From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp12.migadu.com ([2001:41d0:8:6d80::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms5.migadu.com with LMTPS id uEHeGPKMXWJ9SQEAbAwnHQ (envelope-from ) for ; Mon, 18 Apr 2022 18:08:18 +0200 Received: from aspmx1.migadu.com ([2001:41d0:8:6d80::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp12.migadu.com with LMTPS id KMy2GPKMXWImIwAAauVa8A (envelope-from ) for ; Mon, 18 Apr 2022 18:08:18 +0200 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 9392E1FD68 for ; Mon, 18 Apr 2022 18:08:17 +0200 (CEST) Received: from localhost ([::1]:44240 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1ngTvE-0001UV-Fa for larch@yhetil.org; Mon, 18 Apr 2022 12:08:16 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:59140) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1ngTs9-00071f-7I for guix-patches@gnu.org; Mon, 18 Apr 2022 12:05:08 -0400 Received: from debbugs.gnu.org ([209.51.188.43]:46597) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1ngTs5-0000yB-Uz for guix-patches@gnu.org; Mon, 18 Apr 2022 12:05:03 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1ngTs5-0002we-Qq for guix-patches@gnu.org; Mon, 18 Apr 2022 12:05:01 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#55001] [PATCH] gnu: git: Update to 2.35.2 [fixes CVE-2022-24765]. Resent-From: Zhu Zihao Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Mon, 18 Apr 2022 16:05:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 55001 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: Greg Hogan Cc: 55001@debbugs.gnu.org Received: via spool by 55001-submit@debbugs.gnu.org id=B55001.165029789411299 (code B ref 55001); Mon, 18 Apr 2022 16:05:01 +0000 Received: (at 55001) by debbugs.gnu.org; 18 Apr 2022 16:04:54 +0000 Received: from localhost ([127.0.0.1]:40494 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1ngTry-0002wB-5M for submit@debbugs.gnu.org; Mon, 18 Apr 2022 12:04:54 -0400 Received: from mail-m973.mail.163.com ([123.126.97.3]:47335) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1ngTrv-0002vm-7Z for 55001@debbugs.gnu.org; Mon, 18 Apr 2022 12:04:53 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=163.com; s=s110527; h=From:Subject:Date:Message-ID:MIME-Version; bh=+Lk5q tIdAqGPi8yOR0kisyfp67Q/FGM3DoJ553oirQ8=; b=dnFqLata1tomfGkmU06ic wF4kiUg/7/AZKPVKzjEsWZjvIcqSU7OZXaajniafAy3Ssf9ZZY1yN1d8et+Yq4oz OKBkRRmw01cLr8xhrRs6u1LA8Oo3IEys9be7DEPEKTUcLpJKNnmSpQlwun22a06l jgVygLJDALtSLyuosB6Z/I= Received: from asus-laptop (unknown [27.38.172.10]) by smtp3 (Coremail) with SMTP id G9xpCgAHUTAXjF1iCt7vBw--.48235S2; Tue, 19 Apr 2022 00:04:40 +0800 (CST) References: <8635iabj7y.fsf@163.com> User-agent: mu4e 1.6.10; emacs 27.2 From: Zhu Zihao Date: Tue, 19 Apr 2022 00:02:40 +0800 In-reply-to: Message-ID: <86mtgi8jjd.fsf@163.com> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha256; protocol="application/pgp-signature" X-CM-TRANSID: G9xpCgAHUTAXjF1iCt7vBw--.48235S2 X-Coremail-Antispam: 1Uf129KBjvdXoWruw45JrykJF1xZw1xtF18Krg_yoW3XFb_WF Z8Jws5WrWvqa17J3Z3Cr4furs3tryfXry8Gr42gw4jvr1UXF18Wwn3ur1Sgr1q9an7Kryq grn8XrW0yr1IvjkaLaAFLSUrUUUUUb8apTn2vfkv8UJUUUU8Yxn0WfASr-VFAUDa7-sFnT 