve Beattie
Public bug reported: tcpdump has a sync from debian 4.99.0-2 that is currently blocked in hirsute-proposed due to a regression in the apparmor adt tests. The reason for this failure is that 'compile-policy' testcase is failing; this test ensures that various apparmor policies included in packages

[Bug 1909937] Re: Physical Ethernet interfaces leak MAC addresses on link up

2021-04-20 Thread Steve Beattie
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1909937 Title: Physical Ethernet interfaces leak MAC addresses on link up To manag

[Bug 1913976] Re: light-locker fails to lock screen

2021-04-20 Thread Steve Beattie
Hi, looking at your package dependencies, there are a bunch of "oibaf" originating packages in the display stack. Can you confirm that you see the same behavior on a system with packages solely originating from the Ubuntu archive? Thanks. ** Changed in: light-locker (Ubuntu) Status: New =

[Bug 1919419] Re: Phishing vulnerability: Template generation allows external parameters to override placeholders

2021-04-20 Thread Steve Beattie
** Changed in: shibboleth-sp (Ubuntu) Status: New => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1919419 Title: Phishing vulnerability: Template generation allows external param

[Bug 1921585] Re: Screen contents visible when switching between logged in users using CTrl + Alt + Fx

2021-04-20 Thread Steve Beattie
** Changed in: gdm3 (Ubuntu) Status: New => Incomplete ** Changed in: gnome-shell (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1921585 Title: Scree

[Bug 1923320] Re: lot's of teminal command run every time i turn on the system

2021-04-20 Thread Steve Beattie
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1923320 Title: lot's of teminal command run every time i turn on the system To manage noti

[Bug 1923538] Re: jhead heap-buffer-overflow of exif.c in function Get16u

2021-04-20 Thread Steve Beattie
** Changed in: jhead (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1923538 Title: jhead heap-buffer-overflow of exif.c in function Get16u To manage notifica

[Bug 1895839] Re: CVE-2020-24977

2021-04-12 Thread Steve Beattie
Please note that upstream has indicated that this issue only affects the xmllint binary, and not the shared library. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1895839 Title: CVE-2020-24977 To m

Re: [Bug 1923432] Re: apparmor-utils: missing CAP_CHECKPOINT_RESTORE in /etc/apparmor/severity.db

2021-04-12 Thread Steve Beattie
ches can be dropped that much easier. Thanks. -- Steve Beattie -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1923432 Title: apparmor-utils: missing CAP_CHECKPOINT_RESTORE in /etc/apparmor/severity.db

Re: [Bug 1923432] [NEW] apparmor-utils: missing CAP_CHECKPOINT_RESTORE in /etc/apparmor/severity.db

2021-04-12 Thread Steve Beattie
://gitlab.com/apparmor/apparmor/-/commit/80efc15e18a6bb0d0abd2821cb03bf6be51cc517 This should be safe to cherrypick for hirsute. (Similar cherrypicks occurred for prior AppArmor branches.) -- Steve Beattie -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1918482] Re: Update for CVE-2021-21381

2021-04-07 Thread Steve Beattie
** Summary changed: - Update for GHSA-xgh4-387p-hqpp + Update for CVE-2021-21381 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1918482 Title: Update for CVE-2021-21381 To manage notifications abou

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-04-07 Thread Steve Beattie
Hi Fabio and Joshua, thanks for preparing these updates. I have reviewed them, adjusted the changelogs slightly, and have uploaded packages to the ubuntu-security-proposed ppa https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages to make them available for testing. Any tes

[Bug 1918482] Re: Update for GHSA-xgh4-387p-hqpp

2021-04-07 Thread Steve Beattie
. Any feedback on them would be greatly appreciated. Thanks ** Changed in: flatpak (Ubuntu Bionic) Assignee: Andrew Hayzen (ahayzen) => Steve Beattie (sbeattie) ** Changed in: flatpak (Ubuntu Focal) Assignee: Andrew Hayzen (ahayzen) => Steve Beattie (sbeattie) ** Changed in: f

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-04-07 Thread Steve Beattie
Thanks, I'm taking a look at these. I've adjusted the versions to imclude per-release versions, since focal and groovy had the same version of caribou. ** Changed in: caribou (Ubuntu Focal) Assignee: Joshua Peisach (itzswirlz) => Steve Beattie (sbeattie) ** Changed in: ca

[Bug 1922596] Re: linux ADT test failure with linux/4.4.0-208.240

2021-04-06 Thread Steve Beattie
This was merged into q-r-t in https://git.launchpad.net/qa-regression- testing/commit/?id=c1af010b49291e5526ccac85cd1fd334fa3bd0c5 . Until this actually makes into a kernel in updates/security, the test will fail for those kernels. Worth keeping in mind if we have to do any respins. Thanks! ** C

[Bug 1921134] Re: SBAT shim 15.4 release

2021-04-02 Thread Steve Beattie
** Changed in: shim (Ubuntu) Status: New => Confirmed ** Changed in: shim-signed (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1921134 Title: SBAT sh

[Bug 1918312] Re: group changes don't show up in kerberizedd mounts

2021-04-02 Thread Steve Beattie
(Bah, didn't realize the original link contained the full thread as well.) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1918312 Title: group changes don't show up in kerberizedd mounts To manage n

[Bug 1918312] Re: group changes don't show up in kerberizedd mounts

2021-04-02 Thread Steve Beattie
Hey Charles, Apologies for the lack of response earlier. I see that you have gone ahead and reported this issue to upstream at https://lore.kernel.org/linux-nfs/cc0f1034-8572-4556-8351-284999032...@rutgers.edu/ This response explains why things take a long time or don't show up at all: https:/

[Bug 1922160] Re: installstion

2021-04-02 Thread Steve Beattie
It seems like the EFI partition does not have enough free space? Apr 1 01:40:20 ubuntu grub-installer: info: Identified partition label for /dev/sdb2: msdos Apr 1 01:40:20 ubuntu grub-installer: info: Installing grub on '/dev/sdb' Apr 1 01:40:20 ubuntu grub-installer: info: grub-install does n

[Bug 1922160] Re: installstion

2021-04-02 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1922223] Re: package kerneloops 0.12+git20140509-6ubuntu2 failed to install/upgrade: installed kerneloops package post-installation script subprocess returned error exit status 1

2021-04-02 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1922225] Re: error

2021-04-02 Thread Steve Beattie
It seems like the EFI partition might have run out of space? Apr 1 10:45:21 ubuntu grub-installer: info: Identified partition label for /dev/sda6: msdos Apr 1 10:45:21 ubuntu grub-installer: info: Installing grub on '/dev/sda5' Apr 1 10:45:21 ubuntu grub-installer: info: grub-install does not

[Bug 1922225] Re: error

2021-04-02 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1918892] Re: near the end of installation the installer displayed the message "Executing 'grub-install/dev/sda' failed. This is a fatal error."

2021-03-30 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

<    1   2   3   4   5   6   7   8   9   10   >