Bug#989069: nvidia-driver: Crash when displayport is plugged.

2021-05-24 Thread Christian Marillat
On 25 mai 2021 08:10, Andreas Beckmann wrote: > Control: forwarded -1 > https://forums.developer.nvidia.com/t/465-24-02-page-fault/175782 > Control: tag -1 upstream > Control: found -1 465.27-1 > > On 25/05/2021 07.29, Christian Marillat wrote: >> Computer doesn't start when my display is plugged

Bug#989069: nvidia-driver: Crash when displayport is plugged.

2021-05-24 Thread Andreas Beckmann
Control: forwarded -1 https://forums.developer.nvidia.com/t/465-24-02-page-fault/175782 Control: tag -1 upstream Control: found -1 465.27-1 On 25/05/2021 07.29, Christian Marillat wrote: Computer doesn't start when my display is plugged to the displayport. Computer crash when I plug the same di

Bug#989070: RM: mmseqs2 [armel armhf i386 mipsel] -- ROM; Upstream does not support 32-bit systems

2021-05-24 Thread Michael R. Crusoe
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: cru...@debian.org Thanks!

Bug#987906: release-notes: mention non-deterministic SCSI device probing?

2021-05-24 Thread Lucas Nussbaum
Hi, On 24/05/21 at 21:38 +0200, Paul Gevers wrote: > On 01-05-2021 22:55, Lucas Nussbaum wrote: > > One of the change that occured in the kernel side since bullseye that is > > SCSI device probing is now non-deterministic. > > > > We have been bitten by that at $dayjob because we were still relyi

Bug#989069: nvidia-driver: Crash when displayport is plugged.

2021-05-24 Thread Christian Marillat
Package: nvidia-driver Version: 460.80-1 Severity: Serious Dear Maintainer, Bug report done against the testing 460.73.01-1 package as the unstable package 460.80-1 is unusable. Computer doesn't start when my display is plugged to the displayport. Computer crash when I plug the same display on

Bug#989068: ITP: object-cloner -- Java Object cloning library with extensible strategies

2021-05-24 Thread James Valleroy
Package: wnpp Severity: wishlist Owner: James Valleroy X-Debbugs-Cc: debian-de...@lists.debian.org, jvalle...@mailbox.org -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 * Package name: object-cloner Version : 0.2 Upstream Author : Kamran Zafar * URL : https://github

Bug#988886: adminer: CVE-2021-29625: XSS in doc_link

2021-05-24 Thread Salvatore Bonaccorso
On Mon, May 24, 2021 at 10:43:50PM +0200, Moritz Mühlenhoff wrote: > Am Fri, May 21, 2021 at 12:39:42PM +0200 schrieb Alexandre Rossi: > > bullseye : this bug is not RC, so no update. > > Security bugs can still be fixed in they are sensibly backportable, > even if not RC. Simply upload to unstabl

Bug#989066: torrent no fun

2021-05-24 Thread dduehren
Package: installation-reports See comments Boot method: Image version: Date: Machine: Processor: Memory: Partitions: Output of lspci -knn (or lspci -nn): Base System Installation Checklist: [O] = OK, [E] = Error (please elaborate below), [ ] = didn't try it Initial boot

Bug#989066: torrent no fun

2021-05-24 Thread Lou Poppler
On Mon, 2021-05-24 at 15:19 -0700, ddueh...@verizon.net wrote: > > Comments/Problems: > > It’s far easier to just download an image than to try to figure out how to > download via bittorrent.   The downloads are small enough that I can wait for them to download.  I spent much more time finding

Bug#989063: open-invaders: Sometimes segfaults during gameplay due to array overrun

2021-05-24 Thread John G
Package: open-invaders Version: 0.3-4.3+b1 Severity: normal Tags: patch Dear Debian QA Team, The program occasionally segfaults during gameplay. A core dump shows that the problem is caused by the collision detection routine writing out of bounds on an array. Specifically, collision_detection(

Bug#980963: dpkg: Please add ARC architecture

2021-05-24 Thread Vineet Gupta
Hi Guillem, On 3/26/21 10:39 AM, Vineet Gupta wrote: > On 3/4/21 3:56 PM, Vineet Gupta wrote: >>> Also just to make sure, the GNU triplets are: >>> >>>    arc-linux-gnu >>>    arceb-linux-gnu >>> No ABI modifiers (stuff like “eabi”) for the libc part (“gnu“) right? >> Actually it seems we are mi

Bug#950150: Still present in bullseye

2021-05-24 Thread awq6mmxgfse
Dear maintainer this exact behavior is still present in the current bullseye build under Gnome (Wayland). 'apt policy audacity audacity: ... Version table: 2.4.2~dfsg0-4 -1 990 http://deb.debian.org/debian bullseye/main amd64 Packages 300 http://deb.debian.org/debian unsta

