Your message dated Sat, 19 Jun 2021 10:56:39 +0100 with message-id <5c65c3ad2ac9b1b1f78bf73b1cf073041e619b51.camel@adam-barratt.org.uk> and subject line Closing p-u requests for fixes included in 10.10 point release has caused the Debian Bug report #989420, regarding buster-pu: package isc-dhcp/4.4.1-2+deb10u1 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact owner@bugs.debian.org immediately.) -- 989420: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=989420 Debian Bug Tracking System Contact owner@bugs.debian.org with problems
--- Begin Message ---
- To: Debian Bug Tracking System <submit@bugs.debian.org>
- Subject: buster-pu: package isc-dhcp/4.4.1-2+deb10u1
- From: Salvatore Bonaccorso <carnil@debian.org>
- Date: Thu, 03 Jun 2021 13:14:35 +0200
- Message-id: <[🔎] 162271887587.21590.13455521041905994008.reportbug@lorien.valinor.li>
Package: release.debian.org Severity: normal Tags: buster User: release.debian.org@packages.debian.org Usertags: pu X-Debbugs-Cc: carnil@debian.org,kibi@debian.org Hi Stable release managers, This brings the update to address CVE-2021-25217 / #989157 in buster (the fix was applied already as NMU in unstable and unblocked accordingly). The debian/changelog entry is +isc-dhcp (4.4.1-2+deb10u1) buster; urgency=medium + + * Non-maintainer upload. + * A buffer overrun in lease file parsing code can be used to exploit a + common vulnerability shared by dhcpd and dhclient (CVE-2021-25217) + (Closes: #989157) + + -- Salvatore Bonaccorso <carnil@debian.org> Thu, 03 Jun 2021 12:59:09 +0200 The debdiff attached accordingly. But it needs a d-i ack as well from Cyril as it produces udebs. Regards, Salvatorediff -Nru isc-dhcp-4.4.1/debian/changelog isc-dhcp-4.4.1/debian/changelog --- isc-dhcp-4.4.1/debian/changelog 2018-12-11 04:55:12.000000000 +0100 +++ isc-dhcp-4.4.1/debian/changelog 2021-06-03 12:59:09.000000000 +0200 @@ -1,3 +1,12 @@ +isc-dhcp (4.4.1-2+deb10u1) buster; urgency=medium + + * Non-maintainer upload. + * A buffer overrun in lease file parsing code can be used to exploit a + common vulnerability shared by dhcpd and dhclient (CVE-2021-25217) + (Closes: #989157) + + -- Salvatore Bonaccorso <carnil@debian.org> Thu, 03 Jun 2021 12:59:09 +0200 + isc-dhcp (4.4.1-2) unstable; urgency=medium * Set initial address to 0.0.0.0 on hurd (closes: #875566). diff -Nru isc-dhcp-4.4.1/debian/patches/4.4.2.CVE-2021-25217.patch isc-dhcp-4.4.1/debian/patches/4.4.2.CVE-2021-25217.patch --- isc-dhcp-4.4.1/debian/patches/4.4.2.CVE-2021-25217.patch 1970-01-01 01:00:00.000000000 +0100 +++ isc-dhcp-4.4.1/debian/patches/4.4.2.CVE-2021-25217.patch 2021-06-03 12:59:09.000000000 +0200 @@ -0,0 +1,29 @@ +Description: A buffer overrun in lease file parsing code can be used to exploit a common vulnerability shared by dhcpd and dhclient +Origin: vendor +Bug-Debian: https://bugs.debian.org/989157 +Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2021-25217 +Forwarded: not-needed +Author: Salvatore Bonaccorso <carnil@debian.org> +Last-Update: 2021-05-26 + +diff --git a/common/parse.c b/common/parse.c +index 386a6321..fc7b39c6 100644 +--- a/common/parse.c ++++ b/common/parse.c +@@ -5556,13 +5556,14 @@ int parse_X (cfile, buf, max) + skip_to_semi (cfile); + return 0; + } +- convert_num (cfile, &buf [len], val, 16, 8); +- if (len++ > max) { ++ if (len >= max) { + parse_warn (cfile, + "hexadecimal constant too long."); + skip_to_semi (cfile); + return 0; + } ++ convert_num (cfile, &buf [len], val, 16, 8); ++ len++; + token = peek_token (&val, (unsigned *)0, cfile); + if (token == COLON) + token = next_token (&val, diff -Nru isc-dhcp-4.4.1/debian/patches/series isc-dhcp-4.4.1/debian/patches/series --- isc-dhcp-4.4.1/debian/patches/series 2018-11-18 07:13:45.000000000 +0100 +++ isc-dhcp-4.4.1/debian/patches/series 2021-06-03 12:59:09.000000000 +0200 @@ -16,3 +16,5 @@ bind-includes.patch configure.patch + +4.4.2.CVE-2021-25217.patch
--- End Message ---
--- Begin Message ---
- To: 934206-done@bugs.debian.org, 982996-done@bugs.debian.org, 983110-done@bugs.debian.org, 984604-done@bugs.debian.org, 985791-done@bugs.debian.org, 985792-done@bugs.debian.org, 985943-done@bugs.debian.org, 986001-done@bugs.debian.org, 986014-done@bugs.debian.org, 986112-done@bugs.debian.org, 986224-done@bugs.debian.org, 986673-done@bugs.debian.org, 987038-done@bugs.debian.org, 987042-done@bugs.debian.org, 987048-done@bugs.debian.org, 987164-done@bugs.debian.org, 987210-done@bugs.debian.org, 987246-done@bugs.debian.org, 987489-done@bugs.debian.org, 987494-done@bugs.debian.org, 987529-done@bugs.debian.org, 987531-done@bugs.debian.org, 987548-done@bugs.debian.org, 987719-done@bugs.debian.org, 987725-done@bugs.debian.org, 987726-done@bugs.debian.org, 987731-done@bugs.debian.org, 987859-done@bugs.debian.org, 987958-done@bugs.debian.org, 988255-done@bugs.debian.org, 988314-done@bugs.debian.org, 988365-done@bugs.debian.org, 988453-done@bugs.debian.org, 988454-done@bugs.debian.org, 988455-done@bugs.debian.org, 988482-done@bugs.debian.org, 988492-done@bugs.debian.org, 988508-done@bugs.debian.org, 988936-done@bugs.debian.org, 988962-done@bugs.debian.org, 988974-done@bugs.debian.org, 988977-done@bugs.debian.org, 989023-done@bugs.debian.org, 989024-done@bugs.debian.org, 989129-done@bugs.debian.org, 989132-done@bugs.debian.org, 989420-done@bugs.debian.org, 989422-done@bugs.debian.org, 989509-done@bugs.debian.org, 989623-done@bugs.debian.org, 989668-done@bugs.debian.org, 989701-done@bugs.debian.org, 989702-done@bugs.debian.org, 989768-done@bugs.debian.org, 989772-done@bugs.debian.org
- Subject: Closing p-u requests for fixes included in 10.10 point release
- From: "Adam D. Barratt" <adam@adam-barratt.org.uk>
- Date: Sat, 19 Jun 2021 10:56:39 +0100
- Message-id: <5c65c3ad2ac9b1b1f78bf73b1cf073041e619b51.camel@adam-barratt.org.uk>
Package: release.debian.org Version: 10.10 Hi, Each of the updates referenced in these bugs was included in the 10.10 point release today. Regards, Adam
--- End Message ---