The following Fedora 33 Security updates need testing: Age URL 68 https://bodhi.fedoraproject.org/updates/FEDORA-2021-c3d587d52c shim-15.4-1 6 https://bodhi.fedoraproject.org/updates/FEDORA-2021-bf2458347f glibc-2.32-7.fc33 6 https://bodhi.fedoraproject.org/updates/FEDORA-2021-3d770d7179 mingw-ilmbase-2.4.1-3.fc33 6 https://bodhi.fedoraproject.org/updates/FEDORA-2021-051639aad4 mod_http2-1.15.19-1.fc33 5 https://bodhi.fedoraproject.org/updates/FEDORA-2021-ca59eb65a9 iaito-5.2.2-3.fc33 radare2-5.3.1-1.fc33 2 https://bodhi.fedoraproject.org/updates/FEDORA-2021-24d4e06195 libgcrypt-1.8.8-1.fc33 2 https://bodhi.fedoraproject.org/updates/FEDORA-2021-ff4ad9825a tor-0.4.5.9-1.fc33 2 https://bodhi.fedoraproject.org/updates/FEDORA-2021-3d94c14be4 pdfbox-2.0.24-1.fc33 2 https://bodhi.fedoraproject.org/updates/FEDORA-2021-b96947cc69 libslirp-4.3.1-4.fc33 The following Fedora 33 Critical Path updates have yet to be approved: Age URL 86 https://bodhi.fedoraproject.org/updates/FEDORA-2021-2961f34ccb PackageKit-1.2.3-1.fc33 22 https://bodhi.fedoraproject.org/updates/FEDORA-2021-4797e362b3 abrt-2.14.6-1.fc33 libreport-2.15.1-1.fc33 satyr-0.37-2.fc33 10 https://bodhi.fedoraproject.org/updates/FEDORA-2021-3ddd31eb34 abrt-2.14.6-3.fc33 abrt-java-connector-1.2.0-7.fc33 gnome-abrt-1.3.6-7.fc33 libreport-2.15.2-2.fc33 reportd-0.7.4-10.fc33 8 https://bodhi.fedoraproject.org/updates/FEDORA-2021-8155341fed thunderbird-78.11.0-1.fc33 8 https://bodhi.fedoraproject.org/updates/FEDORA-2021-01c16188fe coreutils-8.32-19.fc33 7 https://bodhi.fedoraproject.org/updates/FEDORA-2021-498d277506 audit-3.0.2-1.fc33 7 https://bodhi.fedoraproject.org/updates/FEDORA-2021-b02a75816e dracut-055-2.fc33 7 https://bodhi.fedoraproject.org/updates/FEDORA-2021-fed63bd217 libxcrypt-4.4.22-2.fc33 pam-1.4.0-11.fc33 6 https://bodhi.fedoraproject.org/updates/FEDORA-2021-1e6c5c95dc gnome-shell-3.38.5-1.fc33 mutter-3.38.5-1.fc33 6 https://bodhi.fedoraproject.org/updates/FEDORA-2021-bf2458347f glibc-2.32-7.fc33 6 https://bodhi.fedoraproject.org/updates/FEDORA-2021-5a73bda4a8 redhat-rpm-config-176-1.fc33 2 https://bodhi.fedoraproject.org/updates/FEDORA-2021-b96947cc69 libslirp-4.3.1-4.fc33 2 https://bodhi.fedoraproject.org/updates/FEDORA-2021-b70a99a8fb grep-3.4-6.fc33 2 https://bodhi.fedoraproject.org/updates/FEDORA-2021-312568e814 createrepo_c-0.17.3-1.fc33 dnf-4.8.0-1.fc33 dnf-plugins-core-4.0.22-1.fc33 dnf-plugins-extras-4.0.15-1.fc33 libcomps-0.1.17-1.fc33 libdnf-0.63.1-1.fc33 librepo-1.14.1-1.fc33 2 https://bodhi.fedoraproject.org/updates/FEDORA-2021-b84d81929a expat-2.4.1-1.fc33 2 https://bodhi.fedoraproject.org/updates/FEDORA-2021-24d4e06195 libgcrypt-1.8.8-1.fc33 0 https://bodhi.fedoraproject.org/updates/FEDORA-2021-335b80f6d0 ca-certificates-2021.2.50-1.0.fc33 0 https://bodhi.fedoraproject.org/updates/FEDORA-2021-081f6d8eeb kernel-5.12.11-200.fc33 kernel-tools-5.12.11-200.fc33 0 https://bodhi.fedoraproject.org/updates/FEDORA-2021-a8b5c5b33c firefox-89.0-2.fc33 0 https://bodhi.fedoraproject.org/updates/FEDORA-2021-443a2c1229 libpcap-1.10.1-1.fc33 tcpdump-4.99.1-1.fc33 The following builds have been pushed to Fedora 33 updates-testing aerc-0.5.2-2.fc33 cozy-1.0.3-1.fc33 dm-zoned-tools-2.1.2-1.fc33 editorconfig-0.12.5-1.fc33 golang-github-facebookincubator-ntp-0-0.3.20210617git69c3282.fc33 linux-system-roles-1.2.3-3.fc33 openssh-8.4p1-7.fc33 perl-POE-Component-IRC-6.93-1.fc33 php-phpmailer6-6.5.0-1.fc33 php-swaggest-json-schema-0.12.34-1.fc33 python-asyncpg-0.23.0-4.fc33 python-pingouin-0.3.12-1.fc33 python-toposort-1.6-1.fc33 rubygem-sequel-5.45.0-2.fc33 rust-zcomponents-0.2.0-1.fc33 satyr-0.38-1.fc33 Details about builds: ================================================================================ aerc-0.5.2-2.fc33 (FEDORA-2021-addcb63b4a) Email client for your terminal -------------------------------------------------------------------------------- Update Information: Initial package -------------------------------------------------------------------------------- ChangeLog: -------------------------------------------------------------------------------- ================================================================================ cozy-1.0.3-1.fc33 (FEDORA-2021-c1859b600e) Modern audiobook player -------------------------------------------------------------------------------- Update Information: Update to v1.0.3 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 17 2021 Artur Frenszek-Iwicki <fedora@xxxxxxxxxx> - 1.0.3-1 - Update to v1.0.