[Bug 2117112] Re: 421 Misdirected Request: apache2 regression

2025-07-21 Thread Marc Deslauriers
Here is the upstream bug tracking this issue: https://bz.apache.org/bugzilla/show_bug.cgi?id=69743 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2117112 Title: 421 Misdirected Request: apache2 regr

[Bug 2117112] Re: 421 Misdirected Request: apache2 regression

2025-07-21 Thread Marc Deslauriers
** Bug watch added: bz.apache.org/bugzilla/ #69743 https://bz.apache.org/bugzilla/show_bug.cgi?id=69743 ** Also affects: apache2 via https://bz.apache.org/bugzilla/show_bug.cgi?id=69743 Importance: Unknown Status: Unknown -- You received this bug notification because you are a me

[Bug 2115907] Re: Unexpected ClamAV Major Upgrade in LTS (jammy) via ubuntu-security

2025-07-03 Thread Marc Deslauriers
*** This bug is a duplicate of bug 2115847 *** https://bugs.launchpad.net/bugs/2115847 We regularly update ClamAV versions in ubuntu when upstream support for it is no longer available, as when a release goes EOL it is no longer possible to download database updates. In this case, ClamAV 0.10

[Bug 2115847] Re: Jammy clamav-daemon no longer listening on TCP port after upgrade to 1.4.3+dfsg-0ubuntu0.22.04.1 (jammy-security)

2025-07-03 Thread Marc Deslauriers
The jammy update was based on the packaging from later Ubuntu releases. Unfortunately, you are right, it does look like it is lacking proper socket migration. To enable the socket with the jammy update, please create a file at /etc/systemd/system/clamav-daemon.socket.d/tcp-socket.conf containing:

[Bug 2115847] Re: Jammy clamav-daemon no longer listening on TCP port after upgrade to 1.4.3+dfsg-0ubuntu0.22.04.1 (jammy-security)

2025-07-03 Thread Marc Deslauriers
** Bug watch added: Debian Bug tracker #1042377 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1042377 ** Also affects: clamav (Debian) via https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1042377 Importance: Unknown Status: Unknown -- You received this bug notification becau

[Bug 2114945] Re: block less common filesystems by default

2025-06-25 Thread Marc Deslauriers
the 70-insecure-fs.rules file was shipped in udisks2 (2.10.1-8), so Oracular and later: * Do not automatically mount unmaintained file systems. Ship a udev rules files named 70-insecure-fs.rules which sets the udev property UDISKS_AUTO to 0 for file systems that are marked as "Orphan"

[Bug 2114945] Re: block less common filesystems by default

2025-06-25 Thread Marc Deslauriers
So it looks like there's is also: /usr/lib/udev/rules.d/70-insecure-fs.rules : # Do not automatically mount these file systems because their drivers are # marked as "Orphan" or "Odd Fixes" in the kernel MAINTAINERS file and so # are more at risk of having security-sensitive defects which could be

[Bug 2106301]

2025-06-19 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 2111912] Re: CVE-2025-46836 fix breaks interface counters for ifconfig

2025-05-28 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Bug watch added: Debian Bug tracker #1106147 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1106147 ** Also affects: net-tools (Debian) via https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1106147 Importance: Unk

[Bug 2111870] Re: ifconfig can no logner collect stats for RX/TX packets by Linux kernel 6.6 or later

2025-05-28 Thread Marc Deslauriers
*** This bug is a duplicate of bug 2111912 *** https://bugs.launchpad.net/bugs/2111912 ** This bug has been marked a duplicate of bug 2111912 CVE-2025-46836 fix breaks interface counters for ifconfig -- You received this bug notification because you are a member of Ubuntu Bugs, which is s

[Bug 2110236] Re: [SRU] fixes for AppArmor in Plucky

2025-05-28 Thread Marc Deslauriers
Debdiff in comment #8 looks good, and was uploaded for processing by the SRU team. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2110236 Title: [SRU] fixes for AppArmor in Plucky To manage notifica

[Bug 2111604] Re: lsblk: failed to get sysfs name: Permission denied

2025-05-28 Thread Marc Deslauriers
** Also affects: apparmor (Ubuntu Questing) Importance: Undecided Status: New ** Also affects: apparmor (Ubuntu Plucky) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs

[Bug 2111807] Re: Plucky broke fstab sshfs mounts, which depend on fusermount

2025-05-28 Thread Marc Deslauriers
** Also affects: apparmor (Ubuntu Questing) Importance: Undecided Assignee: Ryan Lee (rlee287) Status: New ** Also affects: apparmor (Ubuntu Plucky) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 2110236] Re: [SRU] fixes for AppArmor in Plucky

2025-05-27 Thread Marc Deslauriers
I have removed the upload from the queue as an issue was discovered in it. A new debdiff will be available soon. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2110236 Title: [SRU] fixes for AppArmor

[Bug 2110236] Re: [SRU] fixes for AppArmor in Plucky

2025-05-15 Thread Marc Deslauriers
debdiff in comment #4 looks to contain the requested changes. Ack. Uploaded for processing by the SRU team. Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2110236 Title: [SRU] fixes for AppAr

[Bug 2110616] Re: apparmor unprivileged_userns profile missing access to /

2025-05-15 Thread Marc Deslauriers
** Also affects: apparmor (Ubuntu Plucky) Importance: Undecided Status: New ** Also affects: apparmor (Ubuntu Questing) Importance: Undecided Assignee: Ryan Lee (rlee287) Status: New ** Changed in: apparmor (Ubuntu Questing) Status: New => Fix Released ** Changed

[Bug 2107455] Re: segfault of lsblk s390x in containers due to apparmor

2025-05-15 Thread Marc Deslauriers
** Also affects: apparmor (Ubuntu Plucky) Importance: Undecided Status: New ** Also affects: apparmor (Ubuntu Questing) Importance: Undecided Assignee: Maxime Bélair (mbelair) Status: Fix Released ** Changed in: apparmor (Ubuntu Plucky) Status: New => In Progress

[Bug 2102033] Re: remmina blocked by apparmor in Plucky

2025-05-15 Thread Marc Deslauriers
** Also affects: apparmor (Ubuntu Plucky) Importance: Undecided Status: New ** Also affects: remmina (Ubuntu Plucky) Importance: Undecided Status: New ** Also affects: apparmor (Ubuntu Questing) Importance: Undecided Assignee: Tim Andersson (andersson123) Status

[Bug 2110624] Re: apparmor fusermount3 profile blocks mounts to /cvmfs/ subdirectories

2025-05-15 Thread Marc Deslauriers
** Also affects: apparmor (Ubuntu Plucky) Importance: Undecided Status: New ** Also affects: apparmor (Ubuntu Questing) Importance: Undecided Status: New ** Changed in: apparmor (Ubuntu Questing) Status: New => Fix Released ** Changed in: apparmor (Ubuntu Plucky)

[Bug 2110626] Re: apparmor fusermount3 profile disallows noatime flag, breaking fuse-overlayfs

2025-05-15 Thread Marc Deslauriers
** Also affects: apparmor (Ubuntu Plucky) Importance: Undecided Status: New ** Also affects: apparmor (Ubuntu Questing) Importance: Undecided Status: New ** Changed in: apparmor (Ubuntu Questing) Status: New => Fix Released ** Changed in: apparmor (Ubuntu Plucky)

[Bug 2110628] Re: apparmor profiles need mr permissions on their own binaries for execution from a confined context

2025-05-15 Thread Marc Deslauriers
** Also affects: apparmor (Ubuntu Questing) Importance: Undecided Status: New ** Also affects: apparmor (Ubuntu Plucky) Importance: Undecided Status: New ** Changed in: apparmor (Ubuntu Questing) Status: New => Fix Released ** Changed in: apparmor (Ubuntu Plucky)

[Bug 2110630] Re: apparmor.d man page contains incorrect information about mount flag combinations

2025-05-15 Thread Marc Deslauriers
** Also affects: apparmor (Ubuntu Plucky) Importance: Undecided Status: New ** Also affects: apparmor (Ubuntu Questing) Importance: Undecided Status: New ** Changed in: apparmor (Ubuntu Questing) Status: New => Fix Released ** Changed in: apparmor (Ubuntu Plucky)

[Bug 2110688] Re: apparmor parser incorrectly treats norelatime mount flag as a no-op

2025-05-15 Thread Marc Deslauriers
** Also affects: apparmor (Ubuntu Plucky) Importance: Undecided Status: New ** Also affects: apparmor (Ubuntu Questing) Importance: Undecided Status: New ** Changed in: apparmor (Ubuntu Questing) Status: New => Fix Released ** Changed in: apparmor (Ubuntu Plucky)

