Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package thrift for openSUSE:Factory checked 
in at 2026-10-03 20:13:11
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/thrift (Old)
 and      /work/SRC/openSUSE:Factory/.thrift.new.1631729 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "thrift"

Sat Oct  3 20:13:11 2026 rev:24 rq:1382170 version:0.25.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/thrift/thrift.changes    2026-08-19 
17:55:13.923341772 +0200
+++ /work/SRC/openSUSE:Factory/.thrift.new.1631729/thrift.changes       
2026-10-03 20:13:15.849925586 +0200
@@ -1,0 +2,59 @@
+Fri Oct  2 17:51:14 UTC 2026 - Martin Pluskal <[email protected]>
+
+- Update to 0.25.0:
+  * CVE-2026-93925: stack-based buffer overflow in the C++ varint
+    writer, reached through THeaderProtocol frames (boo#1284093)
+  * CVE-2026-91135: heap-based buffer overflow when the ZLIB transform
+    is enabled on C++ THeaderTransport frames (boo#1284100)
+  * CVE-2026-82459: integer underflow in the 32-bit C++
+    THeaderTransport frame size leads to an out-of-bounds write
+    (boo#1284077)
+  * CVE-2026-93926: memory not released after its effective lifetime in
+    THeaderTransport (boo#1284092)
+  * CVE-2026-82458: allocation of resources without limits in the C++
+    protocol reader (boo#1284076)
+  * CVE-2026-85086: the Perl SSLSocket defaulted to SSL_VERIFY_NONE,
+    leaving TLS unauthenticated (boo#1284078)
+  * CVE-2026-85494: improper length handling and uncaught exceptions in
+    the Python, Perl and PHP bindings (boo#1284079)
+  * CVE-2026-91137: unvalidated quantity in PHP input causes unbounded
+    allocation (boo#1284080)
+  * CVE-2026-94642: uncaught exception in the PHP bindings
+    (boo#1284081)
+  * CVE-2026-94644: allocation of resources without limits in the PHP
+    bindings (boo#1284097)
+  * CVE-2026-94634: unbounded allocation and insecure default
+    initialization in the Python bindings (boo#1284099)
+  * CVE-2026-94650: uncontrolled recursion in the c_glib protocol
+    reader (boo#1284082)
+  * CVE-2026-85483: use of an uninitialized resource and a wrong status
+    code in the c_glib bindings (boo#1284102)
+  * CVE-2026-96289: uncontrolled recursion in the PHP bindings
+    (boo#1284112)
+  * CVE-2026-94653: inefficient algorithm complexity in the PHP bindings
+    (boo#1284122)
+  * CVE-2026-96287: inefficient algorithm complexity in the Perl
+    bindings (boo#1284114)
+  * CVE-2026-96286: uncaught exception in the Perl bindings
+    (boo#1284115)
+  * CVE-2026-94654: loop with an unreachable exit condition in the
+    Python bindings (boo#1284121)
+  * The remaining CVEs fixed by this release affect bindings this
+    package does not build and are therefore not affected here:
+    CVE-2026-85493 (boo#1284101, Dart and Java ME)
+    CVE-2026-94635 (boo#1284090, Lua)
+    CVE-2026-94633 (boo#1284091, Dart)
+    CVE-2026-96990 (boo#1284094, Erlang)
+    CVE-2026-94651 (boo#1284095, Java)
+    CVE-2026-94645 (boo#1284096, node.js)
+    CVE-2026-94639 (boo#1284098, Java)
+    CVE-2026-96292 (boo#1284111, Lua)
+    CVE-2026-96288 (boo#1284113, Erlang)
+    CVE-2026-96277 (boo#1284116, Ruby)
+    CVE-2026-94658 (boo#1284117, Lua)
+    CVE-2026-94657 (boo#1284118, Java ME)
+    CVE-2026-94656 (boo#1284119, Ruby)
+    CVE-2026-94655 (boo#1284120, Lua)
+    CVE-2026-86537 (boo#1284123, D).
+
+-------------------------------------------------------------------

Old:
----
  thrift-0.24.0.tar.gz
  thrift-0.24.0.tar.gz.asc

New:
----
  thrift-0.25.0.tar.gz
  thrift-0.25.0.tar.gz.asc

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ thrift.spec ++++++
--- /var/tmp/diff_new_pack.b2HAlW/_old  2026-10-03 20:13:16.961972148 +0200
+++ /var/tmp/diff_new_pack.b2HAlW/_new  2026-10-03 20:13:16.963972232 +0200
@@ -55,15 +55,15 @@
 # which is versioned conventionally. Bump only when the C ABI breaks.
 %global libgversion 0
 Name:           %{pkgname}
-Version:        0.24.0
+Version:        0.25.0
 Release:        0
 # The C++ libraries are built with libtool -release, so the version is baked
-# into the file name (libthrift-0.24.0.so) and there is no libthrift.so.N
+# into the file name (libthrift-0.25.0.so) and there is no libthrift.so.N
 # symlink; the shared library packages therefore have to carry %%{version} in
 # their name. Spelled out rather than derived with %%(echo ... | tr . _),
 # because OBS's spec parser cannot expand %%(...) and warns on every build.
 # %%build asserts that it still matches, so a missed bump is an FTBFS.
-%global libversion 0_24_0
+%global libversion 0_25_0
 Summary:        Framework for scalable cross-language services development
 License:        Apache-2.0
 URL:            https://thrift.apache.org

++++++ thrift-0.24.0.tar.gz -> thrift-0.25.0.tar.gz ++++++
++++ 99878 lines of diff (skipped)

Reply via email to