mailweb.openeuler.org
Manage this list
×
Keyboard Shortcuts
Thread View
j
: Next unread message
k
: Previous unread message
j a
: Jump to all threads
j l
: Jump to MailingList overview
2024
November
October
September
August
July
June
May
April
March
February
January
2023
December
November
October
September
August
July
June
May
April
March
February
January
2022
December
November
October
September
August
July
June
May
April
March
February
January
2021
December
November
October
September
August
July
June
May
April
March
February
January
2020
December
November
October
September
August
July
June
May
April
March
February
January
2019
December
November
October
List overview
Download
Dev
----- 2024 -----
November 2024
October 2024
September 2024
August 2024
July 2024
June 2024
May 2024
April 2024
March 2024
February 2024
January 2024
----- 2023 -----
December 2023
November 2023
October 2023
September 2023
August 2023
July 2023
June 2023
May 2023
April 2023
March 2023
February 2023
January 2023
----- 2022 -----
December 2022
November 2022
October 2022
September 2022
August 2022
July 2022
June 2022
May 2022
April 2022
March 2022
February 2022
January 2022
----- 2021 -----
December 2021
November 2021
October 2021
September 2021
August 2021
July 2021
June 2021
May 2021
April 2021
March 2021
February 2021
January 2021
----- 2020 -----
December 2020
November 2020
October 2020
September 2020
August 2020
July 2020
June 2020
May 2020
April 2020
March 2020
February 2020
January 2020
----- 2019 -----
December 2019
November 2019
October 2019
dev@openeuler.org
11 participants
3375 discussions
Start a n
N
ew thread
openEuler update_20221107版本发布公告
by chemingdao
14 Nov '22
14 Nov '22
Dear all, 经社区Release SIG、QA SIG及 CICD SIG 评估,openEuler-20.03-LTS-SP1、openEuler-20.03-LTS-SP3及openEuler-22.03-LTS update版本满足版本出口质量,现进行发布公示。 本公示分为五部分: 1、openEuler-20.03-LTS-SP1 Update 20221107发布情况及待修复缺陷 2、openEuler-20.03-LTS-SP3 Update 20221107发布情况及待修复缺陷 3、openEuler-22.03-LTS Update 20221107发布情况及待修复缺陷 4、openEuler 关键组件待修复CVE 清单 5、openEuler 社区指导文档及开放平台链接 本次update版本发布后,下一个版本里程碑点(预计在2022/11/18)提供 update_20221114版本。 openEuler-20.03-LTS-SP1 Update 20221107 经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP1修复版本已知问题6个,已知漏洞13个。目前版本分支剩余待修复缺陷61个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库 openEuler-20.03-LTS-SP1 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I5ZPR5?from=project-i…
CVE修复: CVE 仓库 CVSS评分 CVE-2022-44638 pixman 8.8 CVE-2022-43995 sudo 7.1 CVE-2022-40304 libxml2 8.1 CVE-2022-40303 libxml2 7.5 CVE-2022-2602 kernel 6.5 CVE-2021-30560 libxslt 8.8 CVE-2022-34917 kafka 7.5 CVE-2022-26612 hadoop 9.8 CVE-2022-25168 hadoop 9.8 CVE-2021-37404 hadoop 9.8 CVE-2019-12399 kafka 7.5 CVE-2022-3756 exiv2 8.8 CVE-2022-40284 nfs-3g 7.8 Bugfix: issue 仓库 #I5Z86E:【OLK-5.10】KASAN: use-after-free Read in eth_type_trans kernel #I6038I:修复问题和优化代码 oec-hardware #I4G5U2:AddressSanitizer CHECK failed in sdscatvprintf hiredis #I604IM:【openEuler-20.03-LTS-SP1】performance.sh脚本中代码对性能有影响 openEuler-release #I5ZZLE:nodejs-minimatch升级导致nodejs-grunt安装缺依赖 nodejs-grunt #I5YIO4:修复CVE-2022-3517导致nodejs-glob包编译失败 nodejs-minimatch openEuler-20.03-LTS-SP1版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1:Epol
openEuler-20.03-LTS-SP1 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/EPOL/update/