Bug#989053: debdelta: Problems with signatures

2021-05-24 Thread Ilari Halminen
Package: debdelta Version: 0.62 Severity: normal Dear Maintainer, I cannot use debdelta at all, because it complains of missing signatures. I do not know if the problems has something to do with my systems special options like still using inittab. I have included a file with all messages so yo

Bug#987377: rescue-mode: when in graphical mode, locks up one prompt before the shell

2021-05-24 Thread Cyril Brulebois
Hi Étienne, Étienne Mollier (2021-05-24): > I admit having checkout out from time to time some of the other open > bugs blocking the release of d-i for bullseye, although I haven't been > following accurately wether the appropriate fix landed in daily builds > yet, so thanks for your ping in that

Bug#988814: unblock: gtk+2.0/2.24.33-2

2021-05-24 Thread Cyril Brulebois
Hi again, Cyril Brulebois (2021-05-21): > Paul Gevers (2021-05-20): > > Ok from my side. As this upload is to fix the d-i issue I'm pretty > > sure that debian-boot is also fine, but I promised kibi this morning > > that I'll follow the process and wait for an explicit ACK from their > > side. >

Bug#989067: CVE-2021-32613

2021-05-24 Thread Moritz Muehlenhoff
Package: radare2 Severity: important Tags: security X-Debbugs-Cc: Debian Security Team CVE-2021-32613 https://github.com/radareorg/radare2/issues/18679 https://github.com/radareorg/radare2/commit/049de62730f4954ef9a642f2eeebbca30a8eccdc Cheers, Moritz

Bug#905456: Please create new list debian-clojure

2021-05-24 Thread Utkarsh Gupta
Hi Alex, On Mon, May 24, 2021 at 11:22 PM Alexander Wirt wrote: > > Ack, please send me the gpg encrypted list of subscribers and I will > > provide the new list asap. > jftr, I created the list, it is ready to use. I will import the > subscribers as soon as I receive them. Thanks a bunch! \o/

Bug#989065: Show packages from next-point-release.txt in source package overview

2021-05-24 Thread Moritz Muehlenhoff
Package: security-tracker Severity: wishlist https://security-tracker.debian.org/tracker/source-package/foo shows CVEs tagged as "vulnerable (no DSA)". If there's an update pending (i.e. if a CVE is listed in data/next-point-release.txt) it could instead be presented as "pending for next point re

Bug#988963: upgrade-reports: upgrade process requires a second "apt full-upgrade"

2021-05-24 Thread Bill Allombert
On Mon, May 24, 2021 at 08:44:55PM +0200, Paul Gevers wrote: > Hi, > > On 23-05-2021 08:55, Bill Allombert wrote: > > On Sat, May 22, 2021 at 11:01:54PM +0200, Paul Gevers wrote: > >> Hi Bill, > >> > >> On 22-05-2021 21:42, Bill Allombert wrote: > >>> Do you have a list of packages whose upgrade t

Bug#989064: curl: output of -w accidentally in microseconds

2021-05-24 Thread Bernd Zeimetz
Package: curl Version: 7.74.0-1.2 Severity: serious Tags: patch upstream Hi, ymmv, but as there are probably zillions of scripts out there parsing the output of curl -w, I think switching to microseconds accidentally will break enough things to warrant a serious bug. Upstream bug is https://gith

Bug#989057: udev doesn't create /dev/fd symlink

2021-05-24 Thread Michael Biebl
Am 24.05.2021 um 22:32 schrieb Mikulas Patocka: On Mon, 24 May 2021, Michael Biebl wrote: Am 24.05.2021 um 21:26 schrieb Mikulas Patocka: Init: sysvinit (via /sbin/init) systemd does create those symlinks. I was told, sysvinit (initscripts) would do the same. Can you reproduce the issue

Bug#989061: Update protobuf to new upstream 3.15.5 or later

2021-05-24 Thread Pirate Praveen
Package: ruby-google-protobuf Version: 3.14.0-1 Severity: wishlist I'm trying to update ruby-pg-query to 2.0.3 (required for gitlab 13.12.0) and build fails with /usr/lib/ruby/vendor_ruby/rubygems/dependency.rb:307:in `to_specs': Could not find 'google-protobuf' (~> 3.15.5) among 57 total gem

Bug#989062: CVE-2021-25287 CVE-2021-25288 CVE-2021-28675 CVE-2021-28676 CVE-2021-28677 CVE-2021-28678

2021-05-24 Thread Moritz Muehlenhoff
Source: pillow Version: 8.1.2+dfsg-0.1 Severity: important Tags: security X-Debbugs-Cc: Debian Security Team Fixed in experimental, but open for bullseye/sid: https://pillow.readthedocs.io/en/stable/releasenotes/8.2.0.html#cve-2021-28678-fix-blp-dos https://github.com/python-pillow/Pillow/commit

