stable

krb5-1.21.3-1.fc40

FEDORA-2024-1f68985052 created by jrische a year ago for Fedora 40

This update fixes multiple CVEs and rebases to the latest upstream version:

* Tue Jul 09 2024 Julien Rische <jrische@redhat.com> - 1.21.3-1
- New upstream version (1.21.3)
- CVE-2024-26458: Memory leak in src/lib/rpc/pmap_rmt.c
  Resolves: rhbz#2266732
- CVE-2024-26461: Memory leak in src/lib/gssapi/krb5/k5sealv3.c
  Resolves: rhbz#2266741
- CVE-2024-26462: Memory leak in src/kdc/ndr.c
  Resolves: rhbz#2266743
- Add missing SPDX license identifiers
  Resolves: rhbz#2265333

* Mon Jul 08 2024 Julien Rische <jrische@redhat.com> - 1.21.2-6
- CVE-2024-37370 CVE-2024-37371: GSS message token handling
  Resolves: rhbz#2294678 rhbz#2294680
- Fix double free in klist's show_ccache()
  Resolves: rhbz#2257301
- Do not include files with "~" termination in krb5-tests

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2024-1f68985052

This update has been submitted for testing by jrische.

a year ago

This update's test gating status has been changed to 'waiting'.

a year ago

This update's test gating status has been changed to 'failed'.

a year ago

This update has been pushed to testing.

a year ago
User Icon bojan commented & provided feedback a year ago
karma

Works.

This update's test gating status has been changed to 'waiting'.

a year ago

This update's test gating status has been changed to 'failed'.

a year ago
User Icon kparal commented & provided feedback a year ago

@jrische The update.upgrade_desktop_encrypted_64bit automatic test is known to be broken (a race condition) at the moment, it's safe to waive the gating failure (if there's no other failure) and allow it to go stable.

karma

This update's test gating status has been changed to 'passed'.

a year ago

This update can be pushed to stable now if the maintainer wishes

a year ago
User Icon filiperosset commented & provided feedback a year ago
karma

no regressions noted

This update has been submitted for stable by bodhi.

a year ago

This update has been pushed to stable.

a year ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
3
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
a year ago
in testing
a year ago
in stable
a year ago
approved
a year ago
BZ#2257301 Fix double free in klist's show_ccache() [fedora-all]
0
0
BZ#2265333 Exhaustive SPDX license expression in specfile
0
0
BZ#2266732 TRIAGE CVE-2024-26458 krb5: Memory leak at /krb5/src/lib/rpc/pmap_rmt.c [fedora-all]
0
0
BZ#2266741 TRIAGE CVE-2024-26461 krb5: Memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c [fedora-all]
0
0
BZ#2266743 TRIAGE CVE-2024-26462 krb5: Memory leak at /krb5/src/kdc/ndr.c [fedora-all]
0
0
BZ#2294678 CVE-2024-37370 krb5: GSS message token handling [fedora-all]
0
0
BZ#2294680 CVE-2024-37371 krb5: GSS message token handling [fedora-all]
0
0

Automated Test Results