mailweb.openeuler.org
Manage this list
×
Keyboard Shortcuts
Thread View
j
: Next unread message
k
: Previous unread message
j a
: Jump to all threads
j l
: Jump to MailingList overview
2024
November
October
September
August
July
June
May
April
March
February
January
2023
December
November
October
September
August
July
June
May
April
March
February
January
2022
December
November
October
September
August
July
June
May
April
March
February
January
2021
December
November
October
September
August
July
June
May
April
March
February
January
2020
December
November
October
List overview
Download
Release
October 2022
----- 2024 -----
November 2024
October 2024
September 2024
August 2024
July 2024
June 2024
May 2024
April 2024
March 2024
February 2024
January 2024
----- 2023 -----
December 2023
November 2023
October 2023
September 2023
August 2023
July 2023
June 2023
May 2023
April 2023
March 2023
February 2023
January 2023
----- 2022 -----
December 2022
November 2022
October 2022
September 2022
August 2022
July 2022
June 2022
May 2022
April 2022
March 2022
February 2022
January 2022
----- 2021 -----
December 2021
November 2021
October 2021
September 2021
August 2021
July 2021
June 2021
May 2021
April 2021
March 2021
February 2021
January 2021
----- 2020 -----
December 2020
November 2020
October 2020
release@openeuler.org
3 participants
9 discussions
Start a n
N
ew thread
openEuler 22.03 LTS SP1需求收集已截止,请大家确认需求是否都已经提交
by Sujinling
08 Nov '22
08 Nov '22
版本需求收集冻结时间10月15日,已经截止,请大家确认需求是否都已经提交。
https://gitee.com/openeuler/release-management/blob/master/openEuler-22.03-…
目前社区已提交的需求如下: no feature status sig owner 发布方式 涉及软件包列表 I5RDEG<
https://gitee.com/openeuler/release-management/issues/I5RDEG
> DDE组件更新支持服务器场景优化 Discussion sig-DDE @weidongkl<
https://gitee.com/weidongkl
> @panchenbo<
https://gitee.com/panchenbo
> EPOL I5RDGW<
https://gitee.com/openeuler/release-management/issues/I5RDGW
> 新增软件更新工具支持 Discussion sig-DDE @weidongkl<
https://gitee.com/weidongkl
> @panchenbo<
https://gitee.com/panchenbo
> EPOL deepin-upgrade-tool I5RDJS<
https://gitee.com/openeuler/release-management/issues/I5RDJS
> 新增备份还原功能支持 Discussion sig-Migration @blueblue<
https://gitee.com/blublue
> EPOL ubackup I5T3MB<
https://gitee.com/openeuler/release-management/issues/I5T3MB
> 新增ROS基础版和ROS2基础版 Discussion sig-ROS @anchuanxu<
https://gitee.com/anchuanxu
> @xiao_yun_wang<
https://gitee.com/xiao_yun_wang
> @wuwei_plct<
https://gitee.com/wuwei_plct
> EPOL ros_comm ros_base I5TT8E<
https://gitee.com/openeuler/release-management/issues/I5TT8E
> 发布kiran-desktop 2.4版本 Discussion sig-KIRAN-DESKTOP @tangjie02<
https://gitee.com/tangjie02
> EPOL kiran-control-panel,kiran-cc-daemon,kiran-qt5-integration,kiran-session-manager,kiran-log I5U6JV<
https://gitee.com/openeuler/release-management/issues/I5U6JV
> 支持树莓派 Discussion sig-RaspberryPi @woqidaideshi<
https://gitee.com/woqidaideshi
> EPOL raspberrypi-firmware,raspberrypi-bluetooth,raspi-config,pigpio,raspberrypi-userland,raspberrypi-eeprom 需求申请流程如下:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E9%9C%…
Thanks & best regards, 苏锦铃 00566192
4
3
0
0
openEuler update_20221024版本发布公告
by chemingdao
29 Oct '22
29 Oct '22
Dear all, 经社区Release SIG、QA SIG及 CICD SIG 评估,openEuler-20.03-LTS-SP1、openEuler-20.03-LTS-SP3及openEuler-22.03-LTS update版本满足版本出口质量,现进行发布公示。 本公示分为五部分: 1、openEuler-20.03-LTS-SP1 Update 20221024发布情况及待修复缺陷 2、openEuler-20.03-LTS-SP3 Update 20221024发布情况及待修复缺陷 3、openEuler-22.03-LTS Update 20221024发布情况及待修复缺陷 4、openEuler 关键组件待修复CVE 清单 5、openEuler 社区指导文档及开放平台链接 本次update版本发布后,下一个版本里程碑点(预计在2022/11/05)提供 update_20221031版本。 openEuler-20.03-LTS-SP1 Update 20221024 经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP1修复版本已知问题4个,已知漏洞26个。目前版本分支剩余待修复缺陷62个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库 openEuler-20.03-LTS-SP1 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I5X85F?from=project-i…
CVE修复: CVE 仓库 CVSS评分 CVE-2022-41849 kernel 4.2 CVE-2022-41742 nginx 7.1 CVE-2022-41741 nginx 7.8 CVE-2022-39260 git 8.8 CVE-2022-39253 git 5.5 CVE-2022-3627 libtiff 6.5 CVE-2022-3626 libtiff 6.5 CVE-2022-3599 libtiff 6.5 CVE-2022-3598 libtiff 6.5 CVE-2022-3597 libtiff 6.5 CVE-2022-3594 kernel 7.5 CVE-2022-3570 libtiff 9.8 CVE-2022-3566 kernel 7.1 CVE-2022-3565 kernel 8 CVE-2022-3564 kernel 8 CVE-2022-3545 kernel 7.8 CVE-2022-3542 kernel 5.5 CVE-2022-3535 kernel 3.5 CVE-2022-3524 kernel 7.5 CVE-2022-3521 kernel 2.5 CVE-2022-3515 libksba 8.1 CVE-2022-20423 kernel 4.6 CVE-2021-46848 libtasn1 9.1 CVE-2022-3517 nodejs-minimatch 7.5 CVE-2022-3555 libX11 7.5 CVE-2022-3554 libX11 7.5 Bugfix: issue 仓库 #I5XX3U:Backport and apply AutoBOLT from openEuler GCC 10.3.1 to openEuler GCC 7.3.1 gcc #I3BQJM:安装kmodtool构建的软件包时出现打印异常,但不影响功能 openEuler-rpm-config #I5XWVP:oec-hardware版本升级至1.1.3 oec-hardware #I5WW82:【openEuler-1.0-LTS】不支持 MegaRAID 9560-16i kernel openEuler-20.03-LTS-SP1版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1:Epol
openEuler-20.03-LTS-SP1 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/EPOL/update/
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP1 Update版本待修复问题清单公示: 任务ID 任务标题 关联仓库 SIG I281C1 【fuzz】runtime error: libsass Base-service I437CR [SP1][arm/x86]obs-server包下11个服务启动关闭,出现报错 obs-server Others I43OSX [clamav] 执行clamscan --statistics pcre命令会出现error,但是最终返回码为0 clamav Others I44RHB large loop in OBJ_obj2txt openssl sig-security-facility I44RIX large loop in bn_lshift_fixed_top openssl sig-security-facility I47I56 yum升级出现dkms的错误告警打印 dkms Others I48GIM 【20.03LTS SP1 update 210901】ovirt-cockpit-sso.service服务启动失败 ovirt-cockpit-sso oVirt I490MU Uncaught exception in get_tokens_unprocessed python-pygments Programming-language I4CJX9 [20.03-LTS-SP1] 389-ds-base包下的部分命令-v参数不显示版本号 three-eight-nine-ds-base Application I4F8YQ integer overflow in start_input_bmp libjpeg-turbo Desktop I4F8ZI heap-buffer-overflow in get_word_rgb_row libjpeg-turbo Desktop I4F903 Unexpect-exit in start_input_tga libjpeg-turbo Desktop I4F913 Timeout in tjDecompress2 libjpeg-turbo Desktop I4FRSL Undefined-shift in bitset_set augeas Desktop I4FT5J Timeout in fa_from_re augeas Desktop I4FT5U stack overflow in fa_from_re augeas Desktop I4FT61 stack overflow in re_case_expand augeas Desktop I4FT67 memleaks in ref_make_ref augeas Desktop I4FT6B SEGV in re_case_expand augeas Desktop I4FT6F stack overflow in parse_concat_exp augeas Desktop I4FT7B stack overflow in calc_eclosure_iter augeas Desktop I4FT8E stack overflow in peek_token augeas Desktop I4FT8P stack overflow in parse_path_expr augeas Desktop I4FT97 Out of memory in ns_from_locpath augeas Desktop I4FT9A SEGV in eval_expr augeas Desktop I4FT9C SEGV in tree_prev augeas Desktop I4FT9G stack overflow in check_expr augeas Desktop I4FT9I stack overflow in free_expr augeas Desktop I4G4A5 Undefine-shift in _bfd_safe_read_leb128 binutils Compiler I4G4B1 Integer overflow in print_vms_time binutils Compiler I4G4VY memleak in parse_gnu_debugaltlink binutils Compiler I4G4WF Heap-buffer-overflow in slurp_hppa_unwind_table binutils Compiler I4G4WW Use-after-free in make_qualified_name binutils Compiler I4G4X6 memleak in byte_get_little_endian binutils Compiler I4G4XF memleak in process_mips_specific binutils Compiler I4G4Y0 out-of-memory in vms_lib_read_index binutils Compiler I4G4YJ Heap-buffer-overflow in bfd_getl16 binutils Compiler I4G4YV Floating point exception in _bfd_vms_slurp_etir binutils Compiler I4G5TL stack-buffer-overflow in redisvFormatCommand hiredis Base-service I4G5U2 AddressSanitizer CHECK failed in sdscatvprintf hiredis Base-service I4G5UN SEGV in redisvFormatCommand hiredis Base-service I4G5WG AddressSanitizer CHECK failed in sdscatlen hiredis Base-service I4G5XO Attempting free wild-addr in hi_free hiredis Base-service I4J0OY 【20.03 SP1】【arm/x86】安装好libdap后,getdap4命令的-i和-k参数使用异常 libdap sig-recycle I4JMG4 【20.03 SP1】【arm/x86】robotframework包的三个命令:libdoc、rebot、robot执行--help/-h/-?