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1966420 - cozy-1.0.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1966420 -------------------------------------------------------------------------------- ================================================================================ dm-zoned-tools-2.1.2-1.fc33 (FEDORA-2021-c16e5fdfb9) Provides utilities to format, check and repair Linux dm-zoned devices -------------------------------------------------------------------------------- Update Information: New dm-zoned-tools package to provide the dmzadm utility to format, check and repair zoned block devices used with the dm-zoned device mapper. -------------------------------------------------------------------------------- ChangeLog: -------------------------------------------------------------------------------- ================================================================================ editorconfig-0.12.5-1.fc33 (FEDORA-2021-66e2b16f3a) Parser for EditorConfig files written in C -------------------------------------------------------------------------------- Update Information: Update to version 0.12.5. This release contains only a fix for a small memory leak and no other changes. Release notes: https://github.com/editorconfig/editorconfig-core-c/releases/tag/v0.12.5 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 17 2021 Fabio Valentini <decathorpe@xxxxxxxxx> - 0.12.5-1 - Update to version 0.12.5. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1973182 - editorconfig-0.12.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=1973182 -------------------------------------------------------------------------------- ================================================================================ golang-github-facebookincubator-ntp-0-0.3.20210617git69c3282.fc33 (FEDORA-2021-d015aca124) Facebook's NTP libraries -------------------------------------------------------------------------------- Update Information: Bump to commit 69c32825dbb77fc0ca7b489eb6936b9081ae1195 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 17 2021 Davide Cavalca <dcavalca@xxxxxxxxxxxxxxxxx> - 0-0.3.20210617git69c3282 - Bump to commit 69c32825dbb77fc0ca7b489eb6936b9081ae1195 * Fri Jun 4 2021 Davide Cavalca <dcavalca@xxxxxxxxxxxxxxxxx> - 0-0.3.20210604git160580e - Bump to commit 160580e390d77d1ee3bda25753686b3092b968cd - Add subpackage for leapsectz - Fix changelog * Tue Jan 26 2021 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0-0.3.20210109git81cb02c - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ linux-system-roles-1.2.3-3.fc33 (FEDORA-2021-56059556b2) Set of interfaces for unified system management -------------------------------------------------------------------------------- Update Information: sources - Fix HTML rendering of internal links when using pandoc/asciidoc Uses pandoc gfm instead of markdown_github Make spec file available for older versions of OSes. Drop python3-six dependency which was used by lsr_role2collection.py. Drop html files from rpm if the version has no markdown parser. Drop unnecessary python scripts which include python3 only code, e.g., f-strings. update sources for fix kdump tests_ssh for basic smoke test The rpm package contains collection README.html files only in %_pkgdocdir and its subdirs, but the collection artifact tarball has README.html in each roles/ROLE directory along with README.md. Fixing it to make the collection artifact tarball consistent with the collection part in rpm. fix logging README.html examples' rendering problems fix broken internal links in README.md files Add the requirement for kramdown for Fedora and RHEL 9 builds -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 17 2021 Sergei Petrosian <spetrosi@xxxxxxxxxx> - 1.2.3-3 - Make the ansible_collection_files macro defined in Fedora automatically and in RHEL manually consistent - having slash at the end to clean double-slashes * Wed Jun 16 2021 Sergei Petrosian <spetrosi@xxxxxxxxxx> - 1.2.3-2 - Remove slash (/) from the end of URLs to improve code readability * Wed Jun 16 2021 Noriko Hosoi <nhosoi@xxxxxxxxxx> - 1.2.3-1 - Add EL 9 support for timesync and network