Bug#987430: upgrade-reports: KDE Plasma without panels and without background after upgrade from Buster to Bullseye

2021-05-24 Thread Norbert Preining
Hi Malvin, > > > I have now upgraded three different machines from (fully updated) Buster > > > to Bullseye, and all three times KDE Plasma was not usable afterwards. And I have now tried the update myself, successfully: - install debian buster wit KDE desktop - log into plasma, play around - do

Bug#989060: CVE-2021-28902 CVE-2021-28903 CVE-2021-28904 CVE-2021-28905 CVE-2021-28906

2021-05-24 Thread Moritz Muehlenhoff
Source: libyang Severity: important Tags: security X-Debbugs-Cc: Debian Security Team CVE-2021-28906 https://github.com/CESNET/libyang/issues/1455 CVE-2021-28905 https://github.com/CESNET/libyang/issues/1452 CVE-2021-28904 https://github.com/CESNET/libyang/issues/1451 CVE-2021-28903 https://gi

Bug#989057: udev doesn't create /dev/fd symlink

2021-05-24 Thread Mikulas Patocka
On Mon, 24 May 2021, Michael Biebl wrote: > Am 24.05.2021 um 21:26 schrieb Mikulas Patocka: > > > Init: sysvinit (via /sbin/init) > > systemd does create those symlinks. > I was told, sysvinit (initscripts) would do the same. > > Can you reproduce the issue with systemd as PID 1? With syste

Bug#988886: adminer: CVE-2021-29625: XSS in doc_link

2021-05-24 Thread Moritz Mühlenhoff
Am Fri, May 21, 2021 at 12:39:42PM +0200 schrieb Alexandre Rossi: > bullseye : this bug is not RC, so no update. Security bugs can still be fixed in they are sensibly backportable, even if not RC. Simply upload to unstable and ask for an unblock. Cheers, Moritz

Bug#989045: gnome-control-center: Region+Language panel segfault after trying to add new input source

2021-05-24 Thread Simon McVittie
On Mon, 24 May 2021 at 16:46:54 +0100, Will Tuladhar-Douglas wrote: > Whenever gnome control panel is open to the Language and Region screen, > if one selects the "+" icon to add a new input source, there's a > segfault. This isn't crashing for me, but I might be able to get somewhere with it if y

Bug#989059: intel-mkl: autopkgtest regression since February 2021: libgcc-8-dev removed

2021-05-24 Thread Paul Gevers
Source: intel-mkl Version: 2020.4.304-1 User: debian...@lists.debian.org Usertags: regression X-Debbugs-CC: debian...@lists.debian.org Dear maintainer, Your package has an autopkgtest, great! However, since the beginning of this year it started to fail [1]. Looking at the error, it's because libg

Bug#932177: Please include apparmor profile directly in the package

2021-05-24 Thread Eduard Bloch
Hallo, * Laurent Bigonville [Tue, Jul 16 2019, 11:55:52AM]: > Package: apt-cacher-ng > Version: 3.2-2 > Severity: wishlist > > Hi, > > Currectly, the apparmor-profiles-extra package includes a profile for > apt-cacher-ng (/etc/apparmor.d/usr.sbin.apt-cacher-ng) > > IMVHO, it would be better if it w

Bug#989057: udev doesn't create /dev/fd symlink

2021-05-24 Thread Michael Biebl
Am 24.05.2021 um 21:26 schrieb Mikulas Patocka: Init: sysvinit (via /sbin/init) systemd does create those symlinks. I was told, sysvinit (initscripts) would do the same. Can you reproduce the issue with systemd as PID 1?

Bug#989058: dumpasn1: new upstream version 20200928

2021-05-24 Thread Daniel Kahn Gillmor
Package: dumpasn1 Version: 20191022-2 Severity: wishlist Tags: patch Peter Gutmann released dumpasn1 20200928 last year. It'd be great to have it in debian, as it includes a default configuration with many more OIDs than the version currently patched. I looked into the packaging and it looks lik

Bug#987906: release-notes: mention non-deterministic SCSI device probing?

2021-05-24 Thread Paul Gevers
Control: tags -1 patch Hi, On 01-05-2021 22:55, Lucas Nussbaum wrote: > One of the change that occured in the kernel side since bullseye that is > SCSI device probing is now non-deterministic. > > We have been bitten by that at $dayjob because we were still relying on > disks ordering (sda, sdb)

Bug#989057: udev doesn't create /dev/fd symlink

2021-05-24 Thread Mikulas Patocka
Package: udev Version: 248.3-1 Severity: important Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? I ran lvm2 testsuite and every test fails. I analyzed the problem, it turns out that the "/dev/fd" symlink is mis

Bug#989047: lynx: broken handling (double slashes) of relative links

2021-05-24 Thread Thomas Dickey
On Mon, May 24, 2021 at 07:21:45PM +0200, Thorsten Glaser wrote: > Package: lynx > Version: 2.9.0dev.6-2 > Severity: normal > X-Debbugs-Cc: t...@mirbsd.de > > Affected: Lynx Version 2.9.0dev.6 (Debian 2.9.0dev.6-2) > Not affected: Lynx Version 2.8.8dev.16-MirOS-0AB8.1 > > $ lynx http://www.mirbsd

Bug#988998: lava: autopkgtest needs update for new version of pyyaml

2021-05-24 Thread Paul Gevers
Control: tags -1 - moreinfo Hi Stefano, On 23-05-2021 01:42, Stefano Rivera wrote: > Hi Paul (2021.05.22_15:22:35_-0400) >> Currently this regression is blocking the migration of pyyaml to testing >> [1]. Of course, pyyaml shouldn't just break your autopkgtest (or even >> worse, your package), bu

Bug#989056: rabbitmq-server: CVE-2021-22116: improper input validation may lead to DoS

2021-05-24 Thread Salvatore Bonaccorso
Source: rabbitmq-server Version: 3.8.9-3 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for rabbitmq-server. CVE-2021-22116[0]: | improper input validation may lead to DoS Reference is at [1] thoug

Bug#989055: libapache2-mod-auth-openidc: CVE-2021-20718

2021-05-24 Thread Salvatore Bonaccorso
Source: libapache2-mod-auth-openidc Version: 2.4.4.1-1 Severity: grave Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for libapache2-mod-auth-openidc. CVE-2021-20718[0]: | mod_auth_openidc 2.4.0 to 2.4.7 allows a remot

Bug#989054: puma: CVE-2021-29509: Keepalive Connections Causing Denial Of Service in puma

2021-05-24 Thread Salvatore Bonaccorso
Source: puma Version: 4.3.6-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for puma, it is caused due to an incomplete fix for CVE-2019-16770. CVE-2021-29509[0]: | Pu

Bug#988627: unblock: broadcom-sta/6.30.223.271-16.1

2021-05-24 Thread Paul Gevers
Hi Roger, On 24-05-2021 19:05, Roger Shimizu wrote: >> control: retitle -1 unblock: broadcom-sta/6.30.223.271-17 >> >> unblock broadcom-sta/6.30.223.271-17 > > ping. > > I'm asking because this package is marked as autoremoval from testing > on June 8th. Although of course slightly annoying for

Bug#989052: wims-lti: [INTL:nl] Dutch translation of debconf messages

2021-05-24 Thread Frans Spiesschaert
Package: wims-lti Severity: wishlist Tags: l10n patch Dear Maintainer, Please find attached the updated Dutch translation of wims-lti debconf messages. It has been submitted for review to the debian-l10n-dutch mailing list. Please add it to your next package revision. It should

Bug#988963: upgrade-reports: upgrade process requires a second "apt full-upgrade"

2021-05-24 Thread Paul Gevers
Hi, On 23-05-2021 08:55, Bill Allombert wrote: > On Sat, May 22, 2021 at 11:01:54PM +0200, Paul Gevers wrote: >> Hi Bill, >> >> On 22-05-2021 21:42, Bill Allombert wrote: >>> Do you have a list of packages whose upgrade triggers this issue ? >> >> https://bugs.debian.org/cgi-bin/bugreport.cgi?att=

Bug#989040: linux-image-5.10.0-6-amd64: Missing CONFIG_AMD_MEM_ENCRYPT in kernel config makes SEV booting impossible

2021-05-24 Thread Louis Bouchard
Package: src:linux Version: 5.10.28-1 Severity: important Dear Kernel team, As previously reported in bug #959069 (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=959069) for kernel 5.5.0-2, the config parameter CONFIG_AMD_MEM_ENCRYPT is missing and, hence, booting an Debian Buster image in

Bug#989051: mrc: FTBFS on hppa - obj/mrc_rsrc.o created with wrong OS/ABI

2021-05-24 Thread John David Anglin
Source: mrc Version: 1.2.3-2 Severity: normal Dear Maintainer, The build fails with the following error: make[1]: Entering directory '/<>' >> mrc.cpp >> dummy.cpp g++ -std=c++17 -o mrc-bootstrap obj/mrc.o obj/dummy.o -L/usr/lib/hppa-linux-gnu -lboost_program_options ./mrc-bootstrap -o obj/mrc_

Bug#989050: syncplay: Please consider splitting the package into a client and server package

2021-05-24 Thread Johannes Schauer Marin Rodrigues
Package: syncplay Version: 1.6.7+repack1-5 Severity: normal Hi, currently, the syncplay package includes the client as well as the server. This means that a server installation also includes the heavy dependencies that are only needed for the client. Installing syncplay on a bare-bones Debian sys

Bug#989049: debspawn: privilege escalation via uid reuse

2021-05-24 Thread Helmut Grohne
Package: debspawn Severity: serious Justification: security hole Tags: security When building a package using debspawn, it dynamically allocates a system user that is used to perform the build. Since system users are allocated sequentially, the chosen uid is very likely to collide with a uid outsi

Bug#983727: thinkfan should not ship an example in /etc/thinkfan.yaml

2021-05-24 Thread Michael Biebl
Am 24.05.21 um 19:00 schrieb Michael Biebl: Fwiw, I would do the following: - Move /etc/thinkpad.yaml to /usr/share/doc/thinkpad/examples - Do not remove /etc/thinkpad.conf (automatically) on upgrades Or at least only remove it when it is unmodified[1] and do *not* rename it to dpkg-bak when m

Bug#989048: userv: client doesn't accept numeric UID on command line (probable doc bug)

2021-05-24 Thread Ben Harris
Package: userv Version: 1.2.0 Severity: normal Dear Ian, The userv spec, describing the command-line interface, says: service-user specifies which user is to provide the service. The user may be a login name or a numeric uid, or - to indicate that the service user is to be the same as the call

Bug#989047: lynx: broken handling (double slashes) of relative links

2021-05-24 Thread Thorsten Glaser
Package: lynx Version: 2.9.0dev.6-2 Severity: normal X-Debbugs-Cc: t...@mirbsd.de Affected: Lynx Version 2.9.0dev.6 (Debian 2.9.0dev.6-2) Not affected: Lynx Version 2.8.8dev.16-MirOS-0AB8.1 $ lynx http://www.mirbsd.org/permalinks/wlog2020_e20210207.htm In Advanced mode, naviate to link #68 “loca

Bug#988627: unblock: broadcom-sta/6.30.223.271-16.1

2021-05-24 Thread Roger Shimizu
> control: retitle -1 unblock: broadcom-sta/6.30.223.271-17 > > unblock broadcom-sta/6.30.223.271-17 ping. I'm asking because this package is marked as autoremoval from testing on June 8th. Is there any concern regarding to the unblocking? Thank you! Cheers, -- Roger Shimizu, GMT +9 Tokyo PGP/G

Bug#983727: thinkfan should not ship an example in /etc/thinkfan.yaml

2021-05-24 Thread Michael Biebl
Fwiw, I would do the following: - Move /etc/thinkpad.yaml to /usr/share/doc/thinkpad/examples - Do not remove /etc/thinkpad.conf (automatically) on upgrades - Put up a big fat NEWS entry with instructions how to convert from /etc/thinkpad.conf to /etc/thinkpad.yaml I know, this will leave /etc/thi

Bug#905456: Please create new list debian-clojure

2021-05-24 Thread Alexander Wirt
Hi, > On Wed, 10 Mar 2021 14:23:10 -0800 Elana Hashman wrote: > > On 2021-03-10 11:34, Alexander Wirt wrote: > > > [...] > > > Uh, oh. Yeah, please. > > > > There's been no objections since this email was last sent -- anyone on > > the list who does not want to be migrated over to the new list,

Bug#988967: unblock: mercurial/5.6.1-3

2021-05-24 Thread Stefano Rivera
Control: retitle -1 unblock: mercurial/5.6.1-4 Made one more change to get a build on mips64el: mercurial (5.6.1-4) unstable; urgency=medium * Revert -mno-lra workaround on mips64el, #871514 was fixed. Fixes occasional FTBFS on mips64el. -- Stefano Rivera Sun, 23 May 2021 08:37:06 -040

Bug#989046: libcurl3-gnutls: Please consider packaging 7.76.1

2021-05-24 Thread Colm Buckley
Package: libcurl3-gnutls Version: 7.74.0-1.2~bpo10+1 Severity: important Dear Maintainer, This bug - https://github.com/curl/curl/issues/6825 - is possibly the underlying cause of #831756 and #987187. Given the importance of the git workflow in particular, I'd like to request that you consider pa

Bug#980171: marked as pending in obs-studio

2021-05-24 Thread Jonathan Rubenstein
Bug #980171 in obs-studio reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/multimedia-team/obs-studio/-/commit/bc9e9f60da6c180164c699f0dc850e2af3232cfb This bug

Bug#989045: gnome-control-center: Region+Language panel segfault after trying to add new input source

2021-05-24 Thread Will Tuladhar-Douglas
Package: gnome-control-center Version: 1:3.38.4-1 Severity: normal -- System Information Debian Release: 11.0 Kernel Version: Linux taksaka 5.10.0-7-amd64 #1 SMP Debian 5.10.38-1 (2021-05-20) x86_64 GNU/Linux Package info: Package: gnome-control-center Status: install ok installed Priority: o

Bug#989044: rule change for 4 syslog rotations

2021-05-24 Thread Marc Haber
Package: aide-common Severity: normal https://salsa.debian.org/debian/aide/-/merge_requests/2 Debian has switched to keeping only 4 rotations of syslog instead of 7. Unfortunately this rule change won't make it to bullseye. Greetings Marc

Bug#988707: qthid-fcd-controller: triggers lintian autoreject tag 'bogus-mail-host'

2021-05-24 Thread Antoine Beaupré
On 2021-05-18 15:45:52, Andreas Beckmann wrote: > Source: qthid-fcd-controller > Version: 4.1-5 > Severity: serious > > Hi, > > src:qthid-fcd-controller triggers the lintian autoreject tag > 'bogus-mail-host', > i.e. if the package would be reuploaded today without changes, it would > be automatic

Bug#989043: squid: CVE-2021-31806 CVE-2021-31807 CVE-2021-31808

2021-05-24 Thread Salvatore Bonaccorso
Source: squid Version: 4.13-9 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerabilities were published for squid. CVE-2021-31806[0], CVE-2021-31807[1], CVE-2021-31808[2], see the SuSE bug as well at [3]. If you fix the v

Bug#989042: CVE-2021-3544 CVE-2021-3545 CVE-2021-3546

2021-05-24 Thread Moritz Muehlenhoff
Package: qemu Severity: important Tags: security X-Debbugs-Cc: Debian Security Team Multiple low severity vhost-user-gpu, none merged yet: CVE-2021-3544: multiple memory leaks CVE-2021-3545: information disclosure due to uninitialized memory reads CVE-2021-3546: out-of-bounds write in virgl_cmd_

Bug#988729: [Pkg-rust-maintainers] Bug#988729: CVE-2021-21299

2021-05-24 Thread Moritz Mühlenhoff
Am Wed, May 19, 2021 at 07:39:55PM +0200 schrieb Fabian Grünbichler: > On May 18, 2021 8:42 pm, Moritz Muehlenhoff wrote: > > Source: rust-hyper > > Severity: grave > > Tags: security > > X-Debbugs-Cc: Debian Security Team > > > > CVE-2021-21299: > > https://github.com/hyperium/hyper/security/adv

Bug#989038: kactivitymanagerd: KDE settings "activities:current" drives all activities to show the last "current activity" I setted

2021-05-24 Thread kmchen
Package: kactivitymanagerd Version: 5.20.5-1 Severity: important X-Debbugs-Cc: t...@webologix.com Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? Not shure but I think it happend with Bullseye version. * What

Bug#989041: eterm: CVE-2021-33477

2021-05-24 Thread Salvatore Bonaccorso
Source: eterm Version: 0.9.6-6 Severity: grave Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Control: found -1 0.9.6-5 Hi, The following vulnerability was published for eterm. Strictly speaking the severity to RC is overrated, but I think it is sensible to make s

Bug#988696: installation-reports: No network management in LXDE task

2021-05-24 Thread Andriy Grytsenko
Thank you everyone for the analysis. Will check how to make it work correctly, let fix it on the next upload.

Bug#989032: mirror listing update for debian.qontinuum.space

2021-05-24 Thread Qontinuum
Okay, thank you. I also added mips, mipsel, mips64el and s390x to the mirror (I don't know if you have seen it since I forgot to mention it in the comments section) \ Original Message On May 24, 2021, 9:09 AM, Peter Palfrader < wea...@debian.org> wrote: reassign 989032 [www.debi

Bug#988998: lava: diff for NMU version 2020.12-4.1

2021-05-24 Thread stefanor
Hi Antonio (2021.05.24_11:58:22_+) > The lava upstream tests caught a problem with this patch on buster, > please cancel the delayed upload. Cancelled. Great, I missed that. And your upstream PR :) SR -- Stefano Rivera http://tumbleweed.org.za/ +1 415 683 3272

Bug#989039: cdebootstrap: fails to bootstrap Devuan (bug in HTTP implementation)

2021-05-24 Thread Simon Richter
Package: cdebootstrap Version: 0.7.8+b1 Severity: normal Hi, I've tried to bootstrap a Devuan system, with cdebootstrap \ --verbose \ --keyring /tmp/devuan-archive-keyring.gpg \ beowulf /target http://deb.devuan.org/merged This successfully downloads one package, the

Bug#988688: linux-source-5.10: Lenovo ThinkPad Yoga 260 fails to suspend and resume

2021-05-24 Thread Kenichiro MATOHARA
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 sorry. I made a mistake in the address, so I will resend it. - > Could you please provide the kernel logs from when you tried to > suspend your machine? suspended it as follows and extracted it from log file. > $ sudo mount -o remount,sync /

Bug#988574: linux-image-armmp-lpae: ethernet on orange pi plus does not work

2021-05-24 Thread Salvatore Bonaccorso
Hi, FTR, pending now in https://git.kernel.org/pub/scm/linux/kernel/git/sunxi/linux.git/commit/?h=sunxi/fixes-for-5.13 Salvatore

Bug#988992: ds9 WCS

2021-05-24 Thread Ole Streicher
Hi Peter, William, thank you for the detailed report, and for the sample file in the Debian bug report. The effect also happens with the (debianized) version 8.3b1 which is in Debian Experimental. I don't think this directly connected to WCS: The output we see here is %1.8G which looks

Bug#988789: diffoscope: .so files are compared using a binary diff in Android APKs

2021-05-24 Thread Chris Lamb
Chris Lamb wrote: > > APKs (Android app files) often contain Linux ELF shared library files, e.g. > > lib/arm64-v8a/libtor.so. These are only compared using a binary diff, but > > they > > should use the shared library comparison. The output looks like: > > It would be great to fix this for you

Bug#988998: lava: diff for NMU version 2020.12-4.1

2021-05-24 Thread Antonio Terceiro
Hi, On Sun, May 23, 2021 at 11:53:56AM -0400, Stefano Rivera wrote: > Control: tags 988998 + pending > > Dear maintainer, > > I've prepared an NMU for lava (versioned as 2020.12-4.1) and > uploaded it to DELAYED/5. Please feel free to tell me if I > should delay it longer. Thanks for looking in

Bug#987377: rescue-mode: when in graphical mode, locks up one prompt before the shell

2021-05-24 Thread Étienne Mollier
Hi Cyril, Cyril Brulebois, on 2021-05-24: > Étienne Mollier (2021-04-28): > > Device en_US fr_FR > > /dev/sdb1ok ok > > /dev/nvme0n1p1 ok ok > > /dev/md/0ok ok > > /dev/debian-vg/root ok ok [...] > I'm not sure whether you fo

Bug#988789: diffoscope: .so files are compared using a binary diff in Android APKs

2021-05-24 Thread Chris Lamb
forwarded 988789 https://salsa.debian.org/reproducible-builds/diffoscope/-/issues/259 thanks I've forwarded this upstream here: https://salsa.debian.org/reproducible-builds/diffoscope/-/issues/259 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris

Bug#989032: mirror listing update for debian.qontinuum.space

2021-05-24 Thread Peter Palfrader
Qontinuum schrieb am Monday, dem 24. May 2021: > I also added mips, mipsel, mips64el and s390x to the mirror (I don't know if > you have seen it since I forgot to mention it in the comments section) I hadn't, thanks for the reminder. Cheers, -- | .''`. ** Deb

Bug#987686: webkit2gtk breaks balsa autopkgtest: xwd: error: No window with name Balsa exists!

2021-05-24 Thread Alberto Garcia
Control: tags -1 patch On Fri, May 21, 2021 at 09:52:53PM +0200, Paul Gevers wrote: > Oh, with the current downgraded dependency the issue is gone. You can also fix it with the attached patch, it's probably the easiest solution. Berto diff --git a/debian/tests/screenshot b/debian/tests/screensho

Bug#941814: libpopt: leaks memory for leftover arguments

2021-05-24 Thread Milan Broz
Hello, what's the status of the fix/patch in this bug? We see many leaks for cryptsetup in valgrind tests if running under Debian (while other distros apparently do not have this problem) and it seems all reported problems are with poptGetNextOpt ... Thanks, Milan

Bug#950488: buster-pu: package kronosnet/1.8-2

2021-05-24 Thread Michal Arbet
Dear Release team, Adam, I also came across bugs that are in the buster version, and the last answer from the release team is from April 26 2020. Can you please comment ? Can it be uploaded to buster-updates ? It would be nice to close this bug with a decision to let Debian users know about it.

Bug#987766: unblock: open-iscsi/2.1.3-2

2021-05-24 Thread Cyril Brulebois
Hi, Ritesh Raj Sarraf (2021-05-24): > Dear Release Team and Paul, > > I am hopeful that this recent upload of open-iscsi at version 2.1.3-5 > is proper. I request an unblock of this version so that the d-i issue > is fixed. > > The patch was prepared in close co-ordination with Cyril from d-i t

Bug#987766: unblock: open-iscsi/2.1.3-2

2021-05-24 Thread Ritesh Raj Sarraf
Control: retitle -1 unblock: open-iscsi/2.1.3-5 Dear Release Team and Paul, I am hopeful that this recent upload of open-iscsi at version 2.1.3-5 is proper. I request an unblock of this version so that the d-i issue is fixed. The patch was prepared in close co-ordination with Cyril from d-i tea

Bug#989032: mirror listing update for debian.qontinuum.space

2021-05-24 Thread Qontinuum
Package: mirrors Severity: minor User: mirr...@packages.debian.org Usertags: mirror-list Submission-Type: update Site: debian.qontinuum.space Type: leaf Archive-architecture: amd64 arm64 armel armhf i386 mips mips64el mipsel powerpc ppc64el s390x Archive-http: /debian/ Archive-rsync: debian/ Main