/--version,查看帮助信息和版本信息,返回值为251 python-robotframework sig-ROS I4K6ES stack-buffer-overflow in UINT32_Marshal libtpms sig-security-facility I4K6FU global-buffer-overflow in Array_Marshal libtpms sig-security-facility I4K6R7 memleak in wrap_nettle_mpi_init gnutls sig-security-facility I4K6UI Timeout in _asn1_find_up gnutls sig-security-facility I4KT2A integer overflow in luaV_execute lua Base-service I4KT3D integer overflow in intarith lua Base-service I4KT3Q Division by zero in luaV_execute lua Base-service I4KT40 Timeout in luaV_finishget lua Base-service I4O16Z 【SP1_update/arm】安装kernel-4.19.90-2108版本有错误提示信息 kernel Kernel I4QV6N 【openEuler-20.03-LTS-SP1】flink命令执行失败 flink sig-bigdata I5G81X 【20.03 SP1】selinux-policy卸载异常 selinux-policy sig-security-facility I5GT2K 【20.03-SP1】【arm/x86】pcp-system-tools包下的pcp-mpstat命令执行报错 pcp Application I5IG1V 【20.03-SP1】【x86/arm】epol源下的efl、efl-devel软件包安装报错,gpg检查失败 efl sig-compat-winapp I5IG6K 【20.03-SP1】【x86/arm】epol源下的opencryptoki、opencryptoki-devel软件包安装报错,gpg检查失败 opencryptoki dev-utils I5JHX2 【20.03 SP1 update 20220727】ovirt-engine在update 20220727版本安装失败 ovirt-engine oVirt I5JNSL 【20.03 SP1 update 20220727】【arm】htcacheclean.service服务启动之后,日志中提示”Can't open PID file /run/httpd/htcacheclean/pid“ httpd Networking I5Q5D1 【20.03 SP1】ibus在sp1分支安装有异常告警 ibus Desktop openEuler-20.03-LTS-SP3 Update 20221024 经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP3修复版本已知问题4个,已知漏洞26个。目前版本分支剩余待修复缺陷14个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库 openEuler-20.03-LTS-SP3 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I5X85G?from=project-i…
CVE修复: 需求类型 软件包 CVSS评分 CVE-2022-41849 kernel 4.2 CVE-2022-41742 nginx 7.1 CVE-2022-41741 nginx 7.8 CVE-2022-39260 git 8.8 CVE-2022-39253 git 5.5 CVE-2022-3627 libtiff 6.5 CVE-2022-3626 libtiff 6.5 CVE-2022-3599 libtiff 6.5 CVE-2022-3598 libtiff 6.5 CVE-2022-3597 libtiff 6.5 CVE-2022-3594 kernel 7.5 CVE-2022-3570 libtiff 9.8 CVE-2022-3566 kernel 7.1 CVE-2022-3565 kernel 8 CVE-2022-3564 kernel 8 CVE-2022-3545 kernel 7.8 CVE-2022-3542 kernel 5.5 CVE-2022-3535 kernel 3.5 CVE-2022-3524 kernel 7.5 CVE-2022-3521 kernel 2.5 CVE-2022-3515 libksba 8.1 CVE-2022-20423 kernel 4.6 CVE-2021-46848 libtasn1 9.1 CVE-2022-3517 nodejs-minimatch 7.5 CVE-2022-3555 libX11 7.5 CVE-2022-3554 libX11 7.5 Bugfix: issue 仓库 #I5XX3U:Backport and apply AutoBOLT from openEuler GCC 10.3.1 to openEuler GCC 7.3.1 gcc #I5XWVQ:oec-hardware版本升级至1.1.3 oec-hardware #I5XV88:第三方模块构建热补丁时报错 kpatch #I5WW82:【openEuler-1.0-LTS】不支持 MegaRAID 9560-16i<
https://gitee.com/open_euler/dashboard?issue_id=I5WW82
> kernel openEuler-20.03-LTS-SP3版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3:Epol
openEuler-20.03-LTS-SP3 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/EPOL/update/main/
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP3 Update版本待修复问题清单公示: 任务ID 任务标题 关联仓库 SIG I4QV7S 【openEuler-20.03-LTS-SP3】flink run 命令执行失败 flink sig-bigdata I4RVHE losetup : 当loop设备编号超过7位时,losetup命令无法操作该设备 util-linux Base-service I4UMEV [openEuler 20.03-LTS SP3]openEuler开启crash_kexec_post_notifiers后,panic通知链无法完全遍历 kernel Kernel I5IGAS 【20.03-SP3】【x86/arm】epol源下的opencryptoki、opencryptoki-devel软件包安装报错,gpg检查失败 opencryptoki dev-utils I5IGOR 【20.03-SP3】【x86/arm】epol源下的fluidsynth、fluidsynth-devel、fluidsynth-help软件包安装报错,gpg检查失败 fluidsynth Application I5JBJ9 【20.03 SP3_EPOL_update20220727】ovirt-engine-backend包卸载过程的告警信息需要优化 ovirt-engine oVirt I5JLNF 【20.03 SP3 update 20220727】【arm/x86】ovirt-websocket-proxy.service服务启动失败 ovirt-engine oVirt I5JLRQ 【20.03 SP3 update 20220727】【arm/x86】ovirt-engine-notifier.service服务启动失败 ovirt-engine oVirt I5KXUY 【20.03 LTS SP3 update 20220803】【arm/x86】ovirt-cockpit-sso.service服务启动失败 ovirt-cockpit-sso oVirt I5KY4S 【20.03 LTS SP3 update 20220803】【arm/x86】vdsmd.service服务启动失败,导致mom-vdsm.service服务无法启动成功 vdsm oVirt I5LYJK 【20.03-sp3_update20220801】【x86】对内核版进行升级后,TCP_option_address安装异常 TCP_option_address Kernel I5PT12 [20.03-LTS-SP3]spec文件存在软件包编译依赖自身,且打包包含系统环境文件 ima-evm-utils Base-service I5PUIA [20.03-LTS-SP3]spec文件存在软件包编译依赖自身,且打包包含系统环境文件 qrencode Desktop I5SCLC 【20.03 SP3】selinux-policy卸载异常 selinux-policy sig-security-facility openEuler-22.03-LTS Update 20221024 经各SIG及社区开发者贡献,本周openEuler-22.03-LTS修复版本已知问题5个,已知漏洞17个。目前版本分支剩余待修复缺陷10个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库 openEuler-22.03-LTS Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I5X85H?from=project-i…
CVE修复: CVE 仓库 CVSS评分 CVE-2022-41742 nginx 7.1 CVE-2022-41741 nginx 7.8 CVE-2022-39260 git 8.8 CVE-2022-39253 git 5.5 CVE-2022-3627 libtiff 6.5 CVE-2022-3626 libtiff 6.5 CVE-2022-3599 libtiff 6.5 CVE-2022-3598 libtiff 6.5 CVE-2022-3597 libtiff 6.5 CVE-2022-3570 libtiff 9.8 CVE-2022-3515 libksba 8.1 CVE-2022-3165 qemu 6.5 CVE-2022-20423 kernel 4.6 CVE-2021-46848 libtasn1 9.1 CVE-2022-3517 nodejs-minimatch 7.5 CVE-2022-3555 libX11 7.5 CVE-2022-3554 libX11 7.5 Bugfix: issue 仓库 #I5RYNU:删除二进制命令文件包含的RPATH和RUNPATH acl #I5UHVY:例行分析grub2软件包开源补丁 grub2 #I5XWVV:oec-hardware版本升级至1.1.3 oec-hardware #I5WI80:upgrade to jdk11.0.17-8(GA) openjdk-11 #I5UNSG: libbpf软件包开源补丁回合 libbpf openEuler-22.03-LTS版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:22.03:LTS
https://build.openeuler.org/project/show/openEuler:22.03:LTS:Epol
openEuler-22.03-LTS Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS/update/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
openEuler-22.03-LTS Update版本待修复问题清单公示: 任务ID 任务标题 关联仓库 SIG I5G9CY 升级iinstall-scripts包会导致系统启动异常 install-scripts sig-OS-Builder I5JIA6 【22.03 LTS update 20220727】ovirt-engine在update 20220727版本安装失败 ovirt-engine oVirt I5JPII 【22.03_update20220727】【x86/arm】ovirt-engine源码包本地自编译失败,缺少编译依赖ovirt-jboss-modules-maven-plugin ovirt-engine oVirt I5LKKX libbluray build problem in openEuler:22.03:LTS libbluray Desktop I5LKM6 libxshmfence build problem in openEuler:22.03:LTS libxshmfence Desktop I5LKY8 yaffs2 build problem in openEuler:22.03:LTS yaffs2 sig-embedded I5QKGT 【22.03LTS_update0907】【arm/x86】kmod-drbd90软件包安装之后文件有缺失 kmod-drbd90 sig-Ha I5RHYO 【22.09 RC4】【arm/x86】package.ini中的redis_host配置为不存在的ip,重启pkgship服务失败,服务一直在尝试重启 pkgship sig-EasyLife I5Q4S3 [22.03-LTS]x86虚拟机卸载qxl模块,机器自动重启 kernel Kernel I5TMFF [22.03-LTS]先安装mysql-server,卸载后再安装mariadb-server,mariadb服务启动失败 mariadb DB 社区待修复漏洞: openEuler社区根据漏洞严重等级采取差异化的修复策略,请各个SIG 关注涉及CVE组件的修复情况。 严重等级(Severity Rating) 漏洞修复时长 致命(Critical) 7天 高(High) 14天 中(Medium) 30天 低(Low) 30天
可参考社区安全委员会漏洞:https://gitee.com/openeuler/security-committee/wikis/%E7%A4%BE…
近14天将超期CVE: 漏洞编号 剩余天数 CVSS评分 软件包 SIG CVE-2022-41849 0.97 4.2 risc-v-kernel sig-RISC-V CVE-2022-41850 0.97 4.7 risc-v-kernel sig-RISC-V CVE-2022-41848 0.98 4.2 risc-v-kernel sig-RISC-V CVE-2022-0778 1.61 7.5 mariadb DB CVE-2022-3529 2.07 7.5 risc-v-kernel sig-RISC-V CVE-2022-3527 2.07 7.5 risc-v-kernel sig-RISC-V CVE-2022-3528 2.07 7.5 risc-v-kernel sig-RISC-V CVE-2022-3534 2.21 8 risc-v-kernel sig-RISC-V CVE-2022-3530 2.21 7.5 risc-v-kernel sig-RISC-V CVE-2022-3545 2.22 7.8 risc-v-kernel sig-RISC-V CVE-2022-3541 2.22 7.8 risc-v-kernel sig-RISC-V CVE-2022-3553 2.57 7.5 xorg-x11-server Desktop CVE-2022-3566 2.65 7.1 risc-v-kernel sig-RISC-V CVE-2022-3567 2.65 7.1 risc-v-kernel sig-RISC-V CVE-2022-3565 2.65 8 risc-v-kernel sig-RISC-V CVE-2022-3564 2.65 8 risc-v-kernel sig-RISC-V CVE-2022-3551 3.09 7.5 xorg-x11-server Desktop CVE-2018-19518 4.09 7.5 php Base-service CVE-2018-19935 4.1 7.5 php Base-service CVE-2022-42468 4.33 9.8 flume sig-bigdata CVE-2022-34169 4.37 7.5 openjdk-1.8.0 Compiler CVE-2022-41420 4.56 5.5 nasm Programming-language CVE-2022-40617 5.34 strongswan Application CVE-2022-3625 5.87 7.8 kernel Kernel CVE-2022-3625 5.87 7.8 risc-v-kernel sig-RISC-V CVE-2022-3623 6.06 7.5 risc-v-kernel sig-RISC-V CVE-2022-3621 6.06 7.5 risc-v-kernel sig-RISC-V CVE-2022-3623 6.06 7.5 kernel Kernel CVE-2022-3621 6.06 7.5 kernel Kernel CVE-2022-3647 6.83 7.5 redis6 sig-bigdata CVE-2022-3647 6.83 7.5 redis5 sig-bigdata CVE-2022-3640 6.83 8.8 risc-v-kernel sig-RISC-V CVE-2022-3635 6.83 7 risc-v-kernel sig-RISC-V CVE-2022-3636 6.83 7.8 risc-v-kernel sig-RISC-V CVE-2022-3635 6.84 7 kernel Kernel CVE-2022-32172 8.14 5.4 zinc sig-Java CVE-2022-32171 8.14 5.4 zinc sig-Java CVE-2022-3424 8.22 risc-v-kernel sig-RISC-V CVE-2022-3577 8.68 7.8 risc-v-kernel sig-RISC-V CVE-2022-3435 9.22 4.3 risc-v-kernel sig-RISC-V CVE-2022-43680 9.43 7.5 expat Base-service CVE-2022-3647 9.94 7.5 redis Others CVE-2019-2684 10.71 5.9 tomcat Application CVE-2022-42703 10.72 5.5 risc-v-kernel sig-RISC-V CVE-2022-41704 10.83 7.5 batik sig-Java CVE-2022-42890 10.86 7.5 batik sig-Java CVE-2022-43750 10.93 7.8 risc-v-kernel sig-RISC-V CVE-1999-0634 12.95 openssh Networking CVE-2022-3466 13.22 cri-o sig-CloudNative CVE-2022-42721 14.1 5.5 risc-v-kernel sig-RISC-V CVE-2022-42721 14.1 5.5 kernel Kernel CVE-2022-42722 14.22 5.5 kernel Kernel CVE-2022-42722 14.22 5.5 risc-v-kernel sig-RISC-V CVE-2022-39229 14.73 4.3 grafana Application openEuler 社区指导文档及开放平台链接: openEuler 版本分支维护规范:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E7%89%…
openEuler release-management 版本分支PR指导:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E5%BC%…
社区QA 版本测试提单规范
https://gitee.com/openeuler/QA/blob/839f952696f271f83c018ccf3218cf493b92d65…
社区QA 测试平台 radiates
https://radiatest.openeuler.org
<
https://radiatest.openeuler.org/
> 车明道(openEuler release SIG) Mobile: +86 15345431107 中国(China)-杭州(Hangzhou)-滨江区江淑路360号华为杭州研发中心 HUAWEI , Jiangshu Road., Binjiang District, Hangzhou, P.R.China E-mail: chemingdao(a)huawei.com<mailto:chemingdao@huawei.com> [cid:image002.png@01D8EBB8.F723AD90]Open Source OS for Digital Infrastructure 本邮件及其附件含有华为公司的保密信息,仅限于发送给上面地址中列出的个人或群组。禁止任何其他人以任何形 式使用(包括但不限于全部或部分地泄露、复制、或散发)本邮件中的信息。如果您错收了本邮件,请您立即电话 或邮件通知发件人并删除本邮件! This e-mail and its attachments contain confidential information from HUAWEI, which is intended only for the person or entity whose address is listed above. Any use of the information contained herein in any way (including, but not limited to, total or partial disclosure, reproduction, or dissemination) by persons other than the intended recipient(s) is prohibited. If you receive this e-mail in error, please notify the sender by phone or email immediately and delete it
1
0
0
0
Release SIG例会
by openEuler conference
25 Oct '22
25 Oct '22
您好! sig-release-management SIG 邀请您参加 2022-10-28 10:00 召开的Zoom会议(自动录制) 会议主题:Release SIG例会 会议内容: 1、openEuler 22.03-LTS SP1版本releaseplan 评审 2、openEuler 22.03-LTS SP1版本软件包选型升级策略讨论 3、openEuler 构建服务更新 会议链接:https://us06web.zoom.us/j/86789787735?pwd=YkFLeVgwbzBwYTRkdGt6UVNUV3g2Zz09
会议纪要:https://etherpad.openeuler.org/p/sig-release-management-meetings
温馨提醒:建议接入会议后修改参会人的姓名,也可以使用您在gitee.com的ID
更多资讯尽在:https://openeuler.org/zh/
Hello! openEuler sig-release-management SIG invites you to attend the Zoom conference(auto recording) will be held at 2022-10-28 10:00, The subject of the conference is Release SIG例会, Summary: 1、openEuler 22.03-LTS SP1版本releaseplan 评审 2、openEuler 22.03-LTS SP1版本软件包选型升级策略讨论 3、openEuler 构建服务更新 You can join the meeting at
https://us06web.zoom.us/j/86789787735?pwd=YkFLeVgwbzBwYTRkdGt6UVNUV3g2Zz09
. Add topics at
https://etherpad.openeuler.org/p/sig-release-management-meetings
. Note: You are advised to change the participant name after joining the conference or use your ID at
gitee.com
. More information:
https://openeuler.org/en/
1
0
0
0
openEuler update_20221017版本发布公告
by chemingdao
21 Oct '22
21 Oct '22
Dear all, 经社区Release SIG、QA SIG及 CICD SIG 评估,openEuler-20.03-LTS-SP1、openEuler-20.03-LTS-SP3及openEuler-22.03-LTS update版本满足版本出口质量,现进行发布公示。 本公示分为五部分: 1、openEuler-20.03-LTS-SP1 Update 20221017发布情况及待修复缺陷 2、openEuler-20.03-LTS-SP3 Update 20221017发布情况及待修复缺陷 3、openEuler-22.03-LTS Update 20221017发布情况及待修复缺陷 4、openEuler 关键组件待修复CVE 清单 5、openEuler 社区指导文档及开放平台链接 本次update版本发布后,下一个版本里程碑点(预计在2022/10/28)提供 update_20221024版本。 openEuler-20.03-LTS-SP1 Update 20221017 经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP1修复版本已知问题1个,已知漏洞24个。目前版本分支剩余待修复缺陷62个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库 openEuler-20.03-LTS-SP1 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I5VZVG?from=project-i…
CVE修复: CVE 仓库 CVSS评分 CVE-2022-42703 kernel 5.5 CVE-2022-42012 dbus 6.5 CVE-2022-42011 dbus 6.5 CVE-2022-42010 dbus 6.5 CVE-2022-41850 kernel 4.7 CVE-2022-41715 golang 4 CVE-2022-37434 mariadb-connector-c 9.8 CVE-2022-3324 vim 7.8 CVE-2022-3297 vim 7.8 CVE-2022-2929 dhcp 6.5 CVE-2022-2928 dhcp 7.5 CVE-2022-2880 golang 5.3 CVE-2022-2879 golang 6.2 CVE-2022-2058 libtiff 6.5 CVE-2022-2056 libtiff 6.5 CVE-2022-20422 kernel 7 CVE-2022-20421 kernel 7.8 CVE-2022-1941 protobuf 7.5 CVE-2020-0198 libexif 7.5 CVE-2020-0181 libexif 7.5 CVE-2020-0093 libexif 5 CVE-2019-9278 libexif 8.8 CVE-2019-1010180 crash 7.8 CVE-2021-33036 hadoop 8.8 Bugfix: issue 仓库 #I5T5DD:[openEuler-1.0-LTS] 解决持有zone->lock后调用printk导致的 lockdep 问题 kernel openEuler-20.03-LTS-SP1版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1:Epol
openEuler-20.03-LTS-SP1 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/EPOL/update/
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP1 Update版本待修复问题清单公示: 任务ID 任务标题 关联仓库 SIG I281C1 【fuzz】runtime error: libsass Base-service I437CR [SP1][arm/x86]obs-server包下11个服务启动关闭,出现报错 obs-server Others I43OSX [clamav] 执行clamscan --statistics pcre命令会出现error,但是最终返回码为0 clamav Others I44RHB large loop in OBJ_obj2txt openssl sig-security-facility I44RIX large loop in bn_lshift_fixed_top openssl sig-security-facility I47I56 yum升级出现dkms的错误告警打印 dkms Others I48GIM 【20.03LTS SP1 update 210901】ovirt-cockpit-sso.service服务启动失败 ovirt-cockpit-sso oVirt I490MU Uncaught exception in get_tokens_unprocessed python-pygments Programming-language I4CJX9 [20.03-LTS-SP1] 389-ds-base包下的部分命令-v参数不显示版本号 three-eight-nine-ds-base Application I4F8YQ integer overflow in start_input_bmp libjpeg-turbo Desktop I4F8ZI heap-buffer-overflow in get_word_rgb_row libjpeg-turbo Desktop I4F903 Unexpect-exit in start_input_tga libjpeg-turbo Desktop I4F913 Timeout in tjDecompress2 libjpeg-turbo Desktop I4FRSL Undefined-shift in bitset_set augeas Desktop I4FT5J Timeout in fa_from_re augeas Desktop I4FT5U stack overflow in fa_from_re augeas Desktop I4FT61 stack overflow in re_case_expand augeas Desktop I4FT67 memleaks in ref_make_ref augeas Desktop I4FT6B SEGV in re_case_expand augeas Desktop I4FT6F stack overflow in parse_concat_exp augeas Desktop I4FT7B stack overflow in calc_eclosure_iter augeas Desktop I4FT8E stack overflow in peek_token augeas Desktop I4FT8P stack overflow in parse_path_expr augeas Desktop I4FT97 Out of memory in ns_from_locpath augeas Desktop I4FT9A SEGV in eval_expr augeas Desktop I4FT9C SEGV in tree_prev augeas Desktop I4FT9G stack overflow in check_expr augeas Desktop I4FT9I stack overflow in free_expr augeas Desktop I4G4A5 Undefine-shift in _bfd_safe_read_leb128 binutils Compiler I4G4B1 Integer overflow in print_vms_time binutils Compiler I4G4VY memleak in parse_gnu_debugaltlink binutils Compiler I4G4WF Heap-buffer-overflow in slurp_hppa_unwind_table binutils Compiler I4G4WW Use-after-free in make_qualified_name binutils Compiler I4G4X6 memleak in byte_get_little_endian binutils Compiler I4G4XF memleak in process_mips_specific binutils Compiler I4G4Y0 out-of-memory in vms_lib_read_index binutils Compiler I4G4YJ Heap-buffer-overflow in bfd_getl16 binutils Compiler I4G4YV Floating point exception in _bfd_vms_slurp_etir binutils Compiler I4G5TL stack-buffer-overflow in redisvFormatCommand hiredis Base-service I4G5U2 AddressSanitizer CHECK failed in sdscatvprintf hiredis Base-service I4G5UN SEGV in redisvFormatCommand hiredis Base-service I4G5WG AddressSanitizer CHECK failed in sdscatlen hiredis Base-service I4G5XO Attempting free wild-addr in hi_free hiredis Base-service I4J0OY 【20.03 SP1】【arm/x86】安装好libdap后,getdap4命令的-i和-k参数使用异常 libdap sig-recycle I4JMG4 【20.03 SP1】【arm/x86】robotframework包的三个命令:libdoc、rebot、robot执行--help/-h/-?/--version,查看帮助信息和版本信息,返回值为251 python-robotframework sig-ROS I4K6ES stack-buffer-overflow in UINT32_Marshal libtpms sig-security-facility I4K6FU global-buffer-overflow in Array_Marshal libtpms sig-security-facility I4K6R7 memleak in wrap_nettle_mpi_init gnutls sig-security-facility I4K6UI Timeout in _asn1_find_up gnutls sig-security-facility I4KT2A integer overflow in luaV_execute lua Base-service I4KT3D integer overflow in intarith lua Base-service I4KT3Q Division by zero in luaV_execute lua Base-service I4KT40 Timeout in luaV_finishget lua Base-service I4O16Z 【SP1_update/arm】安装kernel-4.19.90-2108版本有错误提示信息 kernel Kernel I4QV6N 【openEuler-20.03-LTS-SP1】flink命令执行失败 flink sig-bigdata I5G81X 【20.03 SP1】selinux-policy卸载异常 selinux-policy sig-security-facility I5GT2K 【20.03-SP1】【arm/x86】pcp-system-tools包下的pcp-mpstat命令执行报错 pcp Application I5IG1V 【20.03-SP1】【x86/arm】epol源下的efl、efl-devel软件包安装报错,gpg检查失败 efl sig-compat-winapp I5IG6K 【20.03-SP1】【x86/arm】epol源下的opencryptoki、opencryptoki-devel软件包安装报错,gpg检查失败 opencryptoki dev-utils I5JHX2 【20.03 SP1 update 20220727】ovirt-engine在update 20220727版本安装失败 ovirt-engine oVirt I5JNSL 【20.03 SP1 update 20220727】【arm】htcacheclean.service服务启动之后,日志中提示”Can't open PID file /run/httpd/htcacheclean/pid“ httpd Networking I5Q5D1 【20.03 SP1】ibus在sp1分支安装有异常告警 ibus Desktop openEuler-20.03-LTS-SP3 Update 20221017 经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP3修复版本已知问题3个,已知漏洞21个。目前版本分支剩余待修复缺陷14个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库 openEuler-20.03-LTS-SP3 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I5VZW1?from=project-i…
CVE修复: 需求类型 软件包 CVSS评分 CVE-2022-42703 kernel 5.5 CVE-2022-41850 kernel 4.7 CVE-2022-41715 golang 4 CVE-2022-37434 mariadb-connector-c 9.8 CVE-2022-3324 vim 7.8 CVE-2022-3297 vim 7.8 CVE-2022-2929 dhcp 6.5 CVE-2022-2928 dhcp 7.5 CVE-2022-2880 golang 5.3 CVE-2022-2879 golang 6.2 CVE-2022-2058 libtiff 6.5 CVE-2022-2056 libtiff 6.5 CVE-2022-20422 kernel 7 CVE-2022-20421 kernel 7.8 CVE-2022-1941 protobuf 7.5 CVE-2020-0198 libexif 7.5 CVE-2020-0181 libexif 7.5 CVE-2020-0093 libexif 5 CVE-2019-9278 libexif 8.8 CVE-2019-1010180 crash 7.8 CVE-2021-33036 hadoop 8.8 Bugfix: issue 仓库 #I5NQEE:虚拟机安装时,环形进度条不转动 anaconda #I5T5DD:[openEuler-1.0-LTS] 解决持有zone->lock后调用printk导致的 lockdep 问题 kernel #I5UV23:【20.03 LTS SP3】libcareplus升级到1.0.0-13 libcareplus openEuler-20.03-LTS-SP3版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3:Epol
openEuler-20.03-LTS-SP3 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/EPOL/update/main/
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP3 Update版本待修复问题清单公示: 任务ID 任务标题 关联仓库 SIG I4QV7S 【openEuler-20.03-LTS-SP3】flink run 命令执行失败 flink sig-bigdata I4RVHE losetup : 当loop设备编号超过7位时,losetup命令无法操作该设备 util-linux Base-service I4UMEV [openEuler 20.03-LTS SP3]openEuler开启crash_kexec_post_notifiers后,panic通知链无法完全遍历 openEuler/kernel Kernel I5IGAS 【20.03-SP3】【x86/arm】epol源下的opencryptoki、opencryptoki-devel软件包安装报错,gpg检查失败 opencryptoki dev-utils I5IGOR 【20.03-SP3】【x86/arm】epol源下的fluidsynth、fluidsynth-devel、fluidsynth-help软件包安装报错,gpg检查失败 fluidsynth Application I5JBJ9 【20.03 SP3_EPOL_update20220727】ovirt-engine-backend包卸载过程的告警信息需要优化 ovirt-engine oVirt I5JLNF 【20.03 SP3 update 20220727】【arm/x86】ovirt-websocket-proxy.service服务启动失败 ovirt-engine oVirt I5JLRQ 【20.03 SP3 update 20220727】【arm/x86】ovirt-engine-notifier.service服务启动失败 ovirt-engine oVirt I5KXUY 【20.03 LTS SP3 update 20220803】【arm/x86】ovirt-cockpit-sso.service服务启动失败 ovirt-cockpit-sso oVirt I5KY4S 【20.03 LTS SP3 update 20220803】【arm/x86】vdsmd.service服务启动失败,导致mom-vdsm.service服务无法启动成功 vdsm oVirt I5LYJK 【20.03-sp3_update20220801】【x86】对内核版进行升级后,TCP_option_address安装异常 TCP_option_address Kernel I5PT12 [20.03-LTS-SP3]spec文件存在软件包编译依赖自身,且打包包含系统环境文件 ima-evm-utils Base-service I5PUIA [20.03-LTS-SP3]spec文件存在软件包编译依赖自身,且打包包含系统环境文件 qrencode Desktop I5SCLC 【20.03 SP3】selinux-policy卸载异常 selinux-policy sig-security-facility openEuler-22.03-LTS Update 20221017 经各SIG及社区开发者贡献,本周openEuler-22.03-LTS修复版本已知问题11个,已知漏洞29个。目前版本分支剩余待修复缺陷11个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库 openEuler-22.03-LTS Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I5VZWL?from=project-i…
CVE修复: CVE 仓库 CVSS评分 CVE-2022-3297 vim 7.8 CVE-2022-3324 vim 7.8 CVE-2022-1941 protobuf 7.5 CVE-2022-37434 mariadb-connector-c 9.8 CVE-2022-2056 libtiff 6.5 CVE-2022-2058 libtiff 6.5 CVE-2022-1184 kernel 5.5 CVE-2022-20421 kernel 7.8 CVE-2022-20422 kernel 7 CVE-2022-3303 kernel 4.7 CVE-2022-3435 kernel 4.3 CVE-2022-41674 kernel 8.1 CVE-2022-41849 kernel 4.2 CVE-2022-41850 kernel 4.7 CVE-2022-42703 kernel 5.5 CVE-2022-42719 kernel 8.8 CVE-2022-42720 kernel 7.8 CVE-2022-42721 kernel 5.5 CVE-2022-2879 golang 6.2 CVE-2022-2880 golang 5.3 CVE-2022-41715 golang 4 CVE-2022-2928 dhcp 7.5 CVE-2022-2929 dhcp 6.5 CVE-2022-42010 dbus 6.5 CVE-2022-42011 dbus 6.5 CVE-2022-42012 dbus 6.5 CVE-2019-10101 crash 7.8 CVE-2021-34337 mailman 7.4 CVE-2021-33036 hadoop 8.8 Bugfix: issue 仓库 #I5NQEE:虚拟机安装时,环形进度条不转动 anaconda #I5T5DD:[openEuler-1.0-LTS] 解决持有zone->lock后调用printk导致的 lockdep 问题 kernel #I416C7:kernel-rpm-macros 不支持-p |preamble 参数, openEuler-rpm-config #I5LQP4:[22.09-RC1][aarch64/x86_64]安装完成后输入命令“yum grouplist hidden”回显缺少“Installed Environment Groups” 和 “Installed Groups”子项 dnf #I5UYJU: 有不支持的段,导致热补丁编译失败 kpatch #I5TQQR:openEuler-22.03-LTS和openEuler-20.03-LTS-SP1分支spec差异排查和同步 NetworkManager #I5TWH0:【22.03-LTS】NetworkManager主包中存在多余库文件 NetworkManager #I5WBM8:initscripts spec优化 initscripts #I5WMUY:[libpsl] change release number libpsl #I5W498:【OLK-5.10】IO长稳测试中,正常下发读写时出现文件系统错误导致挂载为readonly kernel #I5WN5N:hange default ntp server and correct the default value of RuntimeDirectoryInodesMax systemd openEuler-22.03-LTS版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:22.03:LTS
https://build.openeuler.org/project/show/openEuler:22.03:LTS:Epol
openEuler-22.03-LTS Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS/update/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
openEuler-22.03-LTS Update版本待修复问题清单公示: 任务ID 任务标题 关联仓库 SIG I5G9CY 升级iinstall-scripts包会导致系统启动异常 install-scripts sig-OS-Builder I5JIA6 【22.03 LTS update 20220727】ovirt-engine在update 20220727版本安装失败 ovirt-engine oVirt I5JPII 【22.03_update20220727】【x86/arm】ovirt-engine源码包本地自编译失败,缺少编译依赖ovirt-jboss-modules-maven-plugin ovirt-engine oVirt I5LKKX libbluray build problem in openEuler:22.03:LTS libbluray Desktop I5LKM6 libxshmfence build problem in openEuler:22.03:LTS libxshmfence Desktop I5LKY8 yaffs2 build problem in openEuler:22.03:LTS yaffs2 sig-embedded I5Q4S3 [22.03-LTS]x86虚拟机卸载qxl模块,机器自动重启 openEuler/kernel Kernel I5QKGT 【22.03LTS_update0907】【arm/x86】kmod-drbd90软件包安装之后文件有缺失 kmod-drbd90 sig-Ha I5RHYO 【22.09 RC4】【arm/x86】package.ini中的redis_host配置为不存在的ip,重启pkgship服务失败,服务一直在尝试重启 pkgship sig-EasyLife I5TMFF [22.03-LTS]先安装mysql-server,卸载后再安装mariadb-server,mariadb服务启动失败 mariadb DB I5VL9Q [22.03-LTS]安装完成后输入命令“yum grouplist hidden”回显缺少“Installed Environment Groups” 和 “Installed Groups”子项 anaconda sig-OS-Builder 社区待修复漏洞: openEuler社区根据漏洞严重等级采取差异化的修复策略,请各个SIG 关注涉及CVE组件的修复情况。 严重等级(Severity Rating) 漏洞修复时长 致命(Critical) 7天 高(High) 14天 中(Medium) 30天 低(Low) 30天
可参考社区安全委员会漏洞:https://gitee.com/openeuler/security-committee/wikis/%E7%A4%BE…
近14天将超期CVE: 漏洞编号 剩余天数 CVSS评分 软件包 SIG CVE-2022-37026 3.79 9.8 erlang Programming-language CVE-2022-32149 4.87 7.5 golang sig-golang CVE-2022-40674 5.7 9.8 firefox Application CVE-2022-41083 5.78 7.8 jupyter sig-bigdata CVE-2022-3479 5.93 7.5 nss sig-security-facility CVE-2022-42720 5.94 7.8 risc-v-kernel sig-RISC-V CVE-2022-42719 5.94 8.8 kernel Kernel CVE-2022-41674 5.94 8.1 kernel Kernel CVE-2022-42720 5.94 7.8 kernel Kernel CVE-2022-42719 5.94 8.8 risc-v-kernel sig-RISC-V CVE-2022-41674 5.94 8.1 risc-v-kernel sig-RISC-V CVE-2022-39201 6.57 7.5 grafana Application CVE-2022-31130 6.58 7.5 grafana Application CVE-2022-31123 6.73 7.8 grafana Application CVE-2022-3517 7.31 7.5 nodejs-minimatch sig-nodejs CVE-2022-3526 9.44 7.5 kernel Kernel CVE-2022-3522 9.44 7 kernel Kernel CVE-2022-3524 9.44 7.5 kernel Kernel CVE-2022-0778 9.45 7.5 mariadb DB CVE-2022-42969 9.52 7.5 python-py Programming-language CVE-2022-3529 9.91 7.5 risc-v-kernel sig-RISC-V CVE-2022-3527 9.91 7.5 risc-v-kernel sig-RISC-V CVE-2022-3528 9.91 7.5 risc-v-kernel sig-RISC-V CVE-2022-3527 9.91 7.5 kernel Kernel CVE-2022-3528 9.91 7.5 kernel Kernel CVE-2022-3554 10.05 7.5 libX11 Desktop CVE-2022-3545 10.05 7.8 kernel Kernel CVE-2022-3555 10.05 7.5 libX11 Desktop CVE-2022-3541 10.05 7.8 kernel Kernel CVE-2022-3534 10.05 8 kernel Kernel CVE-2022-3530 10.05 7.5 risc-v-kernel sig-RISC-V CVE-2022-3530 10.05 7.5 kernel Kernel CVE-2022-3545 10.06 7.8 risc-v-kernel sig-RISC-V CVE-2022-3541 10.06 7.8 risc-v-kernel sig-RISC-V CVE-2022-3534 10.06 8 risc-v-kernel sig-RISC-V CVE-2022-3553 10.42 7.5 xorg-x11-server Desktop CVE-2022-3566 10.49 7.1 risc-v-kernel sig-RISC-V CVE-2022-3565 10.49 8 risc-v-kernel sig-RISC-V CVE-2022-3566 10.49 7.1 kernel Kernel CVE-2022-3565 10.49 8 kernel Kernel CVE-2022-3564 10.49 8 risc-v-kernel sig-RISC-V CVE-2022-3564 10.49 8 kernel Kernel CVE-2018-14553 10.73 7.5 gd Desktop CVE-2018-1000222 10.73 8.8 gd Desktop CVE-2022-32893 10.78 8.8 webkit2gtk3 Desktop CVE-2022-24107 10.79 7.8 poppler Desktop CVE-2022-24106 10.79 7.8 poppler Desktop CVE-2020-36604 10.79 8.1 nodejs-hoek sig-nodejs CVE-2022-38222 10.8 7.8 poppler Desktop CVE-2018-12015 10.85 7.5 tar Base-service CVE-2021-252893 10.91 7.5 python-pillow sig-python-modules CVE-2021-252891 10.91 7.5 python-pillow sig-python-modules CVE-2022-3551 10.93 7.5 xorg-x11-server Desktop CVE-2022-3594 11.38 7.5 kernel Kernel CVE-2018-5744 11.49 7.5 bind Networking CVE-2022-39260 11.56 8.5 git Base-service CVE-2018-19518 11.93 7.5 php Base-service CVE-2018-19935 11.94 7.5 php Base-service CVE-2022-41420 12.4 5.5 nasm Programming-language CVE-2022-40617 13.19 strongswan Application CVE-2022-20424 13.44 kernel Kernel CVE-2022-20423 13.56 4.6 kernel Kernel openEuler 社区指导文档及开放平台链接: openEuler 版本分支维护规范:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E7%89%…
openEuler release-management 版本分支PR指导:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E5%BC%…
社区QA 版本测试提单规范
https://gitee.com/openeuler/QA/blob/839f952696f271f83c018ccf3218cf493b92d65…
社区QA 测试平台 radiates
https://radiatest.openeuler.org
<
https://radiatest.openeuler.org/
> 车明道(openEuler release SIG) Mobile: +86 15345431107 中国(China)-杭州(Hangzhou)-滨江区江淑路360号华为杭州研发中心 HUAWEI , Jiangshu Road., Binjiang District, Hangzhou, P.R.China E-mail: chemingdao(a)huawei.com<mailto:chemingdao@huawei.com> [cid:image002.png@01D8E590.9E38BF00]Open Source OS for Digital Infrastructure 本邮件及其附件含有华为公司的保密信息,仅限于发送给上面地址中列出的个人或群组。禁止任何其他人以任何形 式使用(包括但不限于全部或部分地泄露、复制、或散发)本邮件中的信息。如果您错收了本邮件,请您立即电话 或邮件通知发件人并删除本邮件! This e-mail and its attachments contain confidential information from HUAWEI, which is intended only for the person or entity whose address is listed above. Any use of the information contained herein in any way (including, but not limited to, total or partial disclosure, reproduction, or dissemination) by persons other than the intended recipient(s) is prohibited. If you receive this e-mail in error, please notify the sender by phone or email immediately and delete it
1
0
0
0
dev-util SIG例会
by openEuler conference
17 Oct '22
17 Oct '22
您好! dev-utils SIG 邀请您参加 2022-10-17 16:00 召开的Zoom会议 会议主题:dev-util SIG例会 会议内容:
sysmaster(gitee.com/openeuler/sysmaster)项目使用Rust重新思考和实现1号进程。
会议链接:https://us06web.zoom.us/j/84908413285?pwd=NkNIK2tCWWpOdndqYnBVSnBJckowdz09
会议纪要:https://etherpad.openeuler.org/p/dev-utils-meetings
温馨提醒:建议接入会议后修改参会人的姓名,也可以使用您在gitee.com的ID
更多资讯尽在:https://openeuler.org/zh/
Hello! openEuler dev-utils SIG invites you to attend the Zoom conference will be held at 2022-10-17 16:00, The subject of the conference is dev-util SIG例会, Summary:
sysmaster(gitee.com/openeuler/sysmaster)项目使用Rust重新思考和实现1号进程。
You can join the meeting at
https://us06web.zoom.us/j/84908413285?pwd=NkNIK2tCWWpOdndqYnBVSnBJckowdz09
. Add topics at
https://etherpad.openeuler.org/p/dev-utils-meetings
. Note: You are advised to change the participant name after joining the conference or use your ID at
gitee.com
. More information:
https://openeuler.org/en/
1
0
0
0
openEuler update_20221012 版本发布公告
by chemingdao
15 Oct '22
15 Oct '22
Dear all, 经社区Release SIG、QA SIG及 CICD SIG 评估,openEuler-20.03-LTS-SP1、openEuler-20.03-LTS-SP3及openEuler-22.03-LTS update版本满足版本出口质量,现进行发布公示。 本公示分为五部分: 1、openEuler-20.03-LTS-SP1 Update 20221012发布情况及待修复缺陷 2、openEuler-20.03-LTS-SP3 Update 20221012 发布情况及待修复缺陷 3、openEuler-22.03-LTS Update 20221012发布情况及待修复缺陷 4、openEuler 关键组件待修复CVE 清单 5、openEuler 社区指导文档及开放平台链接 本次update版本发布后,下一个版本里程碑点(预计在2022/10/21)提供 update_20221017版本。 openEuler-20.03-LTS-SP1 Update 20221012 经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP1修复版本已知问题3个,已知漏洞24个。目前版本分支剩余待修复缺陷66个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库 openEuler-20.03-LTS-SP1 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I5UQZ2?from=project-i…
CVE修复: CVE 仓库 CVSS评分 CVE-2022-39842 kernel 7.8 CVE-2022-38178 bind 7.5 CVE-2022-38177 bind 7.5 CVE-2022-3352 vim 7.8 CVE-2022-3303 kernel 4.7 CVE-2022-3296 vim 7.8 CVE-2022-3172 kubernetes 5.1 CVE-2022-30767 uboot-tools 9.8 CVE-2022-2906 bind 7.5 CVE-2022-2881 bind 8.2 CVE-2022-2795 bind 7.5 CVE-2022-2663 kernel 5.3 CVE-2022-1184 kernel 5.5 CVE-2021-3638 qemu 6.5 CVE-2021-25220 dhcp 6.8 CVE-2021-25219 dhcp 5.3 CVE-2021-25215 dhcp 7.5 CVE-2021-25214 dhcp 6.5 CVE-2019-14584 edk2 7.8 CVE-2019-11098 edk2 6.8 CVE-2022-37797 lighttpd 7.5 CVE-2022-30550 dovecot 6.8 CVE-2022-21797 python-joblib 7.3 CVE-2022-3213 ImageMagick 5.5 Bugfix: issue 仓库 #I5TK7K:Submit yaml file into this repository: oec-hardware oec-hardware #I5TY3L:【openEuler-1.0-LTS】bd_link_disk_holder创建sysfs触发unable to handle page fault kernel #I5TTB0:net-snmp补丁回合,修复snmpd命令偶现core问题 net-snmp openEuler-20.03-LTS-SP1版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1:Epol
openEuler-20.03-LTS-SP1 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/EPOL/update/
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP1 Update版本待修复问题清单公示: 任务ID 任务标题 关联仓库 SIG I281C1 【fuzz】runtime error: libsass Base-service I437CR [SP1][arm/x86]obs-server包下11个服务启动关闭,出现报错 obs-server Others I43OSX [clamav] 执行clamscan --statistics pcre命令会出现error,但是最终返回码为0 clamav Others I44RHB large loop in OBJ_obj2txt openssl sig-security-facility I44RIX large loop in bn_lshift_fixed_top openssl sig-security-facility I47I56 yum升级出现dkms的错误告警打印 dkms Others I48GIM 【20.03LTS SP1 update 210901】ovirt-cockpit-sso.service服务启动失败 ovirt-cockpit-sso oVirt I490MU Uncaught exception in get_tokens_unprocessed python-pygments Programming-language I4CJX9 [20.03-LTS-SP1] 389-ds-base包下的部分命令-v参数不显示版本号 three-eight-nine-ds-base Application I4CM78 [20.03-LTS-SP1]389-ds-base和389-ds-base-legacy-tools包的部分命令执行返回No instances found in /etc/sysconfig three-eight-nine-ds-base Application I4F8YQ integer overflow in start_input_bmp libjpeg-turbo Desktop I4F8ZI heap-buffer-overflow in get_word_rgb_row libjpeg-turbo Desktop I4F903 Unexpect-exit in start_input_tga libjpeg-turbo Desktop I4F913 Timeout in tjDecompress2 libjpeg-turbo Desktop I4FRSL Undefined-shift in bitset_set augeas Desktop I4FT5J Timeout in fa_from_re augeas Desktop I4FT5U stack overflow in fa_from_re augeas Desktop I4FT61 stack overflow in re_case_expand augeas Desktop I4FT67 memleaks in ref_make_ref augeas Desktop I4FT6B SEGV in re_case_expand augeas Desktop I4FT6F stack overflow in parse_concat_exp augeas Desktop I4FT7B stack overflow in calc_eclosure_iter augeas Desktop I4FT8E stack overflow in peek_token augeas Desktop I4FT8P stack overflow in parse_path_expr augeas Desktop I4FT97 Out of memory in ns_from_locpath augeas Desktop I4FT9A SEGV in eval_expr augeas Desktop I4FT9C SEGV in tree_prev augeas Desktop I4FT9G stack overflow in check_expr augeas Desktop I4FT9I stack overflow in free_expr augeas Desktop I4G4A5 Undefine-shift in _bfd_safe_read_leb128 binutils Compiler I4G4B1 Integer overflow in print_vms_time binutils Compiler I4G4VY memleak in parse_gnu_debugaltlink binutils Compiler I4G4WF Heap-buffer-overflow in slurp_hppa_unwind_table binutils Compiler I4G4WW Use-after-free in make_qualified_name binutils Compiler I4G4X6 memleak in byte_get_little_endian binutils Compiler I4G4XF memleak in process_mips_specific binutils Compiler I4G4Y0 out-of-memory in vms_lib_read_index binutils Compiler I4G4YJ Heap-buffer-overflow in bfd_getl16 binutils Compiler I4G4YV Floating point exception in _bfd_vms_slurp_etir binutils Compiler I4G5TL stack-buffer-overflow in redisvFormatCommand hiredis Base-service I4G5U2 AddressSanitizer CHECK failed in sdscatvprintf hiredis Base-service I4G5UN SEGV in redisvFormatCommand hiredis Base-service I4G5WG AddressSanitizer CHECK failed in sdscatlen hiredis Base-service I4G5XO Attempting free wild-addr in hi_free hiredis Base-service I4J0OY 【20.03 SP1】【arm/x86】安装好libdap后,getdap4命令的-i和-k参数使用异常 libdap sig-recycle I4JMG4 【20.03 SP1】【arm/x86】robotframework包的三个命令:libdoc、rebot、robot执行--help/-h/-?/--version,查看帮助信息和版本信息,返回值为251 python-robotframework sig-ROS I4K6ES stack-buffer-overflow in UINT32_Marshal libtpms sig-security-facility I4K6FU global-buffer-overflow in Array_Marshal libtpms sig-security-facility I4K6R7 memleak in wrap_nettle_mpi_init gnutls sig-security-facility I4K6UI Timeout in _asn1_find_up gnutls sig-security-facility I4KT2A integer overflow in luaV_execute lua Base-service I4KT3D integer overflow in intarith lua Base-service I4KT3Q Division by zero in luaV_execute lua Base-service I4KT40 Timeout in luaV_finishget lua Base-service I4NNTR [SP1][x86/arm]执行isula pull busybox,报错"fetch and parse manifest failed" iSulad iSulad I4NO1Z 【SP1-arm/x86】openhpi升级有报错信息 openhpi System-tool I4O16Z 【SP1_update/arm】安装kernel-4.19.90-2108版本有错误提示信息 kernel Kernel I4QV6N 【openEuler-20.03-LTS-SP1】flink命令执行失败 flink sig-bigdata I5G81X 【20.03 SP1】selinux-policy卸载异常 selinux-policy sig-security-facility I5GT2K 【20.03-SP1】【arm/x86】pcp-system-tools包下的pcp-mpstat命令执行报错 pcp Application I5IG1V 【20.03-SP1】【x86/arm】epol源下的efl、efl-devel软件包安装报错,gpg检查失败 efl sig-compat-winapp I5IG6K 【20.03-SP1】【x86/arm】epol源下的opencryptoki、opencryptoki-devel软件包安装报错,gpg检查失败 opencryptoki dev-utils I5JHX2 【20.03 SP1 update 20220727】ovirt-engine在update 20220727版本安装失败 ovirt-engine oVirt I5JNSL 【20.03 SP1 update 20220727】【arm】htcacheclean.service服务启动之后,日志中提示”Can't open PID file /run/httpd/htcacheclean/pid“ httpd Networking I5O40D 【20.03 SP1】linux-sgx-driver在20.03 SP1分支安装有异常告警 linux-sgx-driver sig-confidential-computing I5Q5D1 【20.03 SP1】ibus在sp1分支安装有异常告警 ibus Desktop openEuler-20.03-LTS-SP3 Update 20221012 经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP3修复版本已知问题10个,已知漏洞24个。目前版本分支剩余待修复缺陷15个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库 openEuler-20.03-LTS-SP3 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I5UQZ3?from=project-i…
CVE修复: 需求类型 软件包 CVSS评分 CVE-2022-39842 kernel 7.8 CVE-2022-38178 bind 7.5 CVE-2022-38177 bind 7.5 CVE-2022-3352 vim 7.8 CVE-2022-3303 kernel 4.7 CVE-2022-3296 vim 7.8 CVE-2022-3172 kubernetes 5.1 CVE-2022-30767 uboot-tools 9.8 CVE-2022-2906 bind 7.5 CVE-2022-2881 bind 8.2 CVE-2022-2795 bind 7.5 CVE-2022-2663 kernel 5.3 CVE-2022-1184 kernel 5.5 CVE-2021-3638 qemu 6.5 CVE-2021-25220 dhcp 6.8 CVE-2021-25219 dhcp 5.3 CVE-2021-25215 dhcp 7.5 CVE-2021-25214 dhcp 6.5 CVE-2019-14584 edk2 7.8 CVE-2019-11098 edk2 6.8 CVE-2022-37797 lighttpd 7.5 CVE-2022-30550 dovecot 6.8 CVE-2022-21797 python-joblib 7.3 CVE-2022-3213 ImageMagick 5.5 Bugfix: issue 仓库 #I5P7EI:【openEuler-22.09-RC3】【arm/x86】lxc 软件包 "-?" 参数执行返回"invalid option" lxc #I5S705:设置rootfs maskedpath与设置rootfs ro顺序错误 lxc #I5UTFY:告警处理 lcr #I5PY6W:isula 启动容器内执行env,缺少HOSTNAME变量,且直接获取HOSTNAME变量均为localhost iSulad #I5TIEF:isulad使用devicemapper,磁盘处理较慢时可能出现踩内存 iSulad #I5TK7K:Submit yaml file into this repository: oec-hardware oec-hardware #I5TY3L:【openEuler-1.0-LTS】bd_link_disk_holder创建sysfs触发unable to handle page fault kernel #I5TTB0:net-snmp补丁回合,修复snmpd命令偶现core问题 net-snmp #I5VEOW:20.03 spc3 abseil-cpp安装后,缺少absl_dynamic_annotations库 grpc #I5VEOZ:openeuler 20.03 sp3 aarch64 使用pcs控制HA集群,服务无法自动漂移问题 pacemaker openEuler-20.03-LTS-SP3版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3:Epol
openEuler-20.03-LTS-SP3 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/EPOL/update/main/
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP3 Update版本待修复问题清单公示: 任务ID 任务标题 关联仓库 SIG I4QV7S 【openEuler-20.03-LTS-SP3】flink run 命令执行失败 flink sig-bigdata I4RVHE losetup : 当loop设备编号超过7位时,losetup命令无法操作该设备 util-linux Base-service I4UMEV [openEuler 20.03-LTS SP3]openEuler开启crash_kexec_post_notifiers后,panic通知链无法完全遍历 openEuler/kernel Kernel I5IGAS 【20.03-SP3】【x86/arm】epol源下的opencryptoki、opencryptoki-devel软件包安装报错,gpg检查失败 opencryptoki dev-utils I5IGOR 【20.03-SP3】【x86/arm】epol源下的fluidsynth、fluidsynth-devel、fluidsynth-help软件包安装报错,gpg检查失败 fluidsynth Application I5JBJ9 【20.03 SP3_EPOL_update20220727】ovirt-engine-backend包卸载过程的告警信息需要优化 ovirt-engine oVirt I5JLNF 【20.03 SP3 update 20220727】【arm/x86】ovirt-websocket-proxy.service服务启动失败 ovirt-engine oVirt I5JLRQ 【20.03 SP3 update 20220727】【arm/x86】ovirt-engine-notifier.service服务启动失败 ovirt-engine oVirt I5KXUY 【20.03 LTS SP3 update 20220803】【arm/x86】ovirt-cockpit-sso.service服务启动失败 ovirt-cockpit-sso oVirt I5KY4S 【20.03 LTS SP3 update 20220803】【arm/x86】vdsmd.service服务启动失败,导致mom-vdsm.service服务无法启动成功 vdsm oVirt I5LYJK 【20.03-sp3_update20220801】【x86】对内核版进行升级后,TCP_option_address安装异常 TCP_option_address Kernel I5PT12 [20.03-LTS-SP3]spec文件存在软件包编译依赖自身,且打包包含系统环境文件 ima-evm-utils Base-service I5PUIA [20.03-LTS-SP3]spec文件存在软件包编译依赖自身,且打包包含系统环境文件 qrencode Desktop I5RHBG 【20.03_SP3】【arm/x86】iSulad降级时依赖包未同步降级,导致依赖包版本不匹配出现报错 iSulad iSulad I5SCLC 【20.03 SP3】selinux-policy卸载异常 selinux-policy sig-security-facility openEuler-22.03-LTS Update 20221012 经各SIG及社区开发者贡献,本周openEuler-22.03-LTS修复版本已知问题12个,已知漏洞23个。目前版本分支剩余待修复缺陷10个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库 openEuler-22.03-LTS Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I5UQZ4?from=project-i…
CVE修复: CVE 仓库 CVSS评分 CVE-2022-3296 vim 7.8 CVE-2022-3352 vim 7.8 CVE-2022-30767 uboot-tools 9.8 CVE-2021-3638 qemu 6.5 CVE-2022-2962 qemu 7.8 CVE-2022-3172 kubernetes 5.1 CVE-2022-3239 kernel 7.8 CVE-2019-11098 edk2 6.8 CVE-2021-25214 dhcp 6.5 CVE-2021-25215 dhcp 7.5 CVE-2021-25219 dhcp 5.3 CVE-2021-25220 dhcp 6.8 CVE-2022-2795 bind 7.5 CVE-2022-2881 bind 8.2 CVE-2022-2906 bind 7.5 CVE-2022-3080 bind 7.5 CVE-2022-38177 bind 7.5 CVE-2022-38178 bind 7.5 CVE-2022-3190 wireshark 5.5 CVE-2022-21797 python-joblib 7.3 CVE-2022-37797 lighttpd 7.5 CVE-2022-30550 dovecot 6.8 CVE-2022-3213 ImageMagick 5.5 Bugfix: issue 仓库 #I5PY6W:isula 启动容器内执行env,缺少HOSTNAME变量,且直接获取HOSTNAME变量均为localhost iSulad #I5TIEF:isulad使用devicemapper,磁盘处理较慢时可能出现踩内存 iSulad #I5U7EU:优化prep处理逻辑,将libtoolize以及autoreconf移到build中 pcre #I5TK7K:Submit yaml file into this repository: oec-hardware oec-hardware #I5MGRL:[22.09 LTS][Train][Wallaby]openstack-dashboard默认使用/usr/bin/python,导致httpd无法启动 openstack-horizon #I5UYZK:优化prep处理逻辑,将tzdataxxxx-rearguard.tar.gz文件内容的生成移到build中 tzdata #I5TTB0:net-snmp补丁回合,修复snmpd命令偶现core问题 net-snmp #I5DZV6:255个cpu的虚拟机,触发softlockup复位后vmcore-dmesg日志未能生成 kexec-tools #I5AN49: 升级到openEuler-22.03-LTS,kdump服务异常,错误提示存在非法参数kbox_mem kexec-tools #I5U64B:优化kexec-tools的patch,将ARM场景的宏开关移到代码中 kexec-tools #I5KIZ2:rsyslog上游社区补丁回合并使能%check rsyslog #I5TP3M:rsyslog的prep中移除文档的build操作 rsyslog openEuler-22.03-LTS版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:22.03:LTS
https://build.openeuler.org/project/show/openEuler:22.03:LTS:Epol
openEuler-22.03-LTS Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS/update/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
openEuler-22.03-LTS Update版本待修复问题清单公示: 任务ID 任务标题 关联仓库 SIG I5G9CY 升级iinstall-scripts包会导致系统启动异常 install-scripts sig-OS-Builder I5JIA6 【22.03 LTS update 20220727】ovirt-engine在update 20220727版本安装失败 ovirt-engine oVirt I5JPII 【22.03_update20220727】【x86/arm】ovirt-engine源码包本地自编译失败,缺少编译依赖ovirt-jboss-modules-maven-plugin ovirt-engine oVirt I5LKKX libbluray build problem in openEuler:22.03:LTS libbluray Desktop I5LKM6 libxshmfence build problem in openEuler:22.03:LTS libxshmfence Desktop I5LKY8 yaffs2 build problem in openEuler:22.03:LTS yaffs2 sig-embedded I5QKGT 【22.03LTS_update0907】【arm/x86】kmod-drbd90软件包安装之后文件有缺失 kmod-drbd90 sig-Ha I5RHYO 【22.09 RC4】【arm/x86】package.ini中的redis_host配置为不存在的ip,重启pkgship服务失败,服务一直在尝试重启 pkgship sig-EasyLife I5TM41 [22.03-LTS]先安装mariadb-server,卸载后再安装mysql-server,mysqld服务启动失败 mysql Others I5TMFF [22.03-LTS]先安装mysql-server,卸载后再安装mariadb-server,mariadb服务启动失败 mariadb DB 社区待修复漏洞: openEuler社区根据漏洞严重等级采取差异化的修复策略,请各个SIG 关注涉及CVE组件的修复情况。 严重等级(Severity Rating) 漏洞修复时长 致命(Critical) 7天 高(High) 14天 中(Medium) 30天 低(Low) 30天
