[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-06-19 Thread Eduardo Barretto
Thanks again Otto for preparing this package update! As mentioned above this is now published :) ** Changed in: mariadb (Ubuntu) Status: New => Fix Released ** Changed in: mariadb-10.6 (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-06-19 Thread Launchpad Bug Tracker
This bug was fixed in the package mariadb-10.6 - 1:10.6.18-0ubuntu0.22.04.1 --- mariadb-10.6 (1:10.6.18-0ubuntu0.22.04.1) jammy-security; urgency=medium * Update gdb.conf to be aligned with other branches and easier to maintain * Update upstream signing key * SECURITY UPDATE:

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-06-19 Thread Launchpad Bug Tracker
This bug was fixed in the package mariadb - 1:10.11.8-0ubuntu0.23.10.1 --- mariadb (1:10.11.8-0ubuntu0.23.10.1) mantic-security; urgency=medium * Update gdb.conf to be aligned with other branches and easier to maintain * SECURITY UPDATE: New upstream version 10.11.8 includes

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-06-19 Thread Launchpad Bug Tracker
This bug was fixed in the package mariadb - 1:10.11.8-0ubuntu0.24.04.1 --- mariadb (1:10.11.8-0ubuntu0.24.04.1) noble-security; urgency=medium * SECURITY UPDATE: New upstream version 10.11.8 includes fixes for regressions as noted at

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-06-18 Thread Eduardo Barretto
I'm publishing the update first thing tomorrow morning, so far everything looks good. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2067125 Title: CVE-2024-21096 et al affects MariaDB in Ubuntu To

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-06-18 Thread Otto Kekäläinen
Updated branch links to have correct (new) naming scheme. Thanks Dave for triggering autopkgtests. Back in January 2024 I was still able to do it myself (https://bugs.launchpad.net/ubuntu/+source/mariadb/+bug/2045452/comments/18), I wonder what changed. I now checked

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-06-18 Thread Eduardo Barretto
Hi Otto, I've uploaded yesterday the 3 updates to our security-proposed ppa: https://launchpad.net/~ubuntu-security-proposed/+archive/ubuntu/ppa/+packages?field.name_filter=mariadb_filter=published_filter= I will take a look at the autopkgtests we have in that ppa and, if everything is looking

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-06-18 Thread Eduardo Barretto
** Changed in: mariadb (Ubuntu Mantic) Assignee: (unassigned) => Eduardo Barretto (ebarretto) ** Changed in: mariadb (Ubuntu Noble) Assignee: (unassigned) => Eduardo Barretto (ebarretto) ** Changed in: mariadb-10.6 (Ubuntu Jammy) Assignee: (unassigned) => Eduardo Barretto

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-06-17 Thread Dave Jones
Triggered autopkgtests via requested link, and added targetting for affected series (and package). ** Also affects: mariadb-10.6 (Ubuntu) Importance: Undecided Status: New ** Also affects: mariadb (Ubuntu Noble) Importance: Undecided Status: New ** Also affects: mariadb-10.6

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-06-16 Thread Otto Kekäläinen
The above MRs have been merged without further commits. We are aware that there still is an issue with pristine-tar/xdelta3 version compatibilities (https://salsa.debian.org/salsa-ci- team/pipeline/-/issues/326) and we know that Ubuntu-specific autopkgtests can't be triggered for testing anymore

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-06-16 Thread Otto Kekäläinen
** Package changed: mariadb-10.3 (Ubuntu) => mariadb (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2067125 Title: CVE-2024-21096 et al affects MariaDB in Ubuntu To manage notifications

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-06-12 Thread Eduardo Barretto
Hi Otto, all look good, if you are ok I will proceed with the sponsoring -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2067125 Title: CVE-2024-21096 et al affects MariaDB in Ubuntu To manage

Re: [Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-06-11 Thread Otto Kekäläinen
I was waiting for some feedback. If you have none, I will merge as-is. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2067125 Title: CVE-2024-21096 et al affects MariaDB in Ubuntu To manage

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-06-11 Thread Eduardo Barretto
Hey Otto, sorry, I was off for a few days. So should I go ahead with the sponsor or do you want to merge things first? Either work well for me and I can continue with the sponsoring this week still. -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-06-06 Thread Otto Kekäläinen
Eduardo, old notes about xdelta3/pristine-tar incompatibility in https://salsa.debian.org/salsa-ci-team/pipeline/-/issues/326. Do you have any feedback about the import otherwise? I could update and finalize it content-wise. ** Bug watch added: salsa.debian.org/salsa-ci-team/pipeline/-/issues

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-05-30 Thread Eduardo Barretto
Hey Otto, sorry for the delay, the branches look good, and I could successfully build the package and check the diff with the PR, but I again had to bypass that issue with gbp not generating the orig tarball correctly. I'm investigating this issue a bit more to see what is going on. -- You

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-05-27 Thread Eduardo Barretto
Hi Otto, Thanks for preparing the updates! I will be taking a look at the PRs between today and tomorrow -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2067125 Title: CVE-2024-21096 et al affects

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-05-26 Thread Otto Kekäläinen
https://salsa.debian.org/mariadb-team/mariadb-server/-/merge_requests/84 (Prepare MariaDB Server 1:10.6.18-0ubuntu0.22.04.1 for upload to Ubuntu) Let's focus on the review (and fixes) in the first MR!82 first, and only after it is uploaded and everything went fine proceed with the two others. --

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-05-25 Thread Otto Kekäläinen
https://salsa.debian.org/mariadb-team/mariadb-server/-/merge_requests/83 (Prepare MariaDB Server 1:10.11.8-0ubuntu0.23.10.1 for upload to Ubuntu) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2067125

[Bug 2067125] Re: CVE-2024-21096 et al affects MariaDB in Ubuntu

2024-05-24 Thread Otto Kekäläinen
Unlike previous times such as LP#2045452, this time I am trying a new way to ask for review at https://salsa.debian.org/mariadb-team/mariadb- server/-/merge_requests/82 (Prepare MariaDB Server 1:10.11.8-0ubuntu0.24.04.1 for upload to Ubuntu) -- You received this bug notification because you are