mailweb.openeuler.org
Manage this list
×
Keyboard Shortcuts
Thread View
j
: Next unread message
k
: Previous unread message
j a
: Jump to all threads
j l
: Jump to MailingList overview
2025
February
January
2024
December
November
October
September
August
July
June
May
April
March
February
January
2023
December
November
October
September
August
July
June
May
April
March
February
January
2022
December
November
October
September
August
July
June
May
April
March
February
January
2021
December
November
October
September
August
July
June
May
April
March
February
January
2020
December
November
October
September
August
July
June
May
April
March
February
January
2019
December
November
October
List overview
Download
Dev
----- 2025 -----
February 2025
January 2025
----- 2024 -----
December 2024
November 2024
October 2024
September 2024
August 2024
July 2024
June 2024
May 2024
April 2024
March 2024
February 2024
January 2024
----- 2023 -----
December 2023
November 2023
October 2023
September 2023
August 2023
July 2023
June 2023
May 2023
April 2023
March 2023
February 2023
January 2023
----- 2022 -----
December 2022
November 2022
October 2022
September 2022
August 2022
July 2022
June 2022
May 2022
April 2022
March 2022
February 2022
January 2022
----- 2021 -----
December 2021
November 2021
October 2021
September 2021
August 2021
July 2021
June 2021
May 2021
April 2021
March 2021
February 2021
January 2021
----- 2020 -----
December 2020
November 2020
October 2020
September 2020
August 2020
July 2020
June 2020
May 2020
April 2020
March 2020
February 2020
January 2020
----- 2019 -----
December 2019
November 2019
October 2019
dev@openeuler.org
11 participants
3523 discussions
Start a n
N
ew thread
RISCV SIG双周例会
by openEuler conference
22 Jan '25
22 Jan '25
您好! sig-RISC-V 邀请您参加 2025-01-23 10:00 召开的WeLink会议(自动录制) 会议主题:RISCV SIG双周例会 会议链接:https://meeting.huaweicloud.com:36443/#/j/962543867
会议纪要:https://etherpad.openeuler.org/p/sig-RISC-V-meetings
更多资讯尽在:https://www.openeuler.org/zh/
Hello! sig-RISC-V invites you to attend the WeLink conference(auto recording) will be held at 2025-01-23 10:00, The subject of the conference is RISCV SIG双周例会 You can join the meeting at
https://meeting.huaweicloud.com:36443/#/j/962543867
Add topics at
https://etherpad.openeuler.org/p/sig-RISC-V-meetings
More information:
https://www.openeuler.org/en/
1
0
0
0
【月报征集】openEuler 2025年1月月报
by 翁巧贞
22 Jan '25
22 Jan '25
Hi,all openEuler 社区2025年1月 运作报告征集啦! 社区的点滴故事都值得记录。 如果您希望在月报增加您的工作内容, 请于 01月26日(周日)16:00 前 联系 翁巧贞(微信号Qzhen303、wengqiaozhen(a)openeuler.sh) 如邮件回复,请在正文内说明稿件内容(标题、文案、配图、相关链接等)以及您的微信联系方式,以便内容的沟通调整。万分感谢!! 往期回顾:openEuler 社区月报<
https://mp.weixin.qq.com/mp/appmsgalbum?__biz=MzkyMjYzNjU0Ng==&action=getal…
> 感谢大家支持! 翁巧贞/openEuler社区运营
1
0
0
0
SBC SIG例会
by openEuler conference
21 Jan '25
21 Jan '25
您好! sig-SBC 邀请您参加 2025-01-22 17:00 召开的Zoom会议 会议主题:SBC SIG例会 会议内容: 议题收集中,具体参见会议纪要链接 会议链接:https://us06web.zoom.us/j/86529311923?pwd=g9BuXWjritNRUO98oDtjtVMEwbX7gm.1
会议纪要:https://etherpad.openeuler.org/p/sig-SBC-meetings
更多资讯尽在:https://www.openeuler.org/zh/
