Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package rspamd for openSUSE:Factory checked 
in at 2026-10-01 16:48:39
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/rspamd (Old)
 and      /work/SRC/openSUSE:Factory/.rspamd.new.1253 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "rspamd"

Thu Oct  1 16:48:39 2026 rev:54 rq:1381867 version:4.2.1

Changes:
--------
--- /work/SRC/openSUSE:Factory/rspamd/rspamd.changes    2026-09-18 
22:09:23.065749699 +0200
+++ /work/SRC/openSUSE:Factory/.rspamd.new.1253/rspamd.changes  2026-10-01 
16:50:18.362213122 +0200
@@ -1,0 +2,71 @@
+Thu Oct  1 10:18:18 UTC 2026 - Marcus Rueckert <[email protected]>
+
+- Update to 4.2.1
+  - Security: fixed several critical memory-safety bugs; upgrading
+    is strongly recommended. A huge chunk size or Content-Length
+    from a peer could cause an HTTP heap overflow, because the body
+    was - sized from that value. Zero-copy HTTP reads could hit a
+    use-after-free when a finish handler replaced the body. An
+    fstring length that cannot be allocated used to wrap and lead
+    to out-of-bounds - writes; it is now refused. Cryptobox now
+    fails closed on low-order public keys; before, an uninitialised
+    shared secret was cached and used to decrypt fuzzy requests.
+  - HTTP: the parser now refuses messages framed by both
+    Content-Length and Transfer-Encoding. It also checks
+    Content-Length and chunk sizes before they overflow. The last
+    trailer of a chunked - message is now finished, chunk framing
+    stays out of encrypted inner bodies, and timeouts apply at the
+    correct I/O stage. lua_http fixes request tuning after DNS and
+    coroutine cleanup on - cancellation. lua_tcp stops after a
+    fatal TLS read and limits how much data it buffers for a stop
+    pattern.
+  - Redis: hiredis no longer aborts on an assertion when Redis is
+    down. Lua no longer reads freed Redis replies. Fuzzy Redis
+    count scans keep the address userdata.
+  - Maps: maps now use the HTTP body length instead of the shared
+    memory size, which fixes garbage in large chunked maps and
+    their cache. A failed reload keeps the previous map. Truncated
+    zstd  frames - are rejected, and /savemap writes the whole map.
+    Reading cdb maps skips the HTTP cache header, and the shared
+    memory mapping no longer leaks on errors.
+  - Fuzzy storage: the TCP backlog is bounded, unauthenticated
+    error replies are rate-metered, and key expiry is enforced for
+    writes and deletes. The backend saturates deduplicated weights
+    instead  of - overflowing and rejects short Redis shingle
+    digests.
+  - DNS: fixed rdns TCP queue accounting, a dropped last byte in
+    TCP packets, malformed reply handling and the retransmit
+    channel lifetime.
+  - Regexps: hyperscan prefiltered regexps are verified per input,
+    and hit counts saturate instead of wrapping. UTF-8 is validated
+    once per search, not on every remaining suffix.
+  - SPF and DKIM: SPF a and mx without a prefix length now match
+    per address family, and the macro digit transformer is applied.
+    Fixed a DKIM header table leak and the l= body check with
+    relaxed - canonicalisation.
+  - URLs and IPv6: the URL parser no longer reads past an IPv6 host
+    at the end of the input, and it treats mapped loopback
+    addresses as local. The URL redirector keys by the raw URL,
+    caps the whole   - redirect chain and resolves relative
+    Location headers. RBL whitelists now work for IPv6 addresses,
+    and multimap supports IPv6 ULA prefixes in Redis maps.
+  - Archives: hardened rar, 7z and libarchive parsing. 7z reads
+    substream sizes and digests per stream, so archives with an
+    unpacked header now list their files. Avast keeps the cached
+    virus  verdict - for archives.
+  - HTML, CSS and MIME: the HTML parser limits the text it inspects
+    per link and no longer treats JSON attachments as HTML. Nested
+    HTML processing and structure exports are bounded without
+    losing - phishing checks. The parser no longer rescans quoted
+    attributes for >, and entity replacements stay within the
+    consumed input. The CSS parser limits the token count while
+    building the block tree  - and no longer swallows the byte
+    after a hex escape. Adjacent MIME encoded words are decoded
+    with their own charsets.
+  - UCL: binary msgpack strings now own their value, which fixes a
+    use-after-free once the input buffer is released. A msgpack map
+    that ends in an empty value now keeps its key.
+  - Rules: Mailchimp is exempt from SUBJ_EXCESS_QP and
+    REPLYTO_EXCESS_QP.
+
+-------------------------------------------------------------------

Old:
----
  rspamd-4.2.0.tar.gz

New:
----
  rspamd-4.2.1.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ rspamd.spec ++++++
--- /var/tmp/diff_new_pack.IpbXjv/_old  2026-10-01 16:50:19.088242304 +0200
+++ /var/tmp/diff_new_pack.IpbXjv/_new  2026-10-01 16:50:19.090242385 +0200
@@ -70,7 +70,7 @@
 %define __builder ninja
 
 Name:           rspamd
-Version:        4.2.0
+Version:        4.2.1
 Release:        0
 Summary:        Spam filtering system
 License:        Apache-2.0

++++++ rspamd-4.2.0.tar.gz -> rspamd-4.2.1.tar.gz ++++++
/work/SRC/openSUSE:Factory/rspamd/rspamd-4.2.0.tar.gz 
/work/SRC/openSUSE:Factory/.rspamd.new.1253/rspamd-4.2.1.tar.gz differ: char 
28, line 1

Reply via email to