From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:56757) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1exqti-0005dj-HH for guix-patches@gnu.org; Mon, 19 Mar 2018 05:16:12 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1exqte-0004l6-H1 for guix-patches@gnu.org; Mon, 19 Mar 2018 05:16:06 -0400 Received: from debbugs.gnu.org ([208.118.235.43]:32858) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1exqte-0004kd-DW for guix-patches@gnu.org; Mon, 19 Mar 2018 05:16:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1exqte-00019R-4S for guix-patches@gnu.org; Mon, 19 Mar 2018 05:16:02 -0400 Subject: [bug#30827] [PATCH] gnu: util-linux: Fix CVE-2018-7738. Resent-Message-ID: From: ludo@gnu.org (Ludovic =?UTF-8?Q?Court=C3=A8s?=) References: Date: Mon, 19 Mar 2018 10:15:22 +0100 In-Reply-To: (Leo Famulari's message of "Thu, 15 Mar 2018 13:58:42 -0400") Message-ID: <871sggv32t.fsf@gnu.org> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+kyle=kyleam.com@gnu.org Sender: "Guix-patches" To: Leo Famulari Cc: 30827@debbugs.gnu.org Hello! Leo Famulari skribis: > * gnu/packages/patches/util-linux-CVE-2018-7738.patch: New file. > * gnu/local.mk (dist_patch_DATA): Add it. > * gnu/packages/linux.scm (util-linux)[replacement]: New field. > (util-linux/fixed): New variable. [...] > +https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2018-7738 > + > +Patch copied from upstream source repository: > + > +https://github.com/karelzak/util-linux/commit/75f03badd7ed9f1dd951863d75= e756883d3acc55 I=E2=80=99m late to the party, but I=E2=80=99m wondering in this case if, i= nstead of grafting, we should simply add an util-linux@2.31a package, and make sure GuixSD uses that one in %base-packages. That way, both GuixSD and manually installed util-linux would get the Bash completion fix. It=E2=80=99s probably OK that packages that depend on util-linux don=E2=80=99t get the fixed version because users don=E2=80=99t = get bash completion from there. WDYT? Thanks, Ludo=E2=80=99.