9fnUUvcSsGvfC2KfnxnUUI43ZEXa7xRXa9-7UUUUU== X-Originating-IP: [27.38.172.10] X-CM-SenderInfo: pdoosuxxwbztlvw6il2tof0z/xtbBPQDmr2AY-2caYQADss X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+larch=yhetil.org@gnu.org Sender: "Guix-patches" X-Migadu-Flow: FLOW_IN X-Migadu-To: larch@yhetil.org X-Migadu-Country: US ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1650298098; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:resent-cc:resent-from:resent-sender: resent-message-id:in-reply-to:in-reply-to:references:references: list-id:list-help:list-unsubscribe:list-subscribe:list-post: dkim-signature; bh=+Lk5qtIdAqGPi8yOR0kisyfp67Q/FGM3DoJ553oirQ8=; b=hpVOHQXjXWDs03XnDKEpS3qCLu4BOLCTOjiO7Wsow4y7WCgn9mctdZYSk7gX07j6CMuOkg SJniyyfhfVSwahWaoYxwb446RKnuFyDg3rASZYOZXpyqmV2uzPp+N0GObF3QiXU7+YaBEn Ciwcxa+db9X3hhXZ9z9Yuk5uWk3AAmVRjv0BxLFKOcAawe2GvqskJ/HWYczWyKH4SgIPxf ZE2Vm+Nc0RsZ5CFbP5v63XVmwp2p0mLRvPggsU/4v2CUTY4kUKE39almlHzf+zneyFCv+l zc1liOLMy199ivKSiR+YFijEOq65OwmSjMZQo36emMs6HMLI3BDdw4V6cmlXxg== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1650298098; a=rsa-sha256; cv=none; b=KCwzXN7RwuwRErid57JyKy9ALcHBl9/iF6q0TiOW05xvll3uQUZspGMyAZHG/n3R9IILry PvGhxU2v3ndtyuuin1TBsqKQ0r02rmpuFHap1ObRuqNUSImb0rOFYUCJX+xYVoK10Wz+xI djO99aw5Ug/bI2euzlZTwKeHMoyB7nWXexf1teSeWwRgrU+21YsYUkub4WMq4VYhseRpyH tbf7Uec2EGSwt9lI7udZHsNcN4G2TSvwAx8YljqCY9TdTzOztzt34QZnB7lJrdAfGeU60o eJUlTMmugx3sU7XPz2gkBTgXwtX8ZZ+PDGLvsJ0kRFqlWj9SV2doFc4c0Zu4mQ== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=163.com header.s=s110527 header.b=dnFqLata; dmarc=fail reason="SPF not aligned (relaxed)" header.from=163.com (policy=none); spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org" X-Migadu-Spam-Score: 4.36 Authentication-Results: aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=163.com header.s=s110527 header.b=dnFqLata; dmarc=fail reason="SPF not aligned (relaxed)" header.from=163.com (policy=none); spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org" X-Migadu-Queue-Id: 9392E1FD68 X-Spam-Score: 4.36 X-Migadu-Scanner: scn1.migadu.com X-TUID: Ilo8RNpzAhyL --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Greg Hogan writes: > Hi Zihao, > > Is this not a Windows-only vulnerability and bugfix release (also CVE-202= 2-24767)? > > Greg > > On Mon, Apr 18, 2022 at 9:44 AM Zhu Zihao wrote: > > --=20 > Retrieve my PGP public key: > > gpg --recv-keys D47A9C8B2AE3905B563D9135BE42B352A9F6821F > > Zihao Hi. https://www.phoronix.com/scan.php?page=3Dnews_item&px=3DGit-CVE-2022-24765 This article says "likely due to only affect Microsoft Windows". I haven't test this CVE on *nix systems. If it doesn't affect Guix systems, should I remove "[fixes CVE-2022-24765]" in the git commit message or leave it there? =2D-=20 Retrieve my PGP public key: gpg --recv-keys D47A9C8B2AE3905B563D9135BE42B352A9F6821F Zihao --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iIsEARYIADMWIQRefA5qkqvnKdl/GTlmOX+E92aT+QUCYl2MFhUcYWxsX2J1dF9s YXN0QDE2My5jb20ACgkQZjl/hPdmk/l9MwEAoMr5QEkeM/FJeXpbjxBqltS0ayDN uxLSNPQp5z4x/6YBAMCz3V2x1FJYLtR+5rCFuChZQFH9wkE3rlE/VUezSRwH =1e9C -----END PGP SIGNATURE----- --=-=-=--