Hello! sig-SBC invites you to attend the Zoom conference will be held at 2025-01-22 17:00, The subject of the conference is SBC SIG例会, Summary: 议题收集中,具体参见会议纪要链接 You can join the meeting at
https://us06web.zoom.us/j/86529311923?pwd=g9BuXWjritNRUO98oDtjtVMEwbX7gm.1
. Add topics at
https://etherpad.openeuler.org/p/sig-SBC-meetings
. More information:
https://www.openeuler.org/en/
1
0
0
0
bigdata SIG例会
by openEuler conference
21 Jan '25
21 Jan '25
您好! bigdata 邀请您参加 2025-01-23 16:00 召开的WeLink会议(自动录制) 会议主题:bigdata SIG例会 会议链接:https://meeting.huaweicloud.com:36443/#/j/968081957
会议纪要:https://etherpad.openeuler.org/p/bigdata-meetings
更多资讯尽在:https://www.openeuler.org/zh/
Hello! bigdata invites you to attend the WeLink conference(auto recording) will be held at 2025-01-23 16:00, The subject of the conference is bigdata SIG例会, You can join the meeting at
https://meeting.huaweicloud.com:36443/#/j/968081957
. Add topics at
https://etherpad.openeuler.org/p/bigdata-meetings
. More information:
https://www.openeuler.org/en/
1
0
0
0
机密计算SIG例会
by openEuler conference
20 Jan '25
20 Jan '25
您好! sig-confidential-computing 邀请您参加 2025-01-23 14:30 召开的WeLink会议 会议主题:机密计算SIG例会 会议内容: 1.进展更新 2.申请新建guest-component软件仓 会议链接:https://meeting.huaweicloud.com:36443/#/j/965156033
会议纪要:https://etherpad.openeuler.org/p/sig-confidential-computing-meetings
更多资讯尽在:https://www.openeuler.org/zh/
Hello! sig-confidential-computing invites you to attend the WeLink conference will be held at 2025-01-23 14:30, The subject of the conference is 机密计算SIG例会, Summary: 1.进展更新 2.申请新建guest-component软件仓 You can join the meeting at
https://meeting.huaweicloud.com:36443/#/j/965156033
. Add topics at
https://etherpad.openeuler.org/p/sig-confidential-computing-meetings
. More information:
https://www.openeuler.org/en/
1
0
0
0
openEuler基础设施Rsync服务恢复公共 //Re: openEuler基础设施镜像站受rsync漏洞影响维护公告
by 曹志
20 Jan '25
20 Jan '25
openEuler基础设施已完成rsync漏洞的处理,相关站点rsync服务已恢复: 1. 受影响的全部3个镜像站的rsync已升级至开源社区问题修复版本3.4.0, 经验证功能均正常; 2. 已完成对镜像站的全量文件完整性校验,未检测到异常; 3. 基础设施安全平台未检测到攻击痕迹。 Best Regards Infra George > From: "曹志"<george(a)openeuler.sh> > Date: Wed, Jan 15, 2025, 18:32 > Subject: openEuler基础设施镜像站受rsync漏洞影响维护公告 > To: "dev"<dev(a)openeuler.org> > 一、漏洞影响范围 > rsync漏洞对openEuler基础设施影响三个镜像站业务,对其他社区软件生产和用户服务无影响。 > rsync://repo.openeuler.openatom.cn/openeuler/<
http://repo.openeuler.openatom.cn/openeuler/
> > rsync://repo.openeuler.openatom.cn/openeuler/<
http://repo.openeuler.openatom.cn/openeuler/
> >
rsync://repo.openeuler.org/openeuler/
<
http://repo.openeuler.org/openeuler/
> > 二、漏洞响应措施 > 1.openEuler镜像站已暂停openEuler镜像站的rsync服务,临时规避上述漏洞风险;01.15 > 2.rsync开源社区已在rsync3.4.0版本修复上述漏洞,openEuler镜像站正紧急升级rsync版本;01.16 > 3.openEuler基础设施正在检查镜像站数据完整性,确认完成后再开启rsync服务。01.16 > 三、漏洞技术分析 > 1.漏洞影响分析 > openEuler公开镜像仓使用rsync作为后台文件同步软件,用于在多个服务器之间高效地同步和分发文件。用户也可以通过rsync进行文件下载。openEuler镜像主站安装了rsync服务端,受1月14日rsync披露的6个漏洞影响。因为客户端对公共镜像服务器拥有匿名读取访问权限,通过以上漏洞(堆缓冲区溢出和信息泄漏等)结合使用,可导致客户端在运行 Rsync 服务器的设备上执行任意代码。此外,攻击者可以控制一个恶意服务器,并读取/写入任何连接客户端的任意文件,可对openEuler 公共镜像仓的文件完整性造成严重影响。 > 2.漏洞概述 > Rsync 是一个多功能的文件同步工具,包含六个漏洞,存在于 3.3.0 及更早版本中。Rsync 可用于在远程和本地计算机以及存储设备之间同步文件。发现的漏洞包括堆缓冲区溢出、信息泄露、文件泄露、外部目录文件写入、--safe-links 绕过和符号链接竞态条件。 > 以下是发现的漏洞: > · CVE-2024-12084:Rsync 守护进程中的堆缓冲区溢出漏洞,导致攻击者控制的校验和长度(s2length)处理不当。