Package: rauc
Version: 1.13-3
Severity: normal
Tags: patch

Dear Maintainer,


An attempt to mount a corrupt verity bundle results in a crash of rauc:

Steps to reproduce:

Create a bundle in verity format.
Manually delete a few bytes in the bundle payload with an editor, so that 
payload size is no longer a multiple of 4KiB.
Attempt to mount the bundle.
Expected: Mount fails with an error message, rauc exits with error.
Observed: Crash in rauc

Bugreport upstream: https://github.com/rauc/rauc/issues/1684
Fix upstream: 
https://github.com/rauc/rauc/pull/1728/commits/c966aefd872293e8b98ced57e135af8ca667acd4
Affected versions: Debian/Bookworm 1.8-2, Debian/Trixie 1.13-3, Debian/Sid 
1.13-3

Same patch is being attached here.

Best,
  Janek

-- System Information:
Debian Release: 13.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Foreign Architectures: armhf, arm64

Kernel: Linux 6.12.27-amd64 (SMP w/6 CPU threads; PREEMPT)
Kernel taint flags: TAINT_SOFTLOCKUP
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_US:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages rauc depends on:
ii  dbus                1.16.2-2
ii  libc6               2.41-8
ii  libcurl3t64-gnutls  8.13.0-5
ii  libfdisk1           2.41-5
ii  libglib2.0-0t64     2.84.2-1
ii  libjson-glib-1.0-0  1.10.6+ds-2
ii  libnl-3-200         3.7.0-2
ii  libnl-genl-3-200    3.7.0-2
ii  libssl3t64          3.5.0-2
ii  systemd             257.6-1

rauc recommends no packages.

Versions of packages rauc suggests:
pn  casync            <none>
pn  cryptsetup-bin    <none>
ii  dosfstools        4.2-1.2
ii  e2fsprogs         1.47.2-1+b1
pn  efibootmgr        <none>
ii  fakeroot          1.37.1.1-1
ii  grub-common       2.12-7
ii  libubootenv-tool  0.3.5-0.1+b2
ii  mtd-utils         1:2.3.0-1
ii  squashfs-tools    1:4.6.1-1
ii  u-boot-tools      2025.01-3+iris3

-- no debconf information

Reply via email to