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP1 Update版本待修复问题清单公示: 任务ID 任务标题 关联仓库 SIG I281C1 【fuzz】runtime error: libsass Base-service I437CR [SP1][arm/x86]obs-server包下11个服务启动关闭,出现报错 obs-server Others I43OSX [clamav] 执行clamscan --statistics pcre命令会出现error,但是最终返回码为0 clamav Others I44RHB large loop in OBJ_obj2txt openssl sig-security-facility I44RIX large loop in bn_lshift_fixed_top openssl sig-security-facility I48GIM 【20.03LTS SP1 update 210901】ovirt-cockpit-sso.service服务启动失败 ovirt-cockpit-sso oVirt I490MU Uncaught exception in get_tokens_unprocessed python-pygments Programming-language I4CJX9 [20.03-LTS-SP1] 389-ds-base包下的部分命令-v参数不显示版本号 three-eight-nine-ds-base Application I4F8YQ integer overflow in start_input_bmp libjpeg-turbo Desktop I4F8ZI heap-buffer-overflow in get_word_rgb_row libjpeg-turbo Desktop I4F903 Unexpect-exit in start_input_tga libjpeg-turbo Desktop I4F913 Timeout in tjDecompress2 libjpeg-turbo Desktop I4FRSL Undefined-shift in bitset_set augeas Desktop I4FT5J Timeout in fa_from_re augeas Desktop I4FT5U stack overflow in fa_from_re augeas Desktop I4FT61 stack overflow in re_case_expand augeas Desktop I4FT67 memleaks in ref_make_ref augeas Desktop I4FT6B SEGV in re_case_expand augeas Desktop I4FT6F stack overflow in parse_concat_exp augeas Desktop I4FT7B stack overflow in calc_eclosure_iter augeas Desktop I4FT8E stack overflow in peek_token augeas Desktop I4FT8P stack overflow in parse_path_expr augeas Desktop I4FT97 Out of memory in ns_from_locpath augeas Desktop I4FT9A SEGV in eval_expr augeas Desktop I4FT9C SEGV in tree_prev augeas Desktop I4FT9G stack overflow in check_expr augeas Desktop I4FT9I stack overflow in free_expr augeas Desktop I4G4A5 Undefine-shift in _bfd_safe_read_leb128 binutils Compiler I4G4B1 Integer overflow in print_vms_time binutils Compiler I4G4VY memleak in parse_gnu_debugaltlink binutils Compiler I4G4WF Heap-buffer-overflow in slurp_hppa_unwind_table binutils Compiler I4G4WW Use-after-free in make_qualified_name binutils Compiler I4G4X6 memleak in byte_get_little_endian binutils Compiler I4G4XF memleak in process_mips_specific binutils Compiler I4G4Y0 out-of-memory in vms_lib_read_index binutils Compiler I4G4YJ Heap-buffer-overflow in bfd_getl16 binutils Compiler I4G4YV Floating point exception in _bfd_vms_slurp_etir binutils Compiler I4G5TL stack-buffer-overflow in redisvFormatCommand hiredis Base-service I4G5U2 AddressSanitizer CHECK failed in sdscatvprintf hiredis Base-service I4G5UN SEGV in redisvFormatCommand hiredis Base-service I4G5WG AddressSanitizer CHECK failed in sdscatlen hiredis Base-service I4G5XO Attempting free wild-addr in hi_free hiredis Base-service I4J0OY 【20.03 SP1】【arm/x86】安装好libdap后,getdap4命令的-i和-k参数使用异常 libdap sig-recycle I4JMG4 【20.03 SP1】【arm/x86】robotframework包的三个命令:libdoc、rebot、robot执行--help/-h/-?