Resolves rhbz#1952887 * Tue Jun 15 2021 Rich Megginson <rmeggins@xxxxxxxxxx> - 1.2.2-3 - Fix HTML rendering of internal links when using pandoc/asciidoc - Uses pandoc gfm instead of markdown_github Resolves rhbz#1962976 * Fri Jun 11 2021 Noriko Hosoi <nhosoi@xxxxxxxxxx> - 1.2.2-2 - Make spec file available for older versions of OSes. - Drop python3-six dependency which was used by lsr_role2collection.py. - Drop html files from rpm if the version has no markdown parser. - Drop unnecessary python scripts which include python3 only code, e.g., f-strings. Resolves rhbz#1970165 * Wed Jun 9 2021 Rich Megginson <rmeggins@xxxxxxxxxx> - 1.2.2-1 - fix kdump tests_ssh for basic smoke test Resolves rhbz#1957876 * Fri May 21 2021 Noriko Hosoi <nhosoi@xxxxxxxxxx> - 1.2.1-1 - fix logging README.html examples' rendering problems Resolves rhbz#1962374 - fix broken internal links in README.md files Resolves rhbz#1962976 * Fri May 21 2021 Sergei Petrosian <spetrosi@xxxxxxxxxx> - 1.2.0-2 - Add BuildRequires: rubygem-kramdown for Fedora and RHEL >= 9 * Fri May 14 2021 Rich Megginson <rmeggins@xxxxxxxxxx> - 1.2.0-1 - rebase roles to latest upstream Resolves rhbz#1957876 - make postfix role idempotent Resolves rhbz#1960375 - use FQRN in postfix README Resolves rhbz#1958963 - use relayhost in postfix README Resolves rhbz#1866544 - use lazy unmount to fix umount: target is busy Resolves rhbz#1945359 - network - Add support for ETHTOOL Ring option Resolves rhbz#1959649 - storage: calltrace observed when set type: partition for storage_pools Resolves rhbz#1854187 - ha_cluster - cannot read preshared key in binary format Resolves rhbz#1952620 * Thu May 13 2021 Noriko Hosoi <nhosoi@xxxxxxxxxx> - 1.1.0-2 - Dependencies in the collection packaging Resolves rhbz#1954747 * Wed Apr 14 2021 Rich Megginson <rmeggins@xxxxxxxxxx> - 1.1.0-1 - rebase timesync role to latest upstream Resolves rhbz#1937938 - timesync - add timesync_chrony_custom_settings variable for free-form local configs Resolves rhbz#1938023 - do not use ignore_errors in timesync role Resolves rhbz#1938014 - support for timesync_max_distance to configure maxdistance/maxdist parameter Resolves rhbz#1938016 - support for ntp xleave, filter, and hw timestamping Resolves rhbz#1938020 - rebase selinux role to latest upstream Resolves rhbz#1937938 - should not reload the SELinux policy if its not changed Resolves rhbz#1757869 - Ability to install custom SELinux module via Ansible Resolves rhbz#1848683 - rebase storage role to latest upstream Resolves rhbz#1937938 - rebase network role to latest upstream Resolves rhbz#1937938 - support for ipv6_disabled to disable ipv6 for address Resolves rhbz#1939711 - rebase postfix role to latest upstream Resolves rhbz#1937938 - rebase metrics role to latest upstream Resolves rhbz#1937938 - rebase sshd role to latest upstream Resolves rhbz#1937938 - rebase remaining roles to latest upstream Resolves rhbz#1937938 - Generate %files dynamically - add vpn role Resolves rhbz#1943679 * Tue Apr 13 2021 Noriko Hosoi <nhosoi@xxxxxxxxxx> - 1.0.1-2 - Adding the -collection-artifact subpackage, enabled using "--with collection_artifact". It is used for importing to ansible galaxy/automation hub. - README.html files (main README for the collection and README for each role) are not located in /usr/share/ansible/collections, but just put in /usr/share/doc/linux-system-roles/collection in rpm. - The README.html files are not included in the collection artifact. - Fixing "sshd role README.md examples use incorrect role name". -------------------------------------------------------------------------------- ================================================================================ openssh-8.4p1-7.fc33 (FEDORA-2021-1d3698089d) An open source implementation of SSH protocol version 2 -------------------------------------------------------------------------------- Update Information: Add fix to CVE-2021-28041 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 17 2021 Dmitry Belyavskiy <dbelyavs@xxxxxxxxxx> - 8.4p1-7 - Add fix to CVE-2021-28041 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1935055 - CVE-2021-28041 openssh: double-free memory corruption may lead to arbitrary code execution https://bugzilla.redhat.com/show_bug.cgi?id=1935055 -------------------------------------------------------------------------------- ================================================================================ perl-POE-Component-IRC-6.93-1.fc33 (FEDORA-2021-e69f1c2e75) A POE component for building IRC clients -------------------------------------------------------------------------------- Update Information: This release improves the tests. -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 16 2021 Petr Pisar <ppisar@xxxxxxxxxx> - 6.93-1 - 6.93 bump -------------------------------------------------------------------------------- References: [ 1 ] Bug #1972385 - perl-POE-Component-IRC-6.93 is available https://bugzilla.redhat.com/show_bug.cgi?id=1972385 -------------------------------------------------------------------------------- ================================================================================ php-phpmailer6-6.5.0-1.fc33 (FEDORA-2021-ef548cb234) Full-featured email creation and transfer class for PHP -------------------------------------------------------------------------------- Update Information: **Version 6.5.0** (June 16th, 2021) * **SECURITY** Fixes **CVE-2021-34551**, a complex RCE affecting Windows hosts. See SECURITY.md for details. * The fix for this issue changes the way that language files are loaded. While they remain in the same PHP-like format, they are processed as plain text, and any code in them will not be run, including operations such as concatenation using the `.` operator. * *Deprecation* The current translation file format using PHP arrays is now deprecated; the next major version will introduce a new format. * **SECURITY** Fixes **CVE-2021-3603** that may permit untrusted code to be run from an address validator. See SECURITY.md for details. * The fix for this issue includes a minor BC break: callables injected into `validateAddress`, or indirectly through the `$validator` class property, may no longer be simple strings. If you want to inject your own validator, provide a closure instead of a function name. * Haraka message ID strings are now recognised -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 17 2021 Remi Collet <remi@xxxxxxxxxxxx> - 6.5.0-1 - update to 6.5.0 -------------------------------------------------------------------------------- ================================================================================ php-swaggest-json-schema-0.12.34-1.fc33 (FEDORA-2021-9276bfd59d) High definition PHP structures with JSON-schema based validation -------------------------------------------------------------------------------- Update Information: **Version 0.12.34** - 2021-06-17 Fixed - Suppressed failure during reference resolution. -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 17 2021 Remi Collet <remi@xxxxxxxxxxxx> - 0.12.34-1 - update to 0.12.34 -------------------------------------------------------------------------------- ================================================================================ python-asyncpg-0.23.0-4.fc33 (FEDORA-2021-248b0c2e98) A fast PostgreSQL Database Client Library for Python/asyncio -------------------------------------------------------------------------------- Update Information: Patch `setup.py` so a `BuildRequires` on `python3dist(sphinxcontrib-asyncio)` is not generated when we use `python3dist(sphinxcontrib-trio)` instead. Assorted small packaging improvements. (Thanks to @ksurma.) -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 17 2021 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 0.23.0-4 - Use a patch instead of sed expressions to replace sphinxcontrib-asyncio with sphinxcontrib-trio, so it is easier to notice if the upstream sphinxcontrib-asyncio version requirement changes and we do not silently switch back to sphinxcontrib-asyncio from sphinxcontrib-trio - Stop removing bundled egg-info, since this should not be required with pyproject-rpm-macros - Loosen pinned versions selectively rather than across the board * Thu Jun 17 2021 Karolina Surma <ksurma@xxxxxxxxxx> - 0.23.0-3 - Generate correct BuildRequires by defining them in source setup.py * Fri Jun 4 2021 Python Maint <python-maint@xxxxxxxxxx> - 0.23.0-2 - Rebuilt for Python 3.10 -------------------------------------------------------------------------------- ================================================================================ python-pingouin-0.3.12-1.fc33 (FEDORA-2021-0b3fd45ce4) Statistical package for Python -------------------------------------------------------------------------------- Update Information: Update to latest release -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 17 2021 Ankur Sinha <ankursinha AT fedoraproject DOT org> - 0.3.12-1 - Update to new release * Fri Jun 4 2021 Python Maint <python-maint@xxxxxxxxxx> - 0.3.11-2 - Rebuilt for Python 3.10 * Sat May 22 2021 Ankur Sinha <ankursinha AT fedoraproject DOT org> - 0.3.11-1 - Update to latest release * Sun Mar 28 2021 Ankur Sinha <ankursinha AT fedoraproject DOT org> - 0.3.10-1 - Update to new release * Wed Jan 27 2021 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.3.8-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #1965538 - python-pingouin-0.3.12 is available https://bugzilla.redhat.com/show_bug.cgi?id=1965538 -------------------------------------------------------------------------------- ================================================================================ python-toposort-1.6-1.fc33 (FEDORA-2021-01d0354f07) Implements a topological sort algorithm -------------------------------------------------------------------------------- Update Information: Toposort update to v1.6 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 17 2021 Aniket Pradhan <major AT fedoraproject DOT org> - 1.6-1 - Updated to v1.6 * Fri Jun 4 2021 Python Maint <python-maint@xxxxxxxxxx> - 1.5-3 - Rebuilt for Python 3.10 * Wed Jan 27 2021 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #1946775 - python-toposort-1.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=1946775 -------------------------------------------------------------------------------- ================================================================================ rubygem-sequel-5.45.0-2.fc33 (FEDORA-2021-c7f0f48497) The Database Toolkit for Ruby -------------------------------------------------------------------------------- Update Information: Update to sequel 5.45.0 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 17 2021 Alejandro Perez <alejandro.perez.torres@xxxxxxxxx> - 5.45.0-2 - Fix time stamp * Thu Jun 17 2021 Alejandro Perez <alejandro.perez.torres@xxxxxxxxx> - 5.45.0-1 - Initial package -------------------------------------------------------------------------------- ================================================================================ rust-zcomponents-0.2.0-1.fc33 (FEDORA-2021-8570759885) Stupid component storage -------------------------------------------------------------------------------- Update Information: Update to 0.2.0 ---- Initial package -------------------------------------------------------------------------------- ChangeLog: -------------------------------------------------------------------------------- References: [ 1 ] Bug #1971198 - Review Request: rust-zcomponents - ZComponents is a component storage https://bugzilla.redhat.com/show_bug.cgi?id=1971198 [ 2 ] Bug #1973382 - rust-zcomponents-0.2.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1973382 -------------------------------------------------------------------------------- ================================================================================ satyr-0.38-1.fc33 (FEDORA-2021-8a4490b862) Tools to create anonymous, machine-friendly problem reports -------------------------------------------------------------------------------- Update Information: Use GLib for computing SHA-1 digests, drop nettle dependency -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 17 2021 Michal Fabik <mfabik@xxxxxxxxxx> 0.38-1 - New upstream version - lib: Use GLib for computing SHA-1 digests * Tue Mar 2 2021 Michal Fabik <mfabik@xxxxxxxxxx> 0.37-1 - sr_distances_cluster_objects: Check arg safety - spec: Drop trailing comment * Tue Jan 12 2021 Michal Fabik <mfabik@xxxxxxxxxx> 0.36-1 - New upstream version - Fix builds with python3.10 * Tue Jan 12 2021 Michal Fabik <mfabik@xxxxxxxxxx> 0.36-1 - spec: Use autoreconf in %build -------------------------------------------------------------------------------- _______________________________________________ test mailing list -- test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to test-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/test@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure