GNU bug report logs - #47257
mariadb is vulnerable to CVE-2021-27928 (RCE)

Previous Next

Package: guix;

Reported by: Léo Le Bouter <lle-bout <at> zaclys.net>

Date: Fri, 19 Mar 2021 10:26:02 UTC

Severity: normal

Tags: security

Done: Léo Le Bouter <lle-bout <at> zaclys.net>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: Léo Le Bouter <lle-bout <at> zaclys.net>
To: zimoun <zimon.toutoune <at> gmail.com>, 47257 <at> debbugs.gnu.org
Subject: bug#47257: mariadb is vulnerable to CVE-2021-27928 (RCE)
Date: Thu, 25 Mar 2021 12:28:15 +0100
[Message part 1 (text/plain, inline)]
On Fri, 2021-03-19 at 12:35 +0100, zimoun wrote:
> Instead of grafting, I would fix first check the compatibility
> between
> mariadb  and zstd.  Because mariadb <at> 10.5.8 does not build with
> zstd <at> 1.4.9, at least on my machine.

Can you post build logs and repro scenario? mariadb <at> 10.5.8 built fine
for me on core-updates which has zstd <at> 1.4.9.

> Other said, I seem better to do this fix as a whole on core-updates
> without any graft.  Instead of grafting here and there; and not
> necessary small changes (zstd from 1.4.4 to 1.4.9, mariadb from
> 10.5.8
> to 10.5.8).

We can't patch security issues through core-updates, especially this
RCE.

> All the best,
> simon

[signature.asc (application/pgp-signature, inline)]

This bug report was last modified 4 years and 49 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.