/--version,查看帮助信息和版本信息,返回值为251 python-robotframework sig-ROS I4K6ES stack-buffer-overflow in UINT32_Marshal libtpms sig-security-facility I4K6FU global-buffer-overflow in Array_Marshal libtpms sig-security-facility I4K6R7 memleak in wrap_nettle_mpi_init gnutls sig-security-facility I4K6UI Timeout in _asn1_find_up gnutls sig-security-facility I4KT2A integer overflow in luaV_execute lua Base-service I4KT3D integer overflow in intarith lua Base-service I4KT3Q Division by zero in luaV_execute lua Base-service I4KT40 Timeout in luaV_finishget lua Base-service I4O16Z 【SP1_update/arm】安装kernel-4.19.90-2108版本有错误提示信息 kernel Kernel I4QV6N 【openEuler-20.03-LTS-SP1】flink命令执行失败 flink sig-bigdata I5G81X 【20.03 SP1】selinux-policy卸载异常 selinux-policy sig-security-facility I5GT2K 【20.03-SP1】【arm/x86】pcp-system-tools包下的pcp-mpstat命令执行报错 pcp Application I5IG1V 【20.03-SP1】【x86/arm】epol源下的efl、efl-devel软件包安装报错,gpg检查失败 efl sig-compat-winapp I5IG6K 【20.03-SP1】【x86/arm】epol源下的opencryptoki、opencryptoki-devel软件包安装报错,gpg检查失败 opencryptoki dev-utils I5JHX2 【20.03 SP1 update 20220727】ovirt-engine在update 20220727版本安装失败 ovirt-engine oVirt I5JNSL 【20.03 SP1 update 20220727】【arm】htcacheclean.service服务启动之后,日志中提示”Can't open PID file /run/httpd/htcacheclean/pid“ httpd Networking I5Q5D1 【20.03 SP1】ibus在sp1分支安装有异常告警 ibus Desktop openEuler-20.03-LTS-SP3 Update 20221107 经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP3修复版本已知问题6个,已知漏洞18个。目前版本分支剩余待修复缺陷14个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库 openEuler-20.03-LTS-SP3 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I5ZPR8?from=project-i…
CVE修复: 需求类型 软件包 CVSS评分 CVE-2022-44638 pixman 8.8 CVE-2022-43995 sudo 7.1 CVE-2022-42012 dbus 6.5 CVE-2022-42011 dbus 6.5 CVE-2022-42010 dbus 6.5 CVE-2022-40304 libxml2 8.1 CVE-2022-40303 libxml2 7.5 CVE-2022-2602 kernel 6.5 CVE-2021-30560 libxslt 8.8 CVE-2021-28041 openssh 7.1 CVE-2021-38593 qt5-qtbase 7.5 CVE-2022-34917 kafka 7.5 CVE-2022-26612 hadoop 9.8 CVE-2022-25168 hadoop 9.8 CVE-2021-37404 hadoop 9.8 CVE-2019-12399 kafka 7.5 CVE-2022-3756 exiv2 8.8 CVE-2022-40284 nfs-3g 7.8 Bugfix: issue 仓库 #I5Z86E:【OLK-5.10】KASAN: use-after-free Read in eth_type_trans kernel #I5YZLF:openEuler-20.03-lts-SP3需要同步mster代码 grep #I6038I:修复问题和优化代码 oec-hardware #I604J1:【openEuler-20.03-LTS-SP3】performance.sh脚本中代码对性能有影响 openEuler-release #I5ZZLE:nodejs-minimatch升级导致nodejs-grunt安装缺依赖 nodejs-grunt #I5YIO4:修复CVE-2022-3517导致nodejs-glob包编译失败 nodejs-minimatch openEuler-20.03-LTS-SP3版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3:Epol
openEuler-20.03-LTS-SP3 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/EPOL/update/main/
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP3 Update版本待修复问题清单公示: 任务ID 任务标题 关联仓库 SIG I4QV7S 【openEuler-20.03-LTS-SP3】flink run 命令执行失败 flink sig-bigdata I4RVHE losetup : 当loop设备编号超过7位时,losetup命令无法操作该设备 util-linux Base-service I4UMEV [openEuler 20.03-LTS SP3]openEuler开启crash_kexec_post_notifiers后,panic通知链无法完全遍历 kernel Kernel I5IGAS 【20.03-SP3】【x86/arm】epol源下的opencryptoki、opencryptoki-devel软件包安装报错,gpg检查失败 opencryptoki dev-utils I5IGOR 【20.03-SP3】【x86/arm】epol源下的fluidsynth、fluidsynth-devel、fluidsynth-help软件包安装报错,gpg检查失败 fluidsynth Application I5JBJ9 【20.03 SP3_EPOL_update20220727】ovirt-engine-backend包卸载过程的告警信息需要优化 ovirt-engine oVirt I5JLNF 【20.03 SP3 update 20220727】【arm/x86】ovirt-websocket-proxy.service服务启动失败 ovirt-engine oVirt I5JLRQ 【20.03 SP3 update 20220727】【arm/x86】ovirt-engine-notifier.service服务启动失败 ovirt-engine oVirt I5KXUY 【20.03 LTS SP3 update 20220803】【arm/x86】ovirt-cockpit-sso.service服务启动失败 ovirt-cockpit-sso oVirt I5KY4S 【20.03 LTS SP3 update 20220803】【arm/x86】vdsmd.service服务启动失败,导致mom-vdsm.service服务无法启动成功 vdsm oVirt I5LYJK 【20.03-sp3_update20220801】【x86】对内核版进行升级后,TCP_option_address安装异常 TCP_option_address Kernel I5PT12 [20.03-LTS-SP3]spec文件存在软件包编译依赖自身,且打包包含系统环境文件 ima-evm-utils Base-service I5PUIA [20.03-LTS-SP3]spec文件存在软件包编译依赖自身,且打包包含系统环境文件 qrencode Desktop I5SCLC 【20.03 SP3】selinux-policy卸载异常 selinux-policy sig-security-facility openEuler-22.03-LTS Update 20221107 经各SIG及社区开发者贡献,本周openEuler-22.03-LTS修复版本已知问题9个,已知漏洞76个。