Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 949105 - <x11-terms/ghostty-1.1.0: file descriptors leaked to shell
Summary: <x11-terms/ghostty-1.1.0: file descriptors leaked to shell
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial
Assignee: Gentoo Security
URL:
Whiteboard: ~1 [noglsa]
Keywords: PullRequest
Depends on:
Blocks:
 
Reported: 2025-01-30 23:56 UTC by sin-ack
Modified: 2025-02-01 23:15 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description sin-ack 2025-01-30 23:56:27 UTC
GitHub security advisory: https://github.com/ghostty-org/ghostty/security/advisories/GHSA-98wc-794w-gjx3
CVEs: None
Comment 1 Hans de Graaff gentoo-dev Security 2025-01-31 06:19:20 UTC
Thanks for reporting. We use the version in the summary to indicated fixed version in the Gentoo repository, so I've removed it for now until a fixed version has been added.
Comment 2 sin-ack 2025-01-31 08:49:45 UTC
Understood. The linked PR adds ghostty-1.1.0 which fixes the issue.
Comment 3 Larry the Git Cow gentoo-dev 2025-02-01 08:31:16 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f4a5cb2887f16796d9a22be254fb17472c56b22f

commit f4a5cb2887f16796d9a22be254fb17472c56b22f
Author:     sin-ack <sin-ack@protonmail.com>
AuthorDate: 2025-01-30 23:53:50 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2025-02-01 08:31:12 +0000

    x11-terms/ghostty: drop 1.0.1-r3
    
    Bug: https://bugs.gentoo.org/949105
    Signed-off-by: sin-ack <sin-ack@protonmail.com>
    Closes: https://github.com/gentoo/gentoo/pull/40393
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 x11-terms/ghostty/Manifest                         |   4 -
 .../files/ghostty-1.0.0-bzip2-dependency.patch     |  13 ---
 ...t-gtk-move-most-version-checks-to-runtime.patch | 125 ---------------------
 ...stty-1.0.1-copy-terminfo-using-installdir.patch |  44 --------
 x11-terms/ghostty/ghostty-1.0.1-r3.ebuild          | 124 --------------------
 5 files changed, 310 deletions(-)
Comment 4 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2025-02-01 23:15:49 UTC
-> trivial since no stable version. Please reference the security bugs in the relevant commits when available. Thanks!