Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package thrift for openSUSE:Factory checked in at 2026-10-03 20:13:11 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/thrift (Old) and /work/SRC/openSUSE:Factory/.thrift.new.1631729 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "thrift" Sat Oct 3 20:13:11 2026 rev:24 rq:1382170 version:0.25.0 Changes: -------- --- /work/SRC/openSUSE:Factory/thrift/thrift.changes 2026-08-19 17:55:13.923341772 +0200 +++ /work/SRC/openSUSE:Factory/.thrift.new.1631729/thrift.changes 2026-10-03 20:13:15.849925586 +0200 @@ -1,0 +2,59 @@ +Fri Oct 2 17:51:14 UTC 2026 - Martin Pluskal <[email protected]> + +- Update to 0.25.0: + * CVE-2026-93925: stack-based buffer overflow in the C++ varint + writer, reached through THeaderProtocol frames (boo#1284093) + * CVE-2026-91135: heap-based buffer overflow when the ZLIB transform + is enabled on C++ THeaderTransport frames (boo#1284100) + * CVE-2026-82459: integer underflow in the 32-bit C++ + THeaderTransport frame size leads to an out-of-bounds write + (boo#1284077) + * CVE-2026-93926: memory not released after its effective lifetime in + THeaderTransport (boo#1284092) + * CVE-2026-82458: allocation of resources without limits in the C++ + protocol reader (boo#1284076) + * CVE-2026-85086: the Perl SSLSocket defaulted to SSL_VERIFY_NONE, + leaving TLS unauthenticated (boo#1284078) + * CVE-2026-85494: improper length handling and uncaught exceptions in + the Python, Perl and PHP bindings (boo#1284079) + * CVE-2026-91137: unvalidated quantity in PHP input causes unbounded + allocation (boo#1284080) + * CVE-2026-94642: uncaught exception in the PHP bindings + (boo#1284081) + * CVE-2026-94644: allocation of resources without limits in the PHP + bindings (boo#1284097) + * CVE-2026-94634: unbounded allocation and insecure default + initialization in the Python bindings (boo#1284099) + * CVE-2026-94650: uncontrolled recursion in the c_glib protocol + reader (boo#1284082) + * CVE-2026-85483: use of an uninitialized resource and a wrong status + code in the c_glib bindings (boo#1284102) + * CVE-2026-96289: uncontrolled recursion in the PHP bindings + (boo#1284112) + * CVE-2026-94653: inefficient algorithm complexity in the PHP bindings + (boo#1284122) + * CVE-2026-96287: inefficient algorithm complexity in the Perl + bindings (boo#1284114) + * CVE-2026-96286: uncaught exception in the Perl bindings + (boo#1284115) + * CVE-2026-94654: loop with an unreachable exit condition in the + Python bindings (boo#1284121) + * The remaining CVEs fixed by this release affect bindings this + package does not build and are therefore not affected here: + CVE-2026-85493 (boo#1284101, Dart and Java ME) + CVE-2026-94635 (boo#1284090, Lua) + CVE-2026-94633 (boo#1284091, Dart) + CVE-2026-96990 (boo#1284094, Erlang) + CVE-2026-94651 (boo#1284095, Java) + CVE-2026-94645 (boo#1284096, node.js) + CVE-2026-94639 (boo#1284098, Java) + CVE-2026-96292 (boo#1284111, Lua) + CVE-2026-96288 (boo#1284113, Erlang) + CVE-2026-96277 (boo#1284116, Ruby) + CVE-2026-94658 (boo#1284117, Lua) + CVE-2026-94657 (boo#1284118, Java ME) + CVE-2026-94656 (boo#1284119, Ruby) + CVE-2026-94655 (boo#1284120, Lua) + CVE-2026-86537 (boo#1284123, D). + +------------------------------------------------------------------- Old: ---- thrift-0.24.0.tar.gz thrift-0.24.0.tar.gz.asc New: ---- thrift-0.25.0.tar.gz thrift-0.25.0.tar.gz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ thrift.spec ++++++ --- /var/tmp/diff_new_pack.b2HAlW/_old 2026-10-03 20:13:16.961972148 +0200 +++ /var/tmp/diff_new_pack.b2HAlW/_new 2026-10-03 20:13:16.963972232 +0200 @@ -55,15 +55,15 @@ # which is versioned conventionally. Bump only when the C ABI breaks. %global libgversion 0 Name: %{pkgname} -Version: 0.24.0 +Version: 0.25.0 Release: 0 # The C++ libraries are built with libtool -release, so the version is baked -# into the file name (libthrift-0.24.0.so) and there is no libthrift.so.N +# into the file name (libthrift-0.25.0.so) and there is no libthrift.so.N # symlink; the shared library packages therefore have to carry %%{version} in # their name. Spelled out rather than derived with %%(echo ... | tr . _), # because OBS's spec parser cannot expand %%(...) and warns on every build. # %%build asserts that it still matches, so a missed bump is an FTBFS. -%global libversion 0_24_0 +%global libversion 0_25_0 Summary: Framework for scalable cross-language services development License: Apache-2.0 URL: https://thrift.apache.org ++++++ thrift-0.24.0.tar.gz -> thrift-0.25.0.tar.gz ++++++ ++++ 99878 lines of diff (skipped)