目前版本分支剩余待修复缺陷10个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库 openEuler-22.03-LTS Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I5ZPRA?from=project-i…
CVE修复: CVE 仓库 CVSS评分 CVE-2021-45444 zsh 8.8 CVE-2022-24130 xterm 5.5 CVE-2022-23645 swtpm 5.5 CVE-2022-43995 sudo 7.1 CVE-2022-24303 python-pillow 5.9 CVE-2022-44638 pixman 8.8 CVE-2021-30560 libxslt 8.8 CVE-2022-23308 libxml2 7.5 CVE-2022-40303 libxml2 7.5 CVE-2022-40304 libxml2 8.1 CVE-2022-0561 libtiff 5.5 CVE-2022-0562 libtiff 5.5 CVE-2022-0891 libtiff 7.1 CVE-2022-22844 libtiff 5.5 CVE-2022-3542 kernel 5.5 CVE-2022-3606 kernel 5.5 CVE-2022-40768 kernel 5.5 CVE-2022-25235 expat 7.8 CVE-2022-25236 expat 9.8 CVE-2022-25313 expat 6.5 CVE-2022-25314 expat 7.5 CVE-2022-25315 expat 6.5 CVE-2021-0129 bluez 5.7 CVE-2021-43400 bluez 9.1 CVE-2021-43859 xstream 7.5 CVE-2019-17570 xmlrpc 9.8 CVE-2022-0581 wireshark 7.5 CVE-2022-0582 wireshark 9.8 CVE-2022-0583 wireshark 7.5 CVE-2022-0585 wireshark 6.5 CVE-2022-0586 wireshark 7.5 CVE-2022-3725 wireshark 7.5 CVE-2019-25058 usbguard 7.8 CVE-2022-23181 tomcat 7 CVE-2020-35518 three-eight-nine-ds-base 5.3 CVE-2021-45079 strongswan 9.1 CVE-2020-7663 rubygem-websocket-extensions 7.5 CVE-2021-38593 qt5-qtbase 7.5 CVE-2021-45115 python-django 7.5 CVE-2021-45116 python-django 7.5 CVE-2021-45452 python-django 5.3 CVE-2022-22818 python-django 6.1 CVE-2022-23833 python-django 7.5 CVE-2020-8178 nodejs-jison 9.8 CVE-2020-7729 nodejs-grunt 7.1 CVE-2020-28282 nodejs-getobject 9.8 CVE-2019-13173 nodejs-fstream 7.5 CVE-2019-2692 mysql-connector-java 6.3 CVE-2021-34432 mosquitto 7.5 CVE-2021-4104 log4j12 7.5 CVE-2022-23302 log4j12 8.8 CVE-2022-23307 log4j12 9.8 CVE-2021-3596 ImageMagick 6.5 CVE-2021-39212 ImageMagick 4.4 CVE-2022-0711 haproxy 7.5 CVE-2022-21702 grafana 5.4 CVE-2018-17942 gnulib 8.8 CVE-2019-20378 ganglia 6.1 CVE-2019-20379 ganglia 6.1 CVE-2019-13508 freetds 9.8 CVE-2022-25235 firefox 9.8 CVE-2022-25236 firefox 9.8 CVE-2022-25315 firefox 9.8 CVE-2010-3996 festival 7.8 CVE-2021-23214 postgresql 8.1 CVE-2021-23222 postgresql 5.9 CVE-2020-29260 libvncserver 7.5 CVE-2019-12399 kafka 7.5 CVE-2022-34917 kafka 7.5 CVE-2021-37404 hadoop 9.8 CVE-2022-25168 hadoop 9.8 CVE-2022-26612 hadoop 9.8 CVE-2019-19308 gnome-font-viewer 5.5 CVE-2022-42919 python3 7.8 CVE-2022-3756 exiv2 8.8 CVE-2022-40284 nfs-3g 7.8 Bugfix: issue 仓库 #I5WGEF:auxtrace_Record_Reconstruct events in __init, HiSilicon PCIe tuning and tracing devices, PCIe trace packet support. kernel #I604JE:【openEuler-22.03-LTS】performance.sh脚本中代码对性能有影响 openEuler-release #I5YSWV:建议添加编译依赖make,方便rpmbuild本地编译 libnetfilter_cttimeout #I5YTIA:建议添加编译依赖make,方便rpmbuild本地编译 libnfnetlink #I5YSRO:fix Potential Null Pointer Dereference libdnet #I6038I:修复问题和优化代码 oec-hardware #I5ZZAH:rubygem-sqlite3在22.03-LTS分支编译失败 rubygem-sqlite3 #I5ZZLE:nodejs-minimatch升级导致nodejs-grunt安装缺依赖 nodejs-grunt #I5YIO4:修复CVE-2022-3517导致nodejs-glob包编译失败 nodejs-minimatch openEuler-22.03-LTS版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:22.03:LTS