[Bug 2107723] Re: Using KDE Plasma widget "Web Browser" kill Plasma desktop due to QtWebEngine and AppArmor restrictions

2025-05-08 Thread Marc Deslauriers
** Also affects: apparmor (Ubuntu Plucky) Importance: Undecided Status: New ** Also affects: apparmor (Ubuntu Questing) Importance: Undecided Status: Fix Released ** Changed in: apparmor (Ubuntu Plucky) Status: New => In Progress -- You received this bug notification

[Bug 2110236] Re: [SRU] fixes for AppArmor in Plucky

2025-05-08 Thread Marc Deslauriers
ACK on the debdiff in comment #1. Uploaded for processing by the SRU team. Thanks! ** Changed in: apparmor (Ubuntu Plucky) Status: New => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bu

[Bug 2109029] Re: AppArmor OpenVPN profile blocks mDNS lookups

2025-05-08 Thread Marc Deslauriers
** Also affects: apparmor (Ubuntu Plucky) Importance: Undecided Status: New ** Also affects: apparmor (Ubuntu Questing) Importance: Undecided Status: Fix Released ** Changed in: apparmor (Ubuntu Plucky) Status: New => In Progress -- You received this bug notification

[Bug 2107596] Re: Apparmor is missing rule for openvpn to set DNS domain

2025-05-08 Thread Marc Deslauriers
** Also affects: apparmor (Ubuntu Plucky) Importance: Undecided Status: New ** Also affects: apparmor (Ubuntu Questing) Importance: Undecided Status: Fix Released ** Changed in: apparmor (Ubuntu Plucky) Status: New => In Progress -- You received this bug notification

[Bug 2107402] Re: lsblk on IBM z Systems blocked by apparmor in 25.04

2025-05-08 Thread Marc Deslauriers
** Also affects: util-linux (Ubuntu Plucky) Importance: Undecided Status: New ** Also affects: apparmor (Ubuntu Plucky) Importance: Undecided Status: New ** Also affects: util-linux (Ubuntu Questing) Importance: Medium Status: Invalid ** Also affects: apparmor (Ubun

[Bug 2107727] Re: iotop-c: Call of nl_init fails due to insufficient rights

2025-05-08 Thread Marc Deslauriers
** Also affects: apparmor (Ubuntu Plucky) Importance: Undecided Status: New ** Also affects: iotop-c (Ubuntu Plucky) Importance: Undecided Status: New ** Also affects: apparmor (Ubuntu Questing) Importance: Undecided Status: Fix Released ** Also affects: iotop-c (Ub

[Bug 2110236] Re: [SRU] fixes for AppArmor in Plucky

2025-05-08 Thread Marc Deslauriers
** Also affects: apparmor (Ubuntu Plucky) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2110236 Title: [SRU] fixes for AppArmor in Plucky To manage notif

[Bug 2104279] Re: rhythmbox crashed with SIGSEGV in rb_ext_db_cancel_requests()

2025-05-08 Thread Marc Deslauriers
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2104279 Title: rhythmbox crashed with SIGSEGV in rb_ext_db_cancel_requests() To manage noti

[Bug 2109993] Re: linux-bluefield is vulnerable to CVE-2025-21857

2025-05-08 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Changed in: linux-bluefield (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/21099

[Bug 2086693]

2025-05-08 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 2086692]

2025-05-08 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 2086689]

2025-05-08 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 2108995] Re: README.Debian file not being installed

2025-04-24 Thread Marc Deslauriers
Actually, it looks like this got fixed in plucky by the following Debian change: https://salsa.debian.org/libvirt- team/libvirt/-/commit/e09852843c703ba3534da3c1174d5bf0f0d339ce So noble and oracular are the affected releases which don't ship the file. ** Changed in: libvirt (Ubuntu Plucky)

[Bug 2108995] [NEW] README.Debian file not being installed

2025-04-24 Thread Marc Deslauriers
Public bug reported: The libvirt package contains debian/libvirt-daemon.README.Debian which contains important information, namely that the libvirtd group is root equivalent. While the file gets installed in focal and jammy by the libvirt-daemon package, it looks like it's no longer getting insta

[Bug 2107391] Re: Add Ubuntu 25.10 "Questing Quokka"

2025-04-23 Thread Marc Deslauriers
Please also release this to -security, thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2107391 Title: Add Ubuntu 25.10 "Questing Quokka" To manage notifications about this bug go to: https://

