Summary: | <net-misc/openssh-8.5_p1: Double-free in ssh-agent (CVE-2021-28041) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | base-system |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | A3 [glsa+ cve] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 763051, 774177 | ||
Bug Blocks: |
Description
Sam James
2021-03-03 17:59:13 UTC
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=77e3bbd9528150668daa02b6afffe1183a482782 commit 77e3bbd9528150668daa02b6afffe1183a482782 Author: Patrick McLean <patrick.mclean@sony.com> AuthorDate: 2021-03-04 07:03:14 +0000 Commit: Patrick McLean <chutzpah@gentoo.org> CommitDate: 2021-03-04 07:03:14 +0000 net-misc/openssh-8.5_p1: Version bump Bug: https://bugs.gentoo.org/774090 Copyright: Sony Interactive Entertainment Inc. Package-Manager: Portage-3.0.16, Repoman-3.0.2 Signed-off-by: Patrick McLean <chutzpah@gentoo.org> net-misc/openssh/Manifest | 6 + .../openssh/files/openssh-8.5_p1-GSSAPI-dns.patch | 112 +++++ .../files/openssh-8.5_p1-X509-glue-13.0.patch | 73 +++ .../files/openssh-8.5_p1-hpn-15.1-X509-glue.patch | 325 +++++++++++++ .../files/openssh-8.5_p1-hpn-15.1-glue.patch | 242 ++++++++++ .../files/openssh-8.5_p1-hpn-15.1-sctp-glue.patch | 18 + net-misc/openssh/openssh-8.5_p1.ebuild | 515 +++++++++++++++++++++ 7 files changed, 1291 insertions(+) Thanks! Tell us when ready to stable. ping? chutzpah had no objections amd64 stable arm done x86 stable hppa stable ppc stable s390 stable sparc stable ppc64 stable arm64 done all arches done Please cleanup. Added to an existing GLSA request. This issue was resolved and addressed in GLSA 202105-35 at https://security.gentoo.org/glsa/202105-35 by GLSA coordinator Thomas Deutschmann (whissi). |