https://build.openeuler.org/project/show/openEuler:22.03:LTS:Epol
openEuler-22.03-LTS Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS/update/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
openEuler-22.03-LTS Update版本待修复问题清单公示: 任务ID 任务标题 关联仓库 SIG I5G9CY 升级iinstall-scripts包会导致系统启动异常 install-scripts sig-OS-Builder I5JIA6 【22.03 LTS update 20220727】ovirt-engine在update 20220727版本安装失败 ovirt-engine oVirt I5JPII 【22.03_update20220727】【x86/arm】ovirt-engine源码包本地自编译失败,缺少编译依赖ovirt-jboss-modules-maven-plugin ovirt-engine oVirt I5LKKX libbluray build problem in openEuler:22.03:LTS libbluray Desktop I5LKM6 libxshmfence build problem in openEuler:22.03:LTS libxshmfence Desktop I5LKY8 yaffs2 build problem in openEuler:22.03:LTS yaffs2 sig-embedded I5QKGT 【22.03LTS_update0907】【arm/x86】kmod-drbd90软件包安装之后文件有缺失 kmod-drbd90 sig-Ha I5RHYO 【22.09 RC4】【arm/x86】package.ini中的redis_host配置为不存在的ip,重启pkgship服务失败,服务一直在尝试重启 pkgship sig-EasyLife I5Q4S3 [22.03-LTS]x86虚拟机卸载qxl模块,机器自动重启 kernel Kernel I5TMFF [22.03-LTS]先安装mysql-server,卸载后再安装mariadb-server,mariadb服务启动失败 mariadb DB 社区待修复漏洞: openEuler社区根据漏洞严重等级采取差异化的修复策略,请各个SIG 关注涉及CVE组件的修复情况。 严重等级(Severity Rating) 漏洞修复时长 致命(Critical) 7天 高(High) 14天 中(Medium) 30天 低(Low) 30天
可参考社区安全委员会漏洞:https://gitee.com/openeuler/security-committee/wikis/%E7%A4%BE…
近14天将超期CVE: 漏洞编号 Issue ID 剩余天数 CVSS评分 软件包 SIG CVE-2022-2741 I5YPB2 1.1 7.5 zephyr sig-Zephyr CVE-2022-45062 I60DGK 2.78 9.8 xfce4-settings xfce CVE-2022-3535 I5W7BQ 2.94 3.5 risc-v-kernel sig-RISC-V CVE-2022-3531 I5W7BL 2.94 5.7 risc-v-kernel sig-RISC-V CVE-2022-3532 I5W7BF 2.94 5.7 risc-v-kernel sig-RISC-V CVE-2022-3533 I5W7AV 2.94 5.7 risc-v-kernel sig-RISC-V CVE-2022-3544 I5W7BX 2.95 5.5 risc-v-kernel sig-RISC-V CVE-2022-3543 I5W7BW 2.95 5.5 risc-v-kernel sig-RISC-V CVE-2022-3542 I5W7BT 2.95 5.5 risc-v-kernel sig-RISC-V CVE-2022-3563 I5W7ZQ 3.38 5.7 risc-v-kernel sig-RISC-V CVE-2022-38791 I5WD41 3.69 5.5 mariadb DB CVE-2016-5690 I60L14 3.85 9.8 ImageMagick Others CVE-2022-3586 I5WF1J 3.85 5.5 risc-v-kernel sig-RISC-V CVE-2022-3595 I5WFKO 4.26 5.5 risc-v-kernel sig-RISC-V CVE-2022-21589 I5WFL3 4.29 4.3 mysql5 DB CVE-2022-21608 I5WFL5 4.3 4.9 mysql5 DB CVE-2022-21592 I5WFL9 4.31 4.3 mysql5 DB CVE-2022-21617 I5WFLE 4.32 4.9 mysql5 DB CVE-2022-34169 I5HV9H 4.37 7.5 openjdk-1.8.0 Compiler CVE-2018-20657 I5WL3H 4.68 binutils Compiler CVE-2022-3606 I5WLYF 4.73 5.5 risc-v-kernel sig-RISC-V CVE-2022-21626 I5WMU2 4.79 5.3 openjdk-latest Compiler CVE-2022-21626 I5WMTY 4.79 5.3 openjdk-11 Compiler CVE-2022-21597 I5WMXW 4.8 5.3 openjdk-11 Compiler CVE-2022-21618 I5WMXA 4.8 5.3 openjdk-latest Compiler CVE-2022-21618 I5WMX4 4.8 5.3 openjdk-11 Compiler CVE-2022-21624 I5WMVR 4.8 3.7 openjdk-latest Compiler CVE-2022-21619 I5WMVP 4.8 3.7 openjdk-latest Compiler CVE-2022-21624 I5WMVM 4.8 3.7 openjdk-11 Compiler CVE-2017-11552 I5WMZS 4.81 6.5 libmad Others CVE-2022-39399 I5WMYV 4.81 3.7 openjdk-11 Compiler CVE-2022-39399 I5WMYG 4.81 3.7 openjdk-latest Compiler CVE-2022-21628 I5WMYC 4.81 5.3 openjdk-latest Compiler CVE-2022-21628 I5WMY2 4.81 5.3 openjdk-11 Compiler CVE-2018-17828 I5WN2X 4.82 5.5 zziplib Base-service CVE-2018-16548 I5WN1L 4.82 6.5 zziplib Base-service CVE-2022-21619 I5WN4Q 4.83 3.7 