Bug#1053476: [debian-mysql] Bug#1053476: galera-3: CVE-2023-5157

2023-11-19 Thread Salvatore Bonaccorso
Hi Adrian, On Sun, Nov 19, 2023 at 11:10:04PM +0200, Adrian Bunk wrote: > On Thu, Oct 05, 2023 at 09:38:00PM +0200, Salvatore Bonaccorso wrote: > > Hi Otto, > > > > Thanks for the quick followup. > > > > On Wed, Oct 04, 2023 at 08:59:31PM -0700, Otto Kekäläinen wrote: > > > Thanks for reporting

Bug#1053476: [debian-mysql] Bug#1053476: galera-3: CVE-2023-5157

2023-10-05 Thread Salvatore Bonaccorso
Hi Otto, Thanks for the quick followup. On Wed, Oct 04, 2023 at 08:59:31PM -0700, Otto Kekäläinen wrote: > Thanks for reporting this Salvatore! > > Are you aware of what plans upstream has? We are not, basically we require your help for this report for assessing the issue. > The Jira

Bug#1053476: [debian-mysql] Bug#1053476: galera-3: CVE-2023-5157

2023-10-04 Thread Otto Kekäläinen
Thanks for reporting this Salvatore! Are you aware of what plans upstream has? The Jira MDEV-25068 was fixed in Galera 26.4.12 (https://releases.galeracluster.com/galera-4.12/release-notes-galera-26.4.12.txt) in 2022. i don't see any commits on https://github.com/codership/galera/commits/3.x