[Bug 2106404] Re: poppler April 2025 security fixes

2025-04-07 Thread Marc Deslauriers
Thanks Jeremy, I'll handle the stable releases. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2106404 Title: poppler April 2025 security fixes To manage notifications about this bug go to: https://

[Bug 2103454] Re: 3.8.10-0ubuntu1~20.04.16 broke IPv6 zone parsing

2025-03-17 Thread Marc Deslauriers
I can confirm this regression and will upload a package with the problematic patches reverted to the security team PPA for building in a few minutes. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/21034

[Bug 2103454] Re: 3.8.10-0ubuntu1~20.04.16 broke IPv6 zone parsing

2025-03-17 Thread Marc Deslauriers
** Changed in: python3.8 (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2103454 Title: 3.8.10-0ubuntu1~20.04.16 broke IPv6 zone parsing To manage notifications

[Bug 2103454] Re: 3.8.10-0ubuntu1~20.04.16 broke IPv6 zone parsing

2025-03-17 Thread Marc Deslauriers
Package is now building in the security team PPA here, and will be released as soon as the builds are done: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2102129] Re: Fix for CVE-2025-27516 regressed jinja in Python2 on focal

2025-03-12 Thread Marc Deslauriers
I am making this bug public as this regression is probably hitting more than one person. ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/b

[Bug 2100975] Re: CVE-2025-1080

2025-03-12 Thread Marc Deslauriers
https://ubuntu.com/security/notices/USN-7337-1 ** Changed in: libreoffice (Ubuntu Focal) Status: In Progress => Fix Released ** Changed in: libreoffice (Ubuntu Jammy) Status: In Progress => Fix Released ** Changed in: libreoffice (Ubuntu Noble) Status: In Progress => Fix Rel

[Bug 2100975] Re: CVE-2025-1080

2025-03-06 Thread Marc Deslauriers
Thanks! Packages are now building in the security team PPA and will be released soon. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2100975 Title: CVE-2025-1080 To manage notifications about this b

[Bug 2078822] Re: With Bluetooth headset connect, a malicious program can crash Pulseaudio on Ubuntu16.04

2025-02-17 Thread Marc Deslauriers
Hi Rachanan, Since the standard support for Ubuntu 16.04 LTS has ended, fixing this will be available in the ESM repository only. Are you still interested in us sponsoring your fix even if it is only available as an ESM update? Thanks! -- You received this bug notification because you are a memb

[Bug 1977718] Re: buffer overflow in nginx rtmp module

2025-02-14 Thread Marc Deslauriers
** Also affects: nginx (Ubuntu Jammy) Importance: Undecided Status: New ** Also affects: nginx (Ubuntu Focal) Importance: Undecided Status: New ** Changed in: nginx (Ubuntu Focal) Status: New => Confirmed ** Changed in: nginx (Ubuntu Jammy) Status: New => Confir

[Bug 1987228] Re: Bug display when turning to hibernation

2025-02-14 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1987228 Title: Bug display when turning to hibernation To manage notifications about

[Bug 1977875] Re: Ubuntu Desktop boot hangs absent zeroconf packets and after avahi-daemon purge

2025-02-14 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1977875 Title: Ubuntu Desktop boot hangs absent zeroconf packets and after avahi- daemon pu

[Bug 1977718] Re: buffer overflow in nginx rtmp module

2025-02-14 Thread Marc Deslauriers
** Changed in: nginx (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1977718 Title: buffer overflow in nginx rtmp module To manage notifications about this bu

[Bug 1976478] Re: Telegram Desktop steals input on Lock screen (Xorg session)

2025-02-14 Thread Marc Deslauriers
** Changed in: gnome-shell (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1976478 Title: Telegram Desktop steals input on Lock screen (Xorg session) To manage

[Bug 1942673] Re: glibc AddressSanitizer:DEADLYSIGNAL

2025-02-14 Thread Marc Deslauriers
** Changed in: pcre2 (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1942673 Title: glibc AddressSanitizer:DEADLYSIGNAL To manage notifications about this bu

[Bug 1922189] Re: integer overflow for maliciously crafted tga file

2025-02-14 Thread Marc Deslauriers
Since the upstream bug is public, I am making this bug public too. Thanks. ** Also affects: launchphplib Importance: Undecided Status: New ** No longer affects: launchphplib ** Information type changed from Private Security to Public Security ** Changed in: plib (Ubuntu) Status

[Bug 1921301] Re: heap overflow

2025-02-14 Thread Marc Deslauriers
Please file a bug with the upstream jhead developers here: https://github.com/Matthias-Wandel/jhead/issues Once you have done that, please add a comment here with the bug number. Thanks! ** Changed in: jhead (Ubuntu) Status: New => Incomplete -- You received this bug notification becaus

[Bug 1535768] Re: pkexec tty hijacking via TIOCSTI ioctl

2025-02-14 Thread Marc Deslauriers
This is CVE-2016-2568, and there is no solution to this issue as of today. ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2016-2568 ** Bug watch added: Debian Bug tracker #816062 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=816062 ** Also affects: policykit-1 (Debian) via

[Bug 2098089] Re: package cloudkitty-common 20.0.0-1ubuntu2 failed to install/upgrade: 已安装 cloudkitty-common 软件包 post-installation 脚本 子进程返回错误状态 1

2025-02-14 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 2088268] Re: systemd /tmp cleaning removes files that it shouldn't

2025-02-13 Thread Marc Deslauriers
So, before systemd-tmpfiles was used, Ubuntu used tmpreaper to perform periodic cleaning of the /tmp dir. tmpreaper had a list of exceptions: --protect '/tmp/.X*-{lock,unix,unix/*}' \ --protect '/tmp/.ICE-{unix,unix/*}' \ --protect '/tmp/.iroha_{unix,unix/*}' \ --protect '/tmp/.ki2-{unix,unix/*}'

[Bug 2097004] Re: Security bug update to 535.230.02

2025-02-11 Thread Marc Deslauriers
** Changed in: nvidia-graphics-drivers-535 (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/2097004 Title: Security bug update to 535.230.02 To manage

[Bug 2073500] Re: Ubuntu RT2x00 USB Driver Kernel Use-After-Free Vulnerability

2025-02-11 Thread Marc Deslauriers
** Changed in: linux (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2073500 Title: Ubuntu RT2x00 USB Driver Kernel Use-After-Free Vulnerability To manage noti

[Bug 2078822] Re: With Bluetooth headset connect, a malicious program can crash Pulseaudio on Ubuntu16.04

2025-02-11 Thread Marc Deslauriers
** Changed in: pulseaudio (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2078822 Title: With Bluetooth headset connect, a malicious program can crash Pulsea

[Bug 2083047] Re: Failure to maintain locked screen after monitor is turned off for inactivity

2025-02-11 Thread Marc Deslauriers
** Package changed: ubuntu => xscreensaver (Ubuntu) ** Changed in: xscreensaver (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/2083047 Title: Failure t

[Bug 2083312] Re: linux-libc-dev package has vulnerabilities

2025-02-11 Thread Marc Deslauriers
** Changed in: linux (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2083312 Title: linux-libc-dev package has vulnerabilities To manage notifications about t

[Bug 2086515] Re: Cryptographically unsafe RNG used for FIT images

2025-02-11 Thread Marc Deslauriers
** Changed in: u-boot (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2086515 Title: Cryptographically unsafe RNG used for FIT images To manage notifications

[Bug 2086695]

2025-02-11 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 2086697]

2025-02-11 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 2086696]

2025-02-11 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 2088433] Re: Problems with tigervncserver copying credential files to /tmp

2025-02-11 Thread Marc Deslauriers
** No longer affects: systemd (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2088433 Title: Problems with tigervncserver copying credential files to /tmp To manage notifications about this

[Bug 2095001] Re: Very weird and dangerous bug in systemd's sudoing (polkit?) process

2025-02-11 Thread Marc Deslauriers
** Also affects: policykit-1 via https://github.com/polkit-org/polkit/issues/545 Importance: Unknown Status: Unknown -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/2095001 Title:

[Bug 2097004] Re: Security bug update to 535.230.02

2025-02-11 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2097004 Title: Security bug update to 535.230.02 To manage notifications about thi

[Bug 2097105] Re: acpitool 0.5.1-7 crashes with -e flag (buffer overflow)

2025-02-11 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 2097656] Re: package libheif-plugin-aomenc:i386 1.17.6-1ubuntu4.1 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting configuration

2025-02-11 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 2097707] Re: package keyutils (not installed) failed to install/upgrade: dpkg-deb --control subprocess returned error exit status 2