openjdk-11 Compiler CVE-2022-43945 I5ZL2W 5.28 7.5 kernel Kernel CVE-2022-42928 I5WR2P 5.61 firefox Application CVE-2022-3629 I5WYLP 6.6 3.3 risc-v-kernel sig-RISC-V CVE-2022-3624 I5WYKS 6.6 3.3 risc-v-kernel sig-RISC-V CVE-2022-3630 I5WYKI 6.6 5.5 risc-v-kernel sig-RISC-V CVE-2022-3619 I5X0EY 6.69 4.3 risc-v-kernel sig-RISC-V CVE-2022-42432 I5X2IL 6.93 risc-v-kernel sig-RISC-V CVE-2022-3344 I5X2N5 7.04 5.5 risc-v-kernel sig-RISC-V CVE-2022-3633 I5X3LH 7.56 3.3 risc-v-kernel sig-RISC-V CVE-2022-3872 I5ZWYZ 7.78 8.6 qemu Virt CVE-2022-3238 I5X87A 9.29 risc-v-kernel sig-RISC-V CVE-2021-39800 I5XCU6 9.62 5.5 kernel Kernel CVE-2022-39328 I60B4D 9.66 8.1 grafana Application CVE-2022-45061 I60CRW 9.73 7.5 python3 Base-service CVE-2022-45059 I60DGG 9.78 7.5 varnish System-tool CVE-2022-45060 I60DGE 9.78 7.5 varnish System-tool CVE-2022-3650 I5XNUK 10.78 ceph sig-ceph CVE-2022-3474 I5XXF6 12.22 4.3 bazel sig-bigdata CVE-2022-3707 I5XXFH 12.28 risc-v-kernel sig-RISC-V CVE-2022-3707 I5XXFF 12.28 kernel Kernel CVE-2022-39348 I5Y48K 12.79 5.4 python-twisted sig-python-modules CVE-2022-3718 I5Y4G1 12.81 6.5 exiv2 Desktop CVE-2022-24588 I5Y6LH 13.43 5.4 kernel Kernel openEuler 社区指导文档及开放平台链接: openEuler 版本分支维护规范:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E7%89%…
openEuler release-management 版本分支PR指导:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E5%BC%…
社区QA 版本测试提单规范
https://gitee.com/openeuler/QA/blob/839f952696f271f83c018ccf3218cf493b92d65…
社区QA 测试平台 radiates
https://radiatest.openeuler.org
<
https://radiatest.openeuler.org/
> 车明道(openEuler release SIG) Mobile: +86 15345431107 中国(China)-杭州(Hangzhou)-滨江区江淑路360号华为杭州研发中心 HUAWEI , Jiangshu Road., Binjiang District, Hangzhou, P.R.China E-mail: chemingdao(a)huawei.com<mailto:chemingdao@huawei.com> [cid:image003.png@01D8F7BA.A401F8C0]Open Source OS for Digital Infrastructure 本邮件及其附件含有华为公司的保密信息,仅限于发送给上面地址中列出的个人或群组。禁止任何其他人以任何形 式使用(包括但不限于全部或部分地泄露、复制、或散发)本邮件中的信息。如果您错收了本邮件,请您立即电话 或邮件通知发件人并删除本邮件! This e-mail and its attachments contain confidential information from HUAWEI, which is intended only for the person or entity whose address is listed above. Any use of the information contained herein in any way (including, but not limited to, total or partial disclosure, reproduction, or dissemination) by persons other than the intended recipient(s) is prohibited. If you receive this e-mail in error, please notify the sender by phone or email immediately and delete it
1
0
0
0
【请阅】openEuler社区2022年10月运作报告
by openEuler
11 Nov '22
11 Nov '22
1
0
0
0
sig-Zephyr11月例会
by openEuler conference
11 Nov '22
11 Nov '22
您好! sig-Zephyr SIG 邀请您参加 2022-11-12 20:30 召开的Zoom会议(自动录制) 会议主题:sig-Zephyr11月例会 会议内容: 11月例会 会议链接:https://us06web.zoom.us/j/85856003655?pwd=ZUtlaHlTemorRXkwUmlYUURFSWw5dz09
会议纪要:https://etherpad.openeuler.org/p/sig-Zephyr-meetings
温馨提醒:建议接入会议后修改参会人的姓名,也可以使用您在gitee.com的ID
更多资讯尽在:https://openeuler.org/zh/
Hello! openEuler sig-Zephyr SIG invites you to attend the Zoom conference(auto recording) will be held at 2022-11-12 20:30, The subject of the conference is sig-Zephyr11月例会, Summary: 11月例会 You can join the meeting at
https://us06web.zoom.us/j/85856003655?pwd=ZUtlaHlTemorRXkwUmlYUURFSWw5dz09
. Add topics at
https://etherpad.openeuler.org/p/sig-Zephyr-meetings
. Note: You are advised to change the participant name after joining the conference or use your ID at
gitee.com
. More information:
https://openeuler.org/en/
1
0
0
0
【请阅】会议纪要- Compliance SIG 双周例会
by Yixiong Chen
11 Nov '22
11 Nov '22
SIG-compliance 双周例会: 时间:2022年11月10号 10:00-12:00 会议主持人:郑志鹏 与会者(请与会者在下面添加您的姓名):高琨、刘波、魏建刚、王悦良、付善庆、芶新易、陈一雄、黄河清、王泽俊、刘阔、彭业诚、陈悦、丁紫薇、杜奕威、王春力、执委、魏云博、杨潇、chendexi、xp、yz、benteng、邢鹏、汤乘畅、毛周、李剑、李沐阳、谢炜、caodongxia、Wenlong Sun、丁欣、赵岳峰、张超、Feng Wang、路明、Xin Liu 下次例会时间:2022年11月24号 10:00-12:00 下次例会主持人:杨聪 议题: 1.基于SBOM的开源社区软件供应链安全解决方案 刘波 2.按“合规SIG组License准入审阅流程”申请对Linux-OpenIB 审阅 汤乘畅 3.按“合规SIG组License准入审阅流程”申请对BSD 3-Clause Modification 审阅 陈一雄 会议纪要: 1.基于SBOM的开源社区软件供应链安全解决方案 在大规模软件产品中要分清楚依赖关系, 可以建立软件的正反向依赖关系全链路可追溯 检测和修复软件供应链攻击前提是需要建立现代化DevSecOps软件工程体系,从依赖分析——>License分析——>漏洞分析等均需要从人工排查到自动化 当前SBOM软件供应链存在两大难点:识别软件精准依赖、开源软件本身源数据信息采集 SBOM使用场景为软件供应链安全管理,安全漏洞管理、安全应急响应,高可信安全应用管理,能帮助软件生产商、购买者和运营商更高效地识别软件成分、排查License风险/合规风险/安全漏洞影响风险、履行义务声明等
SBOM服务源码仓:https://github.com/opensourceways/sbom-service
SBOM在线服务地址:https://sbom-service.osinfra.cn/#/sbomPackages 2.按“合规SIG组License准入审阅流程”申请对Linux-OpenIB 审阅 汤乘畅:Linux-OpenIB与BSD-2相比在断尾存在差异,BSD-2的描述更加精确,涉及的场景更多。但是整体两者表达的意思是趋近的,整体上都是表达代码作品以及共享者不对这些代码产生的后果负有任何形式的责任 王悦良:Linux-OpenIB相近与BSD-2,许可证本身是宽松的,赞同审阅为oE认可 魏建刚:赞同将Linux-OpenIB审阅为oE认可 高琨:赞同将Linux-OpenIB审阅为oE认可 Linux-OpenIB审阅为oE认可 投票结果——通过 投票情况: 马全一: 高琨:同意 魏建刚:同意 郑志鹏:同意 杨聪:同意 许渊聪: 王悦良:同意 张伟:同意 3.按“合规SIG组License准入审阅流程”申请对BSD 3-Clause Modification 审阅 陈一雄:BSD-3-Clause Modification 相比BSD-3-Clasue 多了修改之后要声明的条款,该条款在Apache-2.0、GPLv2、GPLv3里都是有类似的条款,所以认为较低风险 王悦良:赞同将BSD-3-Clause Modification审阅为oE认可 魏建刚:赞同将BSD-3-Clause Modification审阅为oE认可 高琨:BSD-3-Clause Modification审阅为oE认可 BSD-3-Clause Modification审阅为oE认可 投票结果——通过 投票情况: 马全一: 高琨:同意 魏建刚:同意 郑志鹏:同意 杨聪: 同意 许渊聪: 王悦良:同意 张伟:同意
基于SBOM的开源社区软件供应链安全解决方案材料:https://www.openeuler.org/zh/blog/robell/openEuler…
1
0
0
0
Compiler SIG 双周例会
by openEuler conference
11 Nov '22
11 Nov '22
您好! Compiler SIG 邀请您参加 2022-11-15 10:00 召开的Zoom会议(自动录制) 会议主题:Compiler SIG 双周例会 会议内容: 1. 进展update 2. BiShengCLanguage开源项目简介 会议链接:https://us06web.zoom.us/j/81840169028?pwd=aytBUHZFa1EzbkIybWVqU1pMN0ZlQT09
会议纪要:https://etherpad.openeuler.org/p/Compiler-meetings
温馨提醒:建议接入会议后修改参会人的姓名,也可以使用您在gitee.com的ID
更多资讯尽在:https://openeuler.org/zh/
Hello! openEuler Compiler SIG invites you to attend the Zoom conference(auto recording) will be held at 2022-11-15 10:00, The subject of the conference is Compiler SIG 双周例会, Summary: 1. 进展update 2. BiShengCLanguage开源项目简介 You can join the meeting at
https://us06web.zoom.us/j/81840169028?pwd=aytBUHZFa1EzbkIybWVqU1pMN0ZlQT09
. Add topics at
https://etherpad.openeuler.org/p/Compiler-meetings
. Note: You are advised to change the participant name after joining the conference or use your ID at
gitee.com
. More information:
https://openeuler.org/en/
1
0
0
0
【关于openEuler-22.03-LTS-SP1版本基线启动的通知】
by xiasenlin
11 Nov '22
11 Nov '22
各位openeuler社区的maintainer、 committer和contributor好: 按照社区openEuler-22.09版本release-plan: (1) CICD sig组将在2022/11/9~2022/11/10启动22.03-LTS Next分支大规模编译构建,并跟踪每日单包编译/安装问题; (2) CICD sig组将在2022/11/11~2022/11/12期间,识别持续编译/安装失败的软件包清单,并提交给release sig评审从openEuler-22.03-LTS-SP1版本基线中剔除,届时请涉及sig的maintainer关注release sig例会; (3) CICD sig组将在2022/11/13~2022/11/15完成openEuler-22.03-LTS-SP1版本基线,创建分支及构建工程,期间不接纳零星的版本基线变更需求,如果有,请于15号之后自提PR; (4) 在上述期间OBS构建资源会倾斜22.03-LTS Next,master及转维分支的单包编译/版本构建会有一点影响; 目前已识别的22.03-LTS Next单包编译/安装问题,请涉及sig maintainer尽快处理,谢谢!: [cid:image001.png@01D8F429.500F8320] 附release-plan [cid:image002.png@01D8F429.500F8320]
