LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 01-25-2022, 04:54 PM   #9706
bassmadrigal
LQ Guru
 
Registered: Nov 2003
Location: West Jordan, UT, USA
Distribution: Slackware
Posts: 8,792

Rep: Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656

Quote:
Originally Posted by volkerdi View Post
I'm now targeting Wednesday 2022-02-02.
Uh oh... here comes the hype train.
 
2 members found this post helpful.
Old 01-25-2022, 05:58 PM   #9707
saxa
Senior Member
 
Registered: Aug 2004
Location: Nova Gorica, Salvador
Distribution: Slackware
Posts: 1,226

Rep: Reputation: 301Reputation: 301Reputation: 301Reputation: 301
Quote:
Originally Posted by volkerdi View Post
Well, I have found a reference for this looking around a bit. With the word out I wonder if they'll actually wait until Monday. After missing the last soft deadline for release, I was targeting next Monday but it seems that's not a good day. We really don't want to release with a network service package in the main tree containing a 9.9 critical security issue.

I'm now targeting Wednesday 2022-02-02. We'll hope Slackware doesn't see its shadow that day.
LOL absolutely the best dealine one could choose 22-2-2 , perfect.
 
1 members found this post helpful.
Old 01-25-2022, 07:58 PM   #9708
magicm
Member
 
Registered: May 2003
Distribution: Slackware
Posts: 237

Rep: Reputation: 152Reputation: 152
And it has the XLNT potential for Groundhog Day themed Slackware 15.0 swag !!
 
2 members found this post helpful.
Old 01-25-2022, 09:29 PM   #9709
Nobby6
Member
 
Registered: Jul 2012
Location: Sunshine Coast, Australia
Distribution: Slackware 64
Posts: 237
Blog Entries: 1

Rep: Reputation: 212Reputation: 212Reputation: 212
Security researchers have found a local privilege escalation bug in Linux distributions that allows any unprivileged user to execute code with the root superuser rights, giving them access to the entire system.

Security vendor Qualys called the bug PwnKit, and said it was introduced into the polkit or PolicyKit system-wide privilege control tool in May 2009, which is 12 years ago.

https://www.itnews.com.au/news/serio...2-years-575115'

Qualys said the vulnerability lies in polkit's pkexec command, which has code bugs that let attackers do out-of-bounds writes to introduce unsafe environment variables.

edited: shloud have included from the article that patches and mitigation available, so no need to call this one a blocker

Last edited by Nobby6; 01-25-2022 at 09:37 PM.
 
1 members found this post helpful.
Old 01-25-2022, 10:50 PM   #9710
gmgf
Senior Member
 
Registered: Jun 2012
Location: Bergerac, France
Distribution: Slackware
Posts: 2,295

Rep: Reputation: 1080Reputation: 1080Reputation: 1080Reputation: 1080Reputation: 1080Reputation: 1080Reputation: 1080Reputation: 1080
Quote:
Originally Posted by Nobby6 View Post
Security researchers have found a local privilege escalation bug in Linux distributions that allows any unprivileged user to execute code with the root superuser rights, giving them access to the entire system.

Security vendor Qualys called the bug PwnKit, and said it was introduced into the polkit or PolicyKit system-wide privilege control tool in May 2009, which is 12 years ago.

https://www.itnews.com.au/news/serio...2-years-575115'

Qualys said the vulnerability lies in polkit's pkexec command, which has code bugs that let attackers do out-of-bounds writes to introduce unsafe environment variables.

edited: shloud have included from the article that patches and mitigation available, so no need to call this one a blocker
seem that a fix is available here:

https://gitlab.freedesktop.org/polkit/polkit

https://gitlab.freedesktop.org/polki...055bff81ded683

Last edited by gmgf; 01-25-2022 at 10:51 PM.
 
2 members found this post helpful.
Old 01-26-2022, 03:35 AM   #9711
anon230
LQ Newbie
 
Registered: Jan 2021
Distribution: Slackware
Posts: 13

Rep: Reputation: Disabled
Italian Slackware mirrors broken

Mr. Volkerding,

please fix the Italian (IT) Slackware mirrors links.

Here is what we get using the current URL:

# slackpkg update

http://ba.mirror.garr.it/mirrors/Sla...rrent/GPG-KEY:
2022-01-26 10:30:03 ERROR 404: Not Found.

The correct URL should be "https://slackware.mirror.garr.it/slackware".

Sorry if this is not the right place, but I don't know other channels to report this to you.

Thank you, best regards.
 
Old 01-26-2022, 05:00 AM   #9712
MDKDIO
Member
 
Registered: Mar 2004
Location: Sweden
Distribution: Slackware 15
Posts: 521

Rep: Reputation: 187Reputation: 187
Quote:
Originally Posted by eming View Post
Mr. Volkerding,

please fix the Italian (IT) Slackware mirrors links.

Here is what we get using the current URL:

# slackpkg update

http://ba.mirror.garr.it/mirrors/Sla...rrent/GPG-KEY:
2022-01-26 10:30:03 ERROR 404: Not Found.

The correct URL should be "https://slackware.mirror.garr.it/slackware".

Sorry if this is not the right place, but I don't know other channels to report this to you.

