Bug 56117 - mariadb-10.3: Multiple issues (5.0)
mariadb-10.3: Multiple issues (5.0)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 5.0
All Linux
: P3 normal (vote)
: UCS 5.0-3-errata
Assigned To: Quality Assurance
Philipp Hahn
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2023-06-05 09:40 CEST by Quality Assurance
Modified: 2023-06-07 09:45 CEST (History)
0 users

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score: 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2023-06-05 09:40:34 CEST
New Debian mariadb-10.3 1:10.3.39-0+deb10u1 fixes:
This update addresses the following issue:
1:10.3.38-0+deb10u1 (Thu, 09 Feb 2023 21:59:32 -0800)
[ Otto Kekäläinen ]
* New upstream version 10.3.38. Includes fix for a major performance/memory  consumption issue (MDEV-29988).
* Upstream 10.3.35 included fix for MDEV-27937
1:10.3.39-0+deb10u1 (Sat, 03 Jun 2023 18:57:44 -0700)
* New upstream version 10.3.39. Includes security fixes for: - CVE-2022-47015
* According to https://mariadb.org/about/#maintenance-policy this was the  last minor maintenance release for MariaDB 10.3 series
* Add patch to revert upstream libmariadb API change
* Make SysV init script explicit on its dependencies (Related: #1035949)
Comment 1 Quality Assurance univentionstaff 2023-06-05 10:00:08 CEST
--- mirror/ftp/pool/main/m/mariadb-10.3/mariadb-10.3_10.3.36-0+deb10u2.dsc
+++ apt/ucs_5.0-0-errata5.0-3/source/mariadb-10.3_10.3.39-0+deb10u1.dsc
@@ -1,3 +1,19 @@
+1:10.3.39-0+deb10u1 [Sat, 03 Jun 2023 18:57:44 -0700] Otto Kekäläinen <otto@debian.org>:
+
+  * New upstream version 10.3.39. Includes security fixes for:
+    - CVE-2022-47015
+  * According to https://mariadb.org/about/#maintenance-policy this
+    was the last minor maintenance release for MariaDB 10.3 series
+  * Add patch to revert upstream libmariadb API change (Closes: #1031773)
+  * Make SysV init script explicit on its dependencies (Related: #1035949)
+
+1:10.3.38-0+deb10u1 [Thu, 09 Feb 2023 21:59:32 -0800] Otto Kekäläinen <otto@debian.org>:
+
+  [ Otto Kekäläinen ]
+  * New upstream version 10.3.38. Includes fix for a major
+    performance/memory consumption issue (MDEV-29988).
+  * Upstream 10.3.35 included fix for MDEV-27937 (Closes: #1008629)
+
 1:10.3.36-0+deb10u2 [Fri, 30 Sep 2022 13:07:30 +0200] Emilio Pozuelo Monfort <pochu@debian.org>:
 
   * Rebuild without upstream extra debian/ files (including a trigger

<http://piuparts.knut.univention.de/5.0-3/#4740617203590200105>
Comment 2 Philipp Hahn univentionstaff 2023-06-05 11:51:08 CEST
OK: bug
OK: yaml
OK: announce_errata
OK: patch
~OK: piuparts
 files owned by common mariadb package

[5.0-3] 5186a9e160 Bug #56117: mariadb-10.3 1:10.3.39-0+deb10u1
 doc/errata/staging/mariadb-10.3.yaml | 12 +-----------
 1 file changed, 1 insertion(+), 11 deletions(-)

[5.0-3] 0a9bcfc07e Bug #56117: mariadb-10.3 1:10.3.39-0+deb10u1
 doc/errata/staging/mariadb-10.3.yaml | 22 ++++++++++++++++++++++
 1 file changed, 22 insertions(+)