1
2
0
0
[openeuler-security] 会议纪要:安全委员会&安全技术sig例会 2022-11-09
by Chenxi Mao
10 Nov '22
10 Nov '22
2022-11-09 会议主题:安全委员会&安全技术sig例会 会议链接:https://us06web.zoom.us/j/86420547843?pwd=ZnMweEprMlk3cGkweG5iS0srQm9SUT09 主持人:毛晨曦 与会人:麒麟软件-崔雷、毛晨曦-SUSE、统信-魏东、魏刚、天翼云-吴开顺、天翼云-游益锋 会议议题: 1、社区漏洞感知情况汇报 - 闫志全 10.12-11.9,报告260条漏洞, 2条误报 2、10月份社区漏洞修复情况 - 颜小兵 (请假,推迟到下一次会议) 10月份发布安全公告56个,修复CVE漏洞117个(其中 Critical 8个,High 57个,其它 52个)。公告不受影响CVE 52个。 3、长时间挂起的CVE处理方式; (
https://gitee.com/src-openeuler/httpd/issues/I3W29D?from=project-issue
https://www.openeuler.org/zh/security/cve/
) 游益锋 建议按季度(每6次会议)review长期挂起的CVE的名单。 查找补丁功能需要CVE-manager定期刷新 Sig定期review CVE。 对于这些CVE,后续需要进行处理: 1. 是否存在直接修复的patch 2. 没有直接修复的patch,根据问题严重性,进行进一步分析,看是否需要进行版本升级或者修复 3. 列出长期挂起清单- 颜小兵 4、候补委员转正投票 - 魏刚 谈静国、毛晨曦 通过转正投票
5、CVE处理流程反馈收集情况(https://gitee.com/openeuler/security-committee/issues/I5VE2…
润和软件提出增加搜索选项,后续会和基础设施进行沟通 - 魏刚 6、安全委员会运作规范刷新情况 - 魏刚
提交PR(https://gitee.com/openeuler/security-committee/pulls/26),做线下评审,审核后的版本提…
7、openEuler基于SBOM的开源社区软件供应链安全方案实践 分享人:刘波 时长:30分钟
https://www.openeuler.org/zh/blog/robell/openEuler_SBOM_Practice.html
https://github.com/opensourceways/sbom-service
https://sbom-service.osinfra.cn/#/sbomPackages
遗留问题: 1. 列出CVE长期挂起清单- 颜小兵 2. 下一次例会开始ReviewCVE长期挂起清单 下次会议时间11.23, 主持人:颜小兵
1
0
0
0
凝思软件申报议题:开源HMIR、DSMS、CPDS到欧拉社区
by hazeng@linx-info.com
09 Nov '22
09 Nov '22
尊敬的技术委员会: 我司计划向社区贡献HMIR、DSMS、CPDS软件,特申报TC委员会例会议题。 HMIR(Host Management In Rust)是一组基于jsonrpc的restful接口,用于提供主机管理服务,目的是用于云计算、云桌面、虚拟化等主机管理,其功能包括主机服务管理、软件包管理、主机自启动管理、网络管理、FC存储管理、分布式存储管理等。提供安全可靠的RESTful API以方便使用和集成。 分布式存储管理系统 DSMS (Distributed Storage Management System)是一个分布式存储系统管理平台。该软件实现可视化的存储集群管理,提升易用性。同时基于凝思在电力、能源、银行等多行业底层系统建设的相关经验,对存储系统的安全性、稳定性、性能进行相应优化。 容器故障检测系统 CPDS (Container Problem Detect System) 是一个容器集群故障检测系统,该软件系统实现了对容器TOP故障、亚健康检测的监测与识别。 申请人:北京凝思软件
2
1
0
0
OpenStack SIG例会
by openEuler conference
09 Nov '22
09 Nov '22
您好! sig-openstack SIG 邀请您参加 2022-11-09 15:00 召开的Zoom会议(自动录制) 会议主题:OpenStack SIG例会 会议链接:https://us06web.zoom.us/j/82058120832?pwd=aWxOcXZsTlN3Q05Zd0VUd09sN1ZOQT09
会议纪要:https://etherpad.openeuler.org/p/sig-openstack-meetings
温馨提醒:建议接入会议后修改参会人的姓名,也可以使用您在gitee.com的ID
更多资讯尽在:https://openeuler.org/zh/
Hello! openEuler sig-openstack SIG invites you to attend the Zoom conference(auto recording) will be held at 2022-11-09 15:00, The subject of the conference is OpenStack SIG例会, You can join the meeting at
https://us06web.zoom.us/j/82058120832?pwd=aWxOcXZsTlN3Q05Zd0VUd09sN1ZOQT09
. Add topics at
https://etherpad.openeuler.org/p/sig-openstack-meetings
. Note: You are advised to change the participant name after joining the conference or use your ID at
gitee.com
. More information:
https://openeuler.org/en/
1
0
0
0
议题申请 回复:[Tc] tc双周例会
by 翁巧贞
08 Nov '22
08 Nov '22
TC委员会的老师们, 非常抱歉议题申请得有些晚。 因近期openEuler小助手收到一些想加入SIG组的开发者,他们或从官网、活动等了解openEuler, 但可能因为有些仓的介绍不够完整,比如缺少交流群、例会信息等,小助手交流起来也比较困难,因此,希望仓库中的readme文档能够进一步完善起来,方便开发者查看使用。 因此,可否在TC例会的群内讨论下,对sig的Readme文档进行优化或补充,包含
1
0
0
0
← Newer
1
...
123
124
125
126
127
128
129
...
338
Older →
Jump to page:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
Results per page:
10
25
50
100
200