[obv] [patch] debuginfod-client memory hygiene

2025-02-18 Thread Frank Ch. Eigler
Planning to commit this shortly: commit a71bac67f4705b84368b71f5ece54deedaa1abf1 (HEAD -> master1) Author: Frank Ch. Eigler Date: Tue Feb 18 22:09:12 2025 -0500 debuginfod-client: correct invalid free() in failed ima path debuginfod-find with a failed signature configuration was f

[Bug tools/32657] eu-readelf SEGV (buffer over read) in print_string_section (src/readelf.c:13363)

2025-02-18 Thread mark at klomp dot org
https://sourceware.org/bugzilla/show_bug.cgi?id=32657 --- Comment #2 from Mark Wielaard --- Note that someone created CVE-2025-1372 for this bug without following our SECURITY policy: https://sourceware.org/cgit/elfutils/tree/SECURITY This is NOT a security issue according to our policy: Sinc

debuginfod - IMA crypto enforcement status

2025-02-18 Thread Frank Ch. Eigler
Hi - Having upgraded debuginfod.elfutils.org's server to a more modern distro, this machine now can handle the IMA crypto extensions we added to debuginfod not too long ago. It federates to the same debuginfod servers as before, but for those that show "yes" in the "IMA" column, it now applies "i

[Bug libdw/32713] New: elfutils fails to symbolize core dumps created by Linux 6.12+

2025-02-18 Thread michael+sourceware at stapelberg dot ch
https://sourceware.org/bugzilla/show_bug.cgi?id=32713 Bug ID: 32713 Summary: elfutils fails to symbolize core dumps created by Linux 6.12+ Product: elfutils Version: unspecified Status: UNCONFIRMED Severity: nor