The following Fedora EPEL 8 Security updates need testing: Age URL 6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-52e0512741 java-latest-openjdk-19.0.2.0.7-1.rolling.el8 The following builds have been pushed to Fedora EPEL 8 updates-testing davix-0.8.4-1.el8 retsnoop-0.9.4-2.el8 syncthing-1.23.1-1.el8 syslog-ng-3.23.1-3.el8 Details about builds: ================================================================================ davix-0.8.4-1.el8 (FEDORA-EPEL-2023-a85967f326) Toolkit for http based file management -------------------------------------------------------------------------------- Update Information: Davix 0.8.4 -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 7 2023 Mattias Ellert <mattias.ellert@xxxxxxxxxxxxx> - 0.8.4-1 - New upstream release 0.8.4 - Drop patches accepted upstream * Tue Jan 24 2023 Mattias Ellert <mattias.ellert@xxxxxxxxxxxxx> - 0.8.3-4 - Rebuild for gtest 1.13.0 - Don't downgrade the C++ version * Thu Jan 19 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.8.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Wed Dec 21 2022 Mattias Ellert <mattias.ellert@xxxxxxxxxxxxx> - 0.8.3-2 - Rebuild against gsoap-2.8.124 (bug #2155567) -------------------------------------------------------------------------------- ================================================================================ retsnoop-0.9.4-2.el8 (FEDORA-EPEL-2023-f8b2e6e08b) A tool for investigating kernel error call stacks -------------------------------------------------------------------------------- Update Information: `retsnoop` 0.9.4: - fix IP (instruction pointer) fetching on non-x86_64 architectures on older kernels; - handle io_uring source code files better, after Linux code reorganization; - automatically pick debugfs (/sys/kernel/debug/tracing) or tracefs (/sys/kernel/tracing), whichever is available; - handle very old kernels that don't support BPF global data more gracefully. -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 7 2023 Michel Alexandre Salim <salimma@xxxxxxxxxxxxxxxxx> - 0.9.4-2 - Update vendored dependencies - also generate bundled provides (courtesy of zincati's bundled- provides.jq) * Tue Feb 7 2023 Michel Alexandre Salim <salimma@xxxxxxxxxxxxxxxxx> - 0.9.4-1 - Update to 0.9.4 * Tue Feb 7 2023 Michel Alexandre Salim <salimma@xxxxxxxxxxxxxxxxx> - 0.9.3-2 - Explicitly require llvm -------------------------------------------------------------------------------- References: [ 1 ] Bug #2167831 - retsnoop-0.9.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2167831 -------------------------------------------------------------------------------- ================================================================================ syncthing-1.23.1-1.el8 (FEDORA-EPEL-2023-eb9b142b95) Continuous File Synchronization -------------------------------------------------------------------------------- Update Information: Update to version 1.23.1. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.23.1 -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 7 2023 Fabio Valentini <decathorpe@xxxxxxxxx> - 1.23.1-1 - Update to version 1.23.1 -------------------------------------------------------------------------------- ================================================================================ syslog-ng-3.23.1-3.el8 (FEDORA-EPEL-2023-31e354d8e4) Next-generation syslog server -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2022-38725 -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 6 2023 Peter Czanik <peter@xxxxxxxxx> - 3.23.1-3 - add 4110.diff to fix CVE-2022-38725 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2164618 - CVE-2022-38725 syslog-ng: integer overflow in the RFC3164 parser can lead to DoS https://bugzilla.redhat.com/show_bug.cgi?id=2164618 -------------------------------------------------------------------------------- _______________________________________________ epel-devel mailing list -- epel-devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to epel-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/epel-devel@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue