Backporting a security fix for e2fsprogs to Stable

2019-09-23 Thread Theodore Y. Ts'o
Hi, I just released e2fsprogs v1.45.4 (upstream and for Debian unstable) which among other things, contains a fix[1] for CVE-2019-5094 / TALOS-2019-0887. I imagine Talos will be doing a full disclosure with a proof-of-concept exploit within the next few days. [1] https://git.kernel.org/pub/scm/f

Re: Backporting a security fix for e2fsprogs to Stable

2019-09-23 Thread Salvatore Bonaccorso
Hi Ted, [FTR, this is on the security public discussion list, if you need to contact the security team directly, you might use team@s.d.o or security@d..o] On Mon, Sep 23, 2019 at 07:42:02PM -0400, Theodore Y. Ts'o wrote: > Hi, I just released e2fsprogs v1.45.4 (upstream and for Debian > unstable