stable

libxml2-2.10.3-2.fc37 and xmlsec1-1.2.34-4.fc37

FEDORA-2022-a6812b0224 created by amigadave 3 years ago for Fedora 37

Update to 2.10.3

  • Fix CVE-2022-40303
  • Fix CVE-2022-40304

Logout Required
After installing this update it is required that you logout of your current user session and log back in to ensure the changes supplied by this update are applied properly.

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2022-a6812b0224

This update has been submitted for testing by amigadave.

3 years ago

This update's test gating status has been changed to 'waiting'.

3 years ago

This update's test gating status has been changed to 'passed'.

3 years ago

This update has been pushed to testing.

3 years ago
User Icon arkadiuszn commented & provided feedback 3 years ago

This breaks the openconnect: $ openconnect --help openconnect: symbol lookup error: /lib64/libxmlsec1.so.1: undefined symbol: xmlIOFTPRead, version LIBXML2_2.4.30 Similar issue to arch: https://bugs.archlinux.org/task/75721

User Icon arkadiuszn commented & provided feedback 3 years ago
karma

Can confirm that dnf downgrade libxml2 fixes openconnect.

Bodhi is disabling automatic push to stable due to negative karma. The maintainer may push manually if they determine that the issue is not severe.

3 years ago

amigadave edited this update.

New build(s):

  • xmlsec1-1.2.34-3.fc37

Karma has been reset.

3 years ago

This update has been submitted for testing by amigadave.

3 years ago

amigadave edited this update.

New build(s):

  • xmlsec1-1.2.34-4.fc37

Removed build(s):

  • xmlsec1-1.2.34-3.fc37

Karma has been reset.

3 years ago

This update has been pushed to testing.

3 years ago
User Icon kimbisgaard commented & provided feedback 3 years ago

Fixed openconnect bug here :-)

BZ#2136800 openconnect fails due to missing symbol xmlIOFTPRead
User Icon arkadiuszn commented & provided feedback 3 years ago
karma

Can confirm, thank you :)

User Icon ellert provided feedback 3 years ago
karma
BZ#2136800 openconnect fails due to missing symbol xmlIOFTPRead

This update can be pushed to stable now if the maintainer wishes

3 years ago

This update has been submitted for stable by amigadave.

3 years ago
User Icon bojan commented & provided feedback 3 years ago
karma

Works.

amigadave edited this update.

New build(s):

  • GraphicsMagick-1.3.38-4.fc37

Karma has been reset.

3 years ago

This update has been submitted for testing by amigadave.

3 years ago

This update has been pushed to testing.

3 years ago
User Icon mtasaka commented & provided feedback 3 years ago
karma

For now putting negative karma, ImageMagick is also broken at least.

And many other symbols (other than ftp related) are also removed from libxml2, so I am not confident about all affected packages.

User Icon decathorpe commented & provided feedback 3 years ago
karma

Breaking ABI is not OK without rebuilding all dependent packages (if that's even possible), and shouldn't happen so late in the Fedora 37 cycle anyway.

This update has been obsoleted.

3 years ago

adamwill edited this update.

Removed build(s):

  • GraphicsMagick-1.3.38-4.fc37
  • libxml2-2.10.3-1.fc37

Karma has been reset.

3 years ago

adamwill edited this update.

New build(s):

  • libxml2-2.10.3-2.fc37

Karma has been reset.

3 years ago

This update has been submitted for testing by adamwill.

3 years ago
User Icon adamwill commented & provided feedback 3 years ago

-2 should restore the required symbols, thanks to @mtasaka . Some are still missing, but we're hopeful that nothing was actually using them in practice. We've reported https://gitlab.gnome.org/GNOME/libxml2/-/issues/433 upstream.

This update has been pushed to testing.

3 years ago
User Icon dustymabe commented & provided feedback 3 years ago
karma

This fixes the symbols issue for me. Can we get it pushed to stable?

User Icon frantisekz commented & provided feedback 3 years ago
karma

Seems okay now

This update can be pushed to stable now if the maintainer wishes

3 years ago
User Icon mtasaka commented & provided feedback 3 years ago
karma

Looks good.

BZ#2136800 openconnect fails due to missing symbol xmlIOFTPRead

This update has been submitted for stable by mtasaka.

3 years ago

This update has been pushed to stable.

3 years ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
3
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
disabled
Stable by Time
disabled
Dates
submitted
3 years ago
in testing
3 years ago
in stable
3 years ago
modified
3 years ago
BZ#2119077 libxml2-2.10.2 is available
0
0
BZ#2136274 CVE-2022-40303 libxml2: integer overflows with XML_PARSE_HUGE [fedora-all]
0
0
BZ#2136293 CVE-2022-40304 libxml2: dict corruption caused by entity reference cycles [fedora-all]
0
0
BZ#2136800 openconnect fails due to missing symbol xmlIOFTPRead
0
1

Automated Test Results