当 MAX_DIGEST_LEN 超过固定的 SUM_LENGTH(16 字节)时,攻击者可以在 sum2 缓冲区中写入越界数据。 > · CVE-2024-12085:Rsync 守护进程中存在一个漏洞,在比较文件校验和时,攻击者可以操控校验和长度(s2length),强制比较校验和与未初始化的内存,从而每次泄露一个字节的未初始化堆栈数据。 > · CVE-2024-12086:Rsync 守护进程中的一个漏洞,可能导致服务器泄露客户端机器上的任意文件内容。在文件从客户端复制到服务器的过程中,恶意的 Rsync 服务器可以生成无效的通信令牌和校验和,客户端在比较时会要求服务器重新发送数据,服务器可以利用此机会猜测校验和,进而逐字节地重新处理数据,确定目标文件的内容。 > · CVE-2024-12087:Rsync 守护进程中的路径遍历漏洞,影响 --inc-recursive 选项,这是许多标志的默认启用选项,即使客户端未显式启用,服务器也可以启用。使用该选项时,缺乏适当的符号链接验证,加上去重检查是逐文件列表进行的,这可能允许服务器在客户端的目标目录外写入文件。恶意服务器可以通过利用符号链接触发此行为,这些符号链接的名称与有效的客户端目录/路径相同。 > · CVE-2024-12088:--safe-links 选项漏洞导致 Rsync 未能正确验证符号链接目标是否包含其他符号链接。这会导致路径遍历漏洞,可能导致任意文件被写入到目标目录之外。 > · CVE-2024-12747:Rsync 存在符号链接竞态条件漏洞,可能导致特权提升。用户可能通过此漏洞在受影响的服务器上访问特权文件。 > Best Regards > Infra George > 2025.01.15
1
0
0
0
SDS SIG双周例会
by openEuler conference
20 Jan '25
20 Jan '25
您好! sig-SDS 邀请您参加 2025-01-21 10:00 召开的WeLink会议(自动录制) 会议主题:SDS SIG双周例会 会议内容: 1.社区需求进展 会议链接:https://meeting.huaweicloud.com:36443/#/j/981977275
会议纪要:https://etherpad.openeuler.org/p/sig-SDS-meetings
更多资讯尽在:https://www.openeuler.org/zh/
Hello! sig-SDS invites you to attend the WeLink conference(auto recording) will be held at 2025-01-21 10:00, The subject of the conference is SDS SIG双周例会, Summary: 1.社区需求进展 You can join the meeting at
https://meeting.huaweicloud.com:36443/#/j/981977275
. Add topics at
https://etherpad.openeuler.org/p/sig-SDS-meetings
. More information:
https://www.openeuler.org/en/
1
0
0
0
openEuler社区TC例会
by openEuler conference
19 Jan '25
19 Jan '25
您好! TC 邀请您参加 2025-01-22 10:00 召开的WeLink会议(自动录制) 会议主题:openEuler社区TC例会 会议内容: openEuler社区TC例会 会议链接:https://meeting.huaweicloud.com:36443/#/j/987197343
会议纪要:https://etherpad.openeuler.org/p/TC-meetings
更多资讯尽在:https://www.openeuler.org/zh/
Hello! TC invites you to attend the WeLink conference(auto recording) will be held at 2025-01-22 10:00, The subject of the conference is openEuler社区TC例会, Summary: openEuler社区TC例会 You can join the meeting at
https://meeting.huaweicloud.com:36443/#/j/987197343
. Add topics at
https://etherpad.openeuler.org/p/TC-meetings
. More information:
https://www.openeuler.org/en/
1
0
0
0
[Cancel] openEuler社区TC例会
by openEuler conference
19 Jan '25
19 Jan '25
Sorry! The Zoom meeting will be held at 2025-01-22 10:00 scheduled by TC SIG has been cancelled.
1
0
0
0
openEuler社区TC例会
by openEuler conference
18 Jan '25
18 Jan '25
您好! TC 邀请您参加 2025-01-22 10:00 召开的Zoom会议 会议主题:openEuler社区TC例会 会议内容: 欢迎大家申报议题。 会议链接:https://us06web.zoom.us/j/84200369485?pwd=qxCcIOLuuWZb7dRmZ8xTJlFWj4Z6Ob.1
会议纪要:https://etherpad.openeuler.org/p/TC-meetings
更多资讯尽在:https://www.openeuler.org/zh/
Hello! TC invites you to attend the Zoom conference will be held at 2025-01-22 10:00, The subject of the conference is openEuler社区TC例会, Summary: 欢迎大家申报议题。 You can join the meeting at
https://us06web.zoom.us/j/84200369485?pwd=qxCcIOLuuWZb7dRmZ8xTJlFWj4Z6Ob.1
. Add topics at
https://etherpad.openeuler.org/p/TC-meetings
. More information:
https://www.openeuler.org/en/
1
0
0
0
← Newer
1
2
3
4
5
6
7
8
...
353
Older →
Jump to page:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
Results per page:
10
25
50
100
200