From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp1.migadu.com ([2001:41d0:303:e224::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms13.migadu.com with LMTPS id SL/3KBP7wGayUQEA62LTzQ:P1 (envelope-from ) for ; Sat, 17 Aug 2024 19:33:39 +0000 Received: from aspmx1.migadu.com ([2001:41d0:303:e224::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp1.migadu.com with LMTPS id SL/3KBP7wGayUQEA62LTzQ (envelope-from ) for ; Sat, 17 Aug 2024 21:33:39 +0200 X-Envelope-To: larch@yhetil.org Authentication-Results: aspmx1.migadu.com; dkim=pass header.d=debbugs.gnu.org header.s=debbugs-gnu-org header.b=F9Ba4UGn; dkim=fail ("headers rsa verify failed") header.d=retrospec.tv header.s=fm2 header.b=PsoUHTz1; dkim=fail ("headers rsa verify failed") header.d=messagingengine.com header.s=fm3 header.b=vlITosW6; dmarc=none; spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org" ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1723923219; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding:resent-cc: resent-from:resent-sender:resent-message-id:in-reply-to:in-reply-to: references:references:list-id:list-help:list-unsubscribe: list-subscribe:list-post:dkim-signature; bh=NPdASBYEXFoJqLzZUxXdbk1e/bzGlhXPVCO+s3OkwwA=; b=YbXAC/rL1YhSZmwyMOIQLpHYS8mDJkYnYU3kgNYBX6Ewo5QcODcriJerNQJAWkuuay7MXO pKRniUqK5Nj9dWc6lPOK7j7Z2DEMxFdl00MNjpeP+OCh/oosaVFYpNLbi92gP+hrGDoMMz G+O4z+ufbZN8BCU9rXFhYLqw18rhRJz7Qp5Qx7W6c+dzOrkygBoP15i+6ovOKG10JW31R2 AIBm36YKpR2JG8rWdYnRzJDZ0PTBo05SHFvouNBu3voWT1+2z0L8XodoHMJdF8w5rGs7TX nfID98kW98F3g6z/P3goCHSfMJlHVWKLAyfOjDZ2PprSS9gaJTeIlk3pM7TamA== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1723923219; a=rsa-sha256; cv=none; b=s2UCAM2FKlYLKB0d+24p+Y655qALV4LWKTcLbqJ4eq0kkpV86RuRvUweqqJaij8u+IUwgL EJNNHbzXH4Lj3mbNc/+RFu+EsL/FmYoH7k7he0VA40Lv5+zIjMUKyvcrioqcSTVpkAEHYh SfttEqvQjgteU+45BNuc1b9Lj8DPjnxJcMKYuFXW8/3+M056U8tekXkG+AUHTnE/Y/aoDV STUKajvGwYVzquL1mExPuZhI13oT8aYAM8dxPOCVr+DjBpjLncM0rxjD+Uk1SFNYTV99pq D5RPR1ArdSRJSfOII16n6rmdRpKYJGamq4IO+G5gTaVEbJqsk74epEdNPV5iuA== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=pass header.d=debbugs.gnu.org header.s=debbugs-gnu-org header.b=F9Ba4UGn; dkim=fail ("headers rsa verify failed") header.d=retrospec.tv header.s=fm2 header.b=PsoUHTz1; dkim=fail ("headers rsa verify failed") header.d=messagingengine.com header.s=fm3 header.b=vlITosW6; dmarc=none; spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org" Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 406BE32B11 for ; Sat, 17 Aug 2024 21:33:39 +0200 (CEST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1sfPB4-00083p-Ip; Sat, 17 Aug 2024 15:33:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1sfPAy-00081u-AK for guix-patches@gnu.org; Sat, 17 Aug 2024 15:33:24 -0400 Received: from debbugs.gnu.org ([2001:470:142:5::43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1sfPAx-0000LX-Ta for guix-patches@gnu.org; Sat, 17 Aug 2024 15:33:23 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debbugs.gnu.org; s=debbugs-gnu-org; h=MIME-Version:Date:From:To:In-Reply-To:References:Subject; bh=NPdASBYEXFoJqLzZUxXdbk1e/bzGlhXPVCO+s3OkwwA=; b=F9Ba4UGn/1dIF+bpXC1pyHj4ZdSMhwsoN4ENhKp+jBllPTaYdOfQ0UmtN3Xq8n33ci3RhAvQmMMEB+a3i4aEM7cjtDT9ik1r5RXtE6MBYYTvZc/hOVwo9MOgXypOhVQQ5DBfZKkUFNTFx+OoaAtC1uZn3ppB0df6NJQ9iy4CeoM8YpuXK4WBLKwdCslMEKx20EHp8QTqTkuZ3OnpnZ6sH8wKnL7YfX/ubGrFyEsNc52DP+7SpGRXoBAjoZBYSvs/Q4YIah6YBVYNJ/SIcLdUUuyjpJrki3t0/+7dbL4iPlQR513lyYhMcPAEe9oHy6fPog2L50Lvb6vk7vNYyn2KPA==; Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1sfPBb-0002Qo-4e for guix-patches@gnu.org; Sat, 17 Aug 2024 15:34:03 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#71832] [PATCH v6 0/3] [SECURITY] Update LibreWolf to 129.0.1-1; add nss-rapid References: <20240629035716.21504-1-ian@retrospec.tv> In-Reply-To: <20240629035716.21504-1-ian@retrospec.tv> Resent-From: Ian Eure Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Sat, 17 Aug 2024 19:34:03 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 71832 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 71832@debbugs.gnu.org Cc: Ian Eure , guix-security@gnu.org Received: via spool by 71832-submit@debbugs.gnu.org id=B71832.17239232429331 (code B ref 71832); Sat, 17 Aug 2024 19:34:03 +0000 Received: (at 71832) by debbugs.gnu.org; 17 Aug 2024 19:34:02 +0000 Received: from localhost ([127.0.0.1]:55003 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1sfPBX-0002QA-Vd for submit@debbugs.gnu.org; Sat, 17 Aug 2024 15:34:02 -0400 Received: from fout4-smtp.messagingengine.com ([103.168.172.147]:51257) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1sfPBT-0002PM-2F for 71832@debbugs.gnu.org; Sat, 17 Aug 2024 15:33:55 -0400 Received: from phl-compute-06.internal (phl-compute-06.nyi.internal [10.202.2.46]) by mailfout.nyi.internal (Postfix) with ESMTP id 4338E13868EA; Sat, 17 Aug 2024 15:33:08 -0400 (EDT) Received: from phl-mailfrontend-01 ([10.202.2.162]) by phl-compute-06.internal (MEProxy); Sat, 17 Aug 2024 15:33:08 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=retrospec.tv; h= cc:cc:content-transfer-encoding:content-type:date:date:from:from :in-reply-to:message-id:mime-version:reply-to:subject:subject:to :to; s=fm2; t=1723923188; x=1724009588; bh=NPdASBYEXFoJqLzZUxXdb k1e/bzGlhXPVCO+s3OkwwA=; b=PsoUHTz1Y8AC+f/UM9QLOppNKxVYx8xuR0Mop jgRH8P5Ana6DY4xOLBhxxo9rOoCU20BrGl7N+U4Gj87yC1zJZE47NuJ0J1WRpBY9 EA/Aab5FN2OOuU1J10rFCl8ONycaJLW/BRTZYw5BSPb7LkrwbMvtZXRQBF2W8neN Nq8Hs5XG2eaYKuSIzwhuolVjvMIQSJ2KLbOw7id2DgsLPf9/qCB52F0ZEkUwVNOB NtFN0hvDHNwZJk7WkEnVDDqchZUUZen95cbWjdEA/lV51YQp66Zn+nzXBQin2yVZ ihkT9ALeFVBkQuSPbCCPQ9vRMOQ7WdNN0QCJK/K7hC2qgQ8cw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:message-id:mime-version:reply-to:subject:subject:to :to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s= fm3; t=1723923188; x=1724009588; bh=NPdASBYEXFoJqLzZUxXdbk1e/bzG lhXPVCO+s3OkwwA=; b=vlITosW6GcSuUkSaEZuwUX1r78NQSQJmM0+3sOM6IEfW XOmkDzmmHXF+afOshSsF6kKdWw1f7cFU75GBoMMi10kb9kP6eFTS2vUMv4K3SQQd FMDJBgL3DkWVjDNdX8vuwDxqnROz2GRCIPvNpA4PU5Iw9ju79MuM8hDnWcNBQhGA bWzYBEGq+AV0bc+w9LcHkeu75ocJQINOkUChq6riM7ToG1dzyh+BJPLSSmDzJypa tB2XrJCp/wtGWYWsnmZUYUGG6NzEaamuDmDl3k7a5cTnGjTCQoTEiKFsWB6DX9hO lScuIvAe1CFknvVpl6ijwSdCVSsInsoCNctDtiUKTw== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeeftddruddutddgudegtdcutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpggftfghnshhusghstghrihgsvgdp uffrtefokffrpgfnqfghnecuuegrihhlohhuthemuceftddtnecunecujfgurhephffvve fufffkofgggfestdekredtredttdenucfhrhhomhepkfgrnhcugfhurhgvuceoihgrnhes rhgvthhrohhsphgvtgdrthhvqeenucggtffrrghtthgvrhhnpefgvdejhfelhfeftdeile elfedvhfefffetfeeuteelgfdvleffleevgfefueekjeenucffohhmrghinhepmhhoiihi lhhlrgdrohhrghenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrihhlfh hrohhmpehirghnsehrvghtrhhoshhpvggtrdhtvhdpnhgspghrtghpthhtohepfedpmhho uggvpehsmhhtphhouhhtpdhrtghpthhtohepjedukeefvdesuggvsggsuhhgshdrghhnuh drohhrghdprhgtphhtthhopehguhhigidqshgvtghurhhithihsehgnhhurdhorhhgpdhr tghpthhtohepihgrnhesrhgvthhrohhsphgvtgdrthhv X-ME-Proxy: Feedback-ID: id9014242:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Sat, 17 Aug 2024 15:33:07 -0400 (EDT) From: Ian Eure Date: Sat, 17 Aug 2024 12:32:37 -0700 Message-ID: <20240817193240.27089-1-ian@retrospec.tv> X-Mailer: git-send-email 2.45.2 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+larch=yhetil.org@gnu.org Sender: guix-patches-bounces+larch=yhetil.org@gnu.org X-Migadu-Flow: FLOW_IN X-Migadu-Country: US X-Migadu-Queue-Id: 406BE32B11 X-Migadu-Scanner: mx12.migadu.com X-Migadu-Spam-Score: -10.03 X-Spam-Score: -10.03 X-TUID: Ff4YY/VdavEc vs. the previous versions of this patch series, v6: - Updates LibreWolf to 129.0.1-1, the latest upstream. - Updates nss-rapid, to version 3.103, the latest upstream. - Adds the skr locale to all-mozilla-locales. - Backs out improvements not directly related to updating the browser version, to make review easier. In addition to the CVEs fixed in 128.0, this includes fixes for[1]: CVE-2024-7518: Fullscreen notification dialog can be obscured by document content CVE-2024-7519: Out of bounds memory access in graphics shared memory handling CVE-2024-7520: Type confusion in WebAssembly CVE-2024-7521: Incomplete WebAssembly exception handing CVE-2024-7522: Out of bounds read in editor component CVE-2024-7523: Document content could partially obscure security prompts CVE-2024-7524: CSP strict-dynamic bypass using web-compatibility shims CVE-2024-7525: Missing permission check when creating a StreamFilter CVE-2024-7526: Uninitialized memory used by WebGL CVE-2024-7527: Use-after-free in JavaScript garbage collection CVE-2024-7528: Use-after-free in IndexedDB CVE-2024-7529: Document content could partially obscure security prompts CVE-2024-7530: Use-after-free in JavaScript code coverage collection CVE-2024-7531: PK11_Encrypt using CKM_CHACHA20 can reveal plaintext on Intel Sandy Bridge [1]: https://www.mozilla.org/en-US/security/advisories/mfsa2024-33/ Ian Eure (3): gnu: gnuzilla: Add skr to all-mozilla-locales. gnu: Add nss-rapid. gnu: librewolf: Update to 129.0.1-1. gnu/packages/gnuzilla.scm | 1 + gnu/packages/librewolf.scm | 12 +++---- gnu/packages/nss.scm | 67 ++++++++++++++++++++++++++++++++++++++ 3 files changed, 74 insertions(+), 6 deletions(-) -- 2.45.2