Thank you, best regards.
Already sorted
https://mirrors.slackware.com/mirrorlist/
"it https://slackware.mirror.garr.it/slackware/ "
 
2 members found this post helpful.
Old 01-26-2022, 05:12 AM   #9713
Nobby6
Member
 
Registered: Jul 2012
Location: Sunshine Coast, Australia
Distribution: Slackware 64
Posts: 237
Blog Entries: 1

Rep: Reputation: 212Reputation: 212Reputation: 212
Quote:
Originally Posted by gmgf View Post
Updat was out 90 mins after I posted that, too fast, I suspect Pat already knew and was working on it
 
Old 01-26-2022, 05:12 AM   #9714
anon230
LQ Newbie
 
Registered: Jan 2021
Distribution: Slackware
Posts: 13

Rep: Reputation: Disabled
Quote:
Originally Posted by MDKDIO View Post
Hi MDKDIO,

thank you for the reply. The URL is not yet updated in slackpkg mirrors file.

I think that it will be updated soon or later.

Thank you

Last edited by anon230; 01-26-2022 at 05:14 AM.
 
Old 01-26-2022, 05:14 AM   #9715
MDKDIO
Member
 
Registered: Mar 2004
Location: Sweden
Distribution: Slackware 15
Posts: 521

Rep: Reputation: 187Reputation: 187
Quote:
Originally Posted by eming View Post
Hi MDKDIO,

thank you for the reply. The URL is not yet updated in slackpkg mirrors file.

I think that it will be updated soon or later.

Thank you
True that! Sorry about the noise
 
Old 01-26-2022, 07:12 AM   #9716
gmgf
Senior Member
 
Registered: Jun 2012
Location: Bergerac, France
Distribution: Slackware
Posts: 2,295

Rep: Reputation: 1080Reputation: 1080Reputation: 1080Reputation: 1080Reputation: 1080Reputation: 1080Reputation: 1080Reputation: 1080
Quote:
Originally Posted by Nobby6 View Post
Updat was out 90 mins after I posted that, too fast, I suspect Pat already knew and was working on it
Pat, is LUCKY LUKE
 
Old 01-26-2022, 08:32 AM   #9717
SCerovec
Senior Member
 
Registered: Oct 2006
Location: Cp6uja
Distribution: Slackware on x86 and arm
Posts: 2,480
Blog Entries: 2

Rep: Reputation: 986Reputation: 986Reputation: 986Reputation: 986Reputation: 986Reputation: 986Reputation: 986Reputation: 986
Red face

Quote:
Originally Posted by gmgf View Post
Pat, is LUCKY LUKE
More like PATIENT PATRICK considering all the noise and release-begging
 
Old 01-26-2022, 09:03 AM   #9718
kgha
Senior Member
 
Registered: May 2018
Location: Sweden
Distribution: Slackware 64 -current multilib from AlienBob's LiveSlak MATE
Posts: 1,088

Rep: Reputation: 761Reputation: 761Reputation: 761Reputation: 761Reputation: 761Reputation: 761Reputation: 761
Quote:
Originally Posted by saxa View Post
LOL absolutely the best dealine one could choose 22-2-2 , perfect.
Plus that it offers a fallback date: 22-2-22
 
1 members found this post helpful.
Old 01-26-2022, 10:38 AM   #9719
akschu
Member
 
Registered: Dec 2007
Posts: 96

Rep: Reputation: 39
Quote:
Originally Posted by volkerdi View Post
Well, I have found a reference for this looking around a bit. With the word out I wonder if they'll actually wait until Monday. After missing the last soft deadline for release, I was targeting next Monday but it seems that's not a good day. We really don't want to release with a network service package in the main tree containing a 9.9 critical security issue.

I'm now targeting Wednesday 2022-02-02. We'll hope Slackware doesn't see its shadow that day.
If the FOSS community isn't in a moment of calm, then push off a little longer. We've waited a long time for slackware 15, another few weeks to have this apparent flurry of updates isn't the end of the world.

Also, people that want it now can upgrade to current as it's stable enough for widespread use for most things and upgrading to release should be simple as there aren't any expected make worlds in the queue.

schu
 
Old 01-26-2022, 11:33 AM   #9720
marav
LQ Sage
 
Registered: Sep 2018
Location: Gironde
Distribution: Slackware
Posts: 5,441

Rep: Reputation: 4191Reputation: 4191Reputation: 4191Reputation: 4191Reputation: 4191Reputation: 4191Reputation: 4191Reputation: 4191Reputation: 4191Reputation: 4191Reputation: 4191
glib2 2.70.3

https://gitlab.gnome.org/GNOME/glib/-/tags/2.70.3

Code:
Several important fixes to FD handling in gspawn (#2503, #2506, #2580)
Several important fixes to GDBus message and GVariant parsing of invalid data (#2557, #2572)
Fix potential data loss due to missing fsync when saving files on btrfs (!2437)

Bugs fixed:

#2503 gspawn.c may clobber target fds
#2506 gspawn.c fails to close child_err_report_fd if it is duped to avoid conflation with one of the target_fds
#2557 Arrays of zero-element tuples with non-zero length lead to infinite loops in g_dbus_message_new_from_blob
#2572 Check for GVariant recursion depth before recursing
#2580 gspawn doesn't set CLOEXEC if close_range fails unexpectedly
!2394 Backport !1968 “gspawn: Fix file descriptor conflation issues” to glib-2-70
!2415 Backport !2412 “paramspec: fix unref annotation” to glib-2-70
!2437 Backport !2425 “gfileutils: Remove outdated BTRFS fsync optimization from set_contents” to glib-2-70
!2444 Backport !2435 “gspawn: Report errors with closing file descriptors between fork/exec” to glib-2-70
!2455 Backport !2454 gdbusmessage and gvariant fixes to glib-2-70
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Requests for -current (20151216) rworkman Slackware 3441 12-28-2017 03:50 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 07:17 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration