Package: evms
Version: 2.5.2-1
Severity: critical
Justification: causes serious data loss

This is mainly a placeholder bug for my upcoming EVMS upload to stable;
it has already been addressed in unstable (and will eventually progress
to testing). (A -done message informing the BTS about the fact that 2.5.3
fixes it will be sent shortly.)

EVMS prior to 2.5.3 has a buffer overflow when dealing with degraded
RAID-5 volumes; in short, the wrong memory gets overwritten and EVMS
segfaults. This can render the entire system unbootable (since the root
volume might be on RAID-5, and evms_activate crashes upon loading the md
plugin), but I've also seen it eat the RAID-5 superblock.

There is also a bug where the engine might segfault when doing a RAID-5
expand, but AFAIK, all this does is to segfault evms; I haven't seen it
cause data loss. Also, RAID-5 expand is sort of an infrequent use case
anyhow...

The solution is to simply backport the RAID-5 fixes from 2.5.3 into
2.5.2. The two entries from the changelog are:

 - Fix stack corruption bug in MD plugin. [Marcus Meissner]
 - Fix memory corruption bug for RAID-5 regions running in degraded
   mode. [Gleb Stiblo]              

-- System Information:
Debian Release: testing/unstable
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.14
Locale: LANG=en_DK.UTF-8, LC_CTYPE=en_DK.UTF-8 (charmap=UTF-8)

Versions of packages evms depends on:
ii  libc6                         2.3.5-7    GNU C Library: Shared libraries an
ii  libevms-2.5                   2.5.3-6    Enterprise Volume Management Syste

Versions of packages evms recommends:
pn  evms-cli                      <none>     (no description available)
ii  evms-gui                      2.5.3-6    Enterprise Volume Management Syste

-- debconf-show failed


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to