2025-02-11 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 2070285] Re: package tzdata 2024a-3ubuntu1.1 failed to install/upgrade: installed tzdata package post-installation script subprocess returned error exit status 10

2025-01-29 Thread Marc Deslauriers
Please also release this package into the security pocket as we want to keep them in sync. Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2070285 Title: package tzdata 2024a-3ubuntu1.1 failed

[Bug 2095307] Re: CVE-2024-12425 and CVE-2024-12426

2025-01-27 Thread Marc Deslauriers
These updates have been published. Thanks! https://ubuntu.com/security/notices/USN-7228-1 ** Changed in: libreoffice (Ubuntu Focal) Status: In Progress => Fix Released ** Changed in: libreoffice (Ubuntu Jammy) Status: In Progress => Fix Released ** Changed in: libreoffice (Ubuntu

[Bug 2095307] Re: CVE-2024-12425 and CVE-2024-12426

2025-01-24 Thread Marc Deslauriers
Thanks for these! I'll upload them for building and will release them when done. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2095307 Title: CVE-2024-12425 and CVE-2024-12426 To manage notificatio

[Bug 2060613] Re: Gedit sometimes crashes by segmentation fault at closure

2025-01-14 Thread Marc Deslauriers
I believe this is caused by the snippets plugin. When I disable it, I no longer get a crash on exit. Unfortunately, it looks like the snippets plugin was removed in later versions. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https:

[Bug 2067480] Re: MRE updates of dpdk 23.11.2(Noble)/22.11.5(Mantic)/21.11.7(Jammy)

2024-12-19 Thread Marc Deslauriers
Unfortunately, there was a security update published today to the existing packages, so we definitely need to respin the proposed packages to 23.11.3 and 21.11.9. https://ubuntu.com/security/notices/USN-7178-1 -- You received this bug notification because you are a member of Ubuntu Bugs, which i

[Bug 2091695] Re: PHP ldap: undefined symbol RETURN_THROWS

2024-12-13 Thread Marc Deslauriers
** Changed in: php7.4 (Ubuntu Jammy) Status: Confirmed => Invalid ** Changed in: php7.4 (Ubuntu Noble) Status: Confirmed => Invalid ** Changed in: php7.4 (Ubuntu Oracular) Status: Confirmed => Invalid ** Changed in: php7.4 (Ubuntu Plucky) Status: Confirmed => Invalid

[Bug 2091695] Re: PHP ldap: undefined symbol RETURN_THROWS

2024-12-13 Thread Marc Deslauriers
Thanks for reporting this issue, we are currently investigating. ** Also affects: php7.4 (Ubuntu Oracular) Importance: Undecided Status: New ** Also affects: php7.4 (Ubuntu Noble) Importance: Undecided Status: New ** Also affects: php7.4 (Ubuntu Jammy) Importance: Undecide

[Bug 1987569] Re: Versions in Bionic and Focal are vulnerable to CVE-2020-12823

2024-12-06 Thread Marc Deslauriers
Due to lack of activity from the original bug reporter, we are closing this bug. ** Changed in: openconnect (Ubuntu Bionic) Status: New => Invalid ** Changed in: openconnect (Ubuntu Focal) Status: New => Invalid ** Changed in: openconnect (Ubuntu) Status: In Progress => Inva

[Bug 1955352] Re: Vulnerable to information disclosure through various actions

2024-12-06 Thread Marc Deslauriers
Due to lack of activity from the original bug reporter, we are closing this bug. ** Changed in: mediawiki (Ubuntu Bionic) Status: In Progress => Invalid ** Changed in: mediawiki (Ubuntu Focal) Status: In Progress => Invalid ** Changed in: mediawiki (Ubuntu Jammy) Status: Fix

[Bug 2089680] Re: Insufficient fix for CVE-2024-10573

2024-11-26 Thread Marc Deslauriers
This only affected Focal, the later releases include the second commit already. ** Changed in: mpg123 (Ubuntu Jammy) Status: New => Fix Released ** Changed in: mpg123 (Ubuntu Noble) Status: New => Fix Released ** Changed in: mpg123 (Ubuntu Oracular) Status: New => Fix Releas

[Bug 2089680] [NEW] Insufficient fix for CVE-2024-10573

2024-11-26 Thread Marc Deslauriers
*** This bug is a security vulnerability *** Public security bug reported: The fix for CVE-2024-10573 is insufficient in certain releases, pending investigation. This is the tracking bug. ** Affects: mpg123 (Ubuntu) Importance: Undecided Assignee: Marc Deslauriers (mdeslaur

[Bug 1889248] Re: [MIR] mdevctl, jq, libonig

2024-11-26 Thread Marc Deslauriers
Since the jq and libonig focal packages contain mostly the same major versions as the packages which are in main in jammy, and the detailed information in comment #15, ACK from the security team on promoting them to main in focal. -- You received this bug notification because you are a member of

[Bug 2088217] Re: Feature request, can we distro-patch sshd to emit warnings on dangerous configurations?