Bug#988214: fixed in rails 2:6.0.3.7+dfsg-1

2021-05-24 Thread Utkarsh Gupta
Hi Paul, On Wed, 19 May 2021 22:12:59 +0200 Paul Gevers wrote: > This new rails version renewed its versioned dependency on ruby-marcel. > The new ruby-marcel version doesn't look like a targeted fix, so it > doesn't fit the freeze policy. If I read the changelog correctly, this > dependency is t

Bug#987641: Bug#988830: [pre-approval] unblock e2fsprogs [Was: Bug#987641: e2fsprogs: FTBFS on armel/armhf with a 64-bit kernel]

2021-05-24 Thread Cyril Brulebois
Theodore Y. Ts'o (2021-05-20): > The real world corner cases are if you are using a 32-bit arm binary > on a 64-bit binary, and if you are using a sparc64 system (not an > officially supported Debian arch). I'm not sure if misaligned pointer > accesses are allowed in arm-32 kernel code, but it's

Bug#905456: Please create new list debian-clojure

2021-05-24 Thread Utkarsh Gupta
Hi Alex, On Wed, 10 Mar 2021 14:23:10 -0800 Elana Hashman wrote: > On 2021-03-10 11:34, Alexander Wirt wrote: > > [...] > > Uh, oh. Yeah, please. > > There's been no objections since this email was last sent -- anyone on > the list who does not want to be migrated over to the new list, speak > no

Bug#989037: unblock: rails/2:6.0.3.7+dfsg-1

2021-05-24 Thread Utkarsh Gupta
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: debian-r...@lists.debian.org Hello, Rails was recently affected by 3 CVEs (CVE-2021-2290{2,4} and CVE-2021-22885). I'm attaching a filtered diff for your review; the diff is

Bug#988969: kdenlive crashes on start with "Cyclic dependency detected between" message

2021-05-24 Thread Dennis Filder
Control: retitle -1 kdenlive: fails to start natively under Wayland with "QWaylandGLContext::makeCurrent: eglError: 3009, this: 0x555c4734dcc0" Control: tag -1 upstream Control: severity -1 wishlist X-Debbugs-CC: mar...@kucharczyk.im I'm lowering the severity since native Wayland support in kdenl

Bug#989036: unblock: ruby-marcel/1.0.1+dfsg-2

2021-05-24 Thread Utkarsh Gupta
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: debian-r...@lists.debian.org Hello, We had to bump ruby-marcel to a newer version because the mimemagic dependency - which relies on GPL-licensed mime type data from freedeskt

Bug#989035: nyx: leaks memory

2021-05-24 Thread Dennis Filder
Package: nyx Version: 2.1.0-2.1 Severity: normal nyx leaks memory, 262144 (== 64*4096) bytes every 5 seconds in my case. Under Buster it didn't. Running strace -e trace=mmap -v -ttt -f -p $(pgrep nyx) shows calls to 99483: mmap(NULL, 262144, ...) every 5 seconds. Running dd if=/proc/$

Bug#890947: Tag #890947 as unreproducible

2021-05-24 Thread James Lu
Control: tag 890947 + unreproducible I forgot to follow up with this formally. I've tried changing settings like font, background, etc. from l-g-g-s locally and never got any sort of truncation issues. I suspect that if this happens again, the app will log some errors, maybe in ~/.xsession-errors

Bug#989034: wifi-qr: Pointless package description

2021-05-24 Thread Eduard Bloch
Package: wifi-qr Version: 0.2-1 Severity: normal Dear Maintainer, * What led up to the situation? I was looking for a tool which shares files from PC to Android phone, maybe sending the link via QR. * What was the outcome of this action? apt search has found your package. But reading the

Bug#983357: Netinst crashes xen domU when loading kernel

2021-05-24 Thread Michael Biebl
Hi Phillip Am 24.05.2021 um 06:19 schrieb Cyril Brulebois: trigger to cold plug all devices. Both scripts are set -e. The Xen Virtual Keyboard driver and at least one other driver have always failed to trigger due to having absurdly long modalias, but the error used to be ignored. The kernel

Bug#989032: mirror listing update for debian.qontinuum.space

2021-05-24 Thread Peter Palfrader
reassign 989032 www.debian.org retitle 989032 Monaco missing from countries list tags 989032 = patch thanks Qontinuum schrieb am Monday, dem 24. May 2021: > Submission-Type: update > Site: debian.qontinuum.space > Type: leaf > Archive-architecture: amd64 arm64 armel armhf i386 mips mips64el mipse

Bug#988724: firefox: Firefox 88 unusable on intel gpu

2021-05-24 Thread Kamil Jońca
Mike Hommey writes: > > Can you also provide about:support content for that working firefox 88? Application Basics -- Name: Firefox Version: 88.0.1 Build ID: 20210504152106 Distribution ID: User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:88.0) Gecko/20100101 Firefox/88.0 OS: L