2024-11-14 Thread Marc Deslauriers
I think this is a great idea. We should, at the very least, print a warning about password authentication if it's enabled, as that is a default configuration we know should ideally be changed once a system is installed. -- You received this bug notification because you are a member of Ubuntu Bugs

[Bug 2088207] Re: cloud-init enables ssh password auth in an unexpected config file

2024-11-14 Thread Marc Deslauriers
I'm adding the openssh package to this bug, as the default configuration file has a Debian/Ubuntu-specific include directory configured and I think we should add an appropriate comment to inform the user that files included in the directory may override the configuration items in ssd_config. This w

[Bug 2088207] Re: cloud-init enables ssh password auth in an unexpected config file

2024-11-14 Thread Marc Deslauriers
If you google "how to disable ssh password authentication", there are pages and pages of instructions that instruct to modify sshd_config. I'm not sure how to correct user expectations. Maybe adding more explicit comments to sshd_config could be okay. How is cloud-init making sure another file in

[Bug 2088207] Re: cloud-init enables ssh password auth in an unexpected config file

2024-11-14 Thread Marc Deslauriers
Perhaps an acceptable solution could be to write the file only if cloud- init needs to overwrite the value to "no", but if the value is "yes", the openssh default, it shouldn't create the file. This would allow continuing to use the .d directory, but would prevent confusion which results in passwor

[Bug 2088207] Re: cloud-init enables ssh password auth in an unexpected config file

2024-11-14 Thread Marc Deslauriers
While the override directory is documented, it is quite unexpected that a default installation will make use of it, which is why this bug exists in the first place. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad

[Bug 2088207] Re: cloud-init enables ssh password auth in an unexpected config file

2024-11-14 Thread Marc Deslauriers
Is there a reason cloud-init needs to create an override in the first place, rather than changing the setting in the main file? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2088207 Title: cloud-ini

[Bug 2085851] Re: Jammy package 2:20.3.1-0ubuntu1.4 is missing the upstream privsep pieces

2024-11-07 Thread Marc Deslauriers
@james-page thanks for the tests, will publish today. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2085851 Title: Jammy package 2:20.3.1-0ubuntu1.4 is missing the upstream privsep pieces To mana

[Bug 2085667] Re: package mysql-server-8.0 8.0.39-0ubuntu0.24.04.2 failed to install/upgrade: installed mysql-server-8.0 package post-installation script subprocess returned error exit status 1 , also

2024-11-07 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 2084401] Re: My whole system has been collapsing. I'm going to down load and reinstall.

2024-11-07 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 2084491] Re: In my HD is installed ubuntu 24 and I'm trying to downgrade to 22. I was intaling and everything was ok until I got back a step and the it wasn't able to access my HD anymore

2024-11-07 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 2086358]

2024-11-07 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 2085388] Re: MSI Bravo 15, AMD, Radeon - loud fan, HDMI not working

2024-11-07 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 2085666] Re: Roundcube CVE-2024-37383 and CVE-2024-37384

2024-11-07 Thread Marc Deslauriers
** Changed in: roundcube (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2085666 Title: Roundcube CVE-2024-37383 and CVE-2024-37384 To manage notifications ab

[Bug 2086160] Re: package xdiagnose 3.8.10 failed to install/upgrade: no se puede abrir `/usr/lib/systemd/system/failsafe-x.service.dpkg-new': No existe el archivo o el directorio

2024-11-07 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 2085731] Re: keine bereitschaft möglich in ubutu 24.04

2024-11-07 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 2086546] Re: I get the bug as an esm bug problem when I write the command sudo apt update

2024-11-07 Thread Marc Deslauriers
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2086546 Title: I get the bug as an esm bug problem when I write the command sudo apt updat

  1   2   3   4   5   6   7   8   9   10   >