可参考社区安全委员会漏洞:https://gitee.com/openeuler/security-committee/wikis/%E7%A4%BE…
近14天将超期CVE: 漏洞编号 Issue ID 剩余天数 CVSS评分 软件包 责任SIG CVE-2022-40626 I5R4GB 0.17 4 zabbix Base-service CVE-2022-21222 I5U305 0.44 7.5 pcs sig-Ha CVE-2022-40476 I5R4K9 0.45 5.5 risc-v-kernel sig-RISC-V CVE-2021-4127 I5R6GY 0.58 thunderbird sig-desktop-apps CVE-2022-36402 I5RJWC 2.21 5.5 risc-v-kernel sig-RISC-V CVE-2022-34169 I5HV9H 4.37 7.5 openjdk-1.8.0 Compiler CVE-2022-42004 I5U706 4.56 7.5 jackson-databind sig-Java CVE-2022-20421 I5U713 4.57 7.8 kernel Kernel CVE-2022-42003 I5U709 4.57 7.5 jackson-databind sig-Java CVE-2022-20422 I5U71M 4.58 7 kernel Kernel CVE-2022-2928 I5U80N 5.08 7.5 dhcp Networking CVE-2021-34337 I5S654 6.37 mailman Application CVE-2022-23084 I5S79U 6.55 risc-v-kernel sig-RISC-V CVE-2022-23086 I5S7L9 6.56 risc-v-kernel sig-RISC-V CVE-2022-23085 I5S7KN 6.56 risc-v-kernel sig-RISC-V CVE-2022-34305 I5SD31 6.86 6.1 tomcat Application CVE-2022-41218 I5SDEB 6.87 5.5 risc-v-kernel sig-RISC-V CVE-2022-3171 I5UBLT 6.96 7.5 protobuf sig-CloudNative CVE-2022-31008 I5UBQ6 7 7.5 rabbitmq-server Application CVE-2022-35957 I5SELV 7.08 6.6 grafana Application CVE-2022-36062 I5SELR 7.08 3.8 grafana Application CVE-2022-3155 I5SELN 7.08 CVE-2022-3297 I5T0SC 7.12 7.8 vim Base-service CVE-2022-1941 I5SV4T 7.12 7.5 protobuf sig-CloudNative CVE-2022-3277 I5SNDX 8.45 openstack-neutron sig-openstack CVE-2022-2785 I5SVBG 9 5.5 risc-v-kernel sig-RISC-V CVE-2022-2785 I5SVBF 9 5.5 kernel Kernel CVE-2022-21824 I5USM1 9.57 8.2 mysql Others CVE-2022-3303 I5T9C4 12.2 4.7 risc-v-kernel sig-RISC-V CVE-2022-3303 I5T9C3 12.2 4.7 kernel Kernel CVE-2022-39282 I5VGTX 12.58 7.5 freerdp Application CVE-2022-39283 I5VGTP 12.58 7.5 freerdp Application CVE-2021-3481 I5TEAF 12.78 5.4 qt5 Desktop CVE-2022-41083 I5VK2C 12.8 7.8 jupyter sig-bigdata CVE-2022-3078 I5TEMI 12.8 5.5 risc-v-kernel sig-RISC-V CVE-2020-10136 I5TF8O 12.83 5.3 kernel Kernel CVE-2019-2101 I5TF8C 12.83 5.5 kernel Kernel CVE-2022-21233 I5TF80 12.83 5.5 risc-v-kernel sig-RISC-V CVE-2020-26143 I5TGQO 12.94 6.5 kernel Kernel CVE-2020-26140 I5TGQL 12.94 6.5 kernel Kernel CVE-2022-39835 I5THMV 13.35 5.3 gajim sig-mate-desktop CVE-2022-35255 I5TOU4 13.95 nodejs sig-nodejs CVE-2022-35256 I5TOU1 13.95 CVE-2021-27854 I5TP92 14.05 4.7 risc-v-kernel sig-RISC-V CVE-2021-27854 I5TP8Z 14.05 4.7 kernel Kernel CVE-2021-27861 I5TPBD 14.06 4.7 risc-v-kernel sig-RISC-V CVE-2021-27861 I5TPB2 14.06 4.7 kernel Kernel CVE-2022-3287 I5TPE8 14.07 6.5 fwupd System-tool CVE-2021-27853 I5TPCA 14.07 4.7 risc-v-kernel sig-RISC-V CVE-2021-27853 I5TPC2 14.07 4.7 kernel Kernel CVE-2021-27862 I5TPEG 14.08 CVE-2022-31629 I5TPJZ 14.46 6.5 php Base-service CVE-2021-43980 I5TQD3 14.53 5.3 tomcat Application CVE-2022-31628 I5TRIM 14.58 5.5 php Base-service CVE-2022-31628 I5TSDJ 14.62 5.5 php Base-service CVE-2022-1520 I5TUGK 14.79 thunderbird sig-desktop-apps CVE-2022-2805 I5TUGD 14.79 ovirt-engine oVirt CVE-2022-1736 I5TUG3 14.79 gnome-remote-desktop GNOME CVE-2022-28289 I5TUET 14.79 firefox Application CVE-2022-3306 I5TUZS 14.82 chromium Application CVE-2022-1834 I5TUWK 14.82 thunderbird sig-desktop-apps openEuler 社区指导文档及开放平台链接: openEuler 版本分支维护规范:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E7%89%…
openEuler release-management 版本分支PR指导:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E5%BC%…
社区QA 版本测试提单规范
https://gitee.com/openeuler/QA/blob/839f952696f271f83c018ccf3218cf493b92d65…
社区QA 测试平台 radiates
https://radiatest.openeuler.org
<
https://radiatest.openeuler.org/
> 车明道(openEuler release SIG) Mobile: +86 15345431107 中国(China)-杭州(Hangzhou)-滨江区江淑路360号华为杭州研发中心 HUAWEI , Jiangshu Road., Binjiang District, Hangzhou, P.R.China E-mail: chemingdao(a)huawei.com<mailto:chemingdao@huawei.com> [cid:image002.png@01D8E0A5.3FDFB200]Open Source OS for Digital Infrastructure 本邮件及其附件含有华为公司的保密信息,仅限于发送给上面地址中列出的个人或群组。禁止任何其他人以任何形 式使用(包括但不限于全部或部分地泄露、复制、或散发)本邮件中的信息。如果您错收了本邮件,请您立即电话 或邮件通知发件人并删除本邮件! This e-mail and its attachments contain confidential information from HUAWEI, which is intended only for the person or entity whose address is listed above. Any use of the information contained herein in any way (including, but not limited to, total or partial disclosure, reproduction, or dissemination) by persons other than the intended recipient(s) is prohibited. If you receive this e-mail in error, please notify the sender by phone or email immediately and delete it
1
0
0
0
撤回: openEuler update_20221012 版本发布公告
by chemingdao
15 Oct '22
15 Oct '22
chemingdao 将撤回邮件“openEuler update_20221012 版本发布公告”。
1
0
0
0
撤回: openEuler update_20221012 版本发布公告
by chemingdao
15 Oct '22
15 Oct '22
chemingdao 将撤回邮件“openEuler update_20221012 版本发布公告”。
1
0
0
0
openEuler update_20221012 版本发布公告
by chemingdao
14 Oct '22
14 Oct '22
Dear all, 经社区Release SIG、QA SIG及 CICD SIG 评估,openEuler-20.03-LTS-SP1、openEuler-20.03-LTS-SP3及openEuler-22.03-LTS update版本满足版本出口质量,现进行发布公示。 本公示分为五部分: 1、openEuler-20.03-LTS-SP1 Update 20221012发布情况及待修复缺陷 2、openEuler-20.03-LTS-SP3 Update 20221012 发布情况及待修复缺陷 3、openEuler-22.03-LTS Update 20221012发布情况及待修复缺陷 4、openEuler 关键组件待修复CVE 清单 5、openEuler 社区指导文档及开放平台链接 本次update版本发布后,下一个版本里程碑点(预计在2022/10/21)提供 update_20221017版本。 openEuler-20.03-LTS-SP1 Update 20221012 经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP1修复版本已知问题3个,已知漏洞24个。目前版本分支剩余待修复缺陷66个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库 openEuler-20.03-LTS-SP1 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I5UQZ2?from=project-i…
CVE修复: CVE 仓库 CVSS评分 CVE-2022-39842 kernel 7.8 CVE-2022-38178 bind 7.5 CVE-2022-38177 bind 7.5 CVE-2022-3352 vim 7.8 CVE-2022-3303 kernel 4.7 CVE-2022-3296 vim 7.8 CVE-2022-3172 kubernetes 5.1 CVE-2022-30767 uboot-tools 9.8 CVE-2022-2906 bind 7.5 CVE-2022-2881 bind 8.2 CVE-2022-2795 bind 7.5 CVE-2022-2663 kernel 5.3 CVE-2022-1184 kernel 5.5 CVE-2021-3638 qemu 6.5 CVE-2021-25220 dhcp 6.8 CVE-2021-25219 dhcp 5.3 CVE-2021-25215 dhcp 7.5 CVE-2021-25214 dhcp 6.5 CVE-2019-14584 edk2 7.8 CVE-2019-11098 edk2 6.8 CVE-2022-37797 lighttpd 7.5 CVE-2022-30550 dovecot 6.8 CVE-2022-21797 python-joblib 7.3 CVE-2022-3213 ImageMagick 5.5 Bugfix: issue 仓库 责任田 #I5TK7K:Submit yaml file into this repository: oec-hardware oec-hardware openEuler #I5TY3L:【openEuler-1.0-LTS】bd_link_disk_holder创建sysfs触发unable to handle page fault kernel EulerOS #I5TTB0:net-snmp补丁回合,修复snmpd命令偶现core问题 net-snmp EulerOS openEuler-20.03-LTS-SP1版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1:Epol
openEuler-20.03-LTS-SP1 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/EPOL/update/
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP1 Update版本待修复问题清单公示: 任务ID 任务标题 关联仓库 SIG I281C1 【fuzz】runtime error: libsass Base-service I437CR [SP1][arm/x86]obs-server包下11个服务启动关闭,出现报错 obs-server Others I43OSX [clamav] 执行clamscan --statistics pcre命令会出现error,但是最终返回码为0 clamav Others I44RHB large loop in OBJ_obj2txt openssl sig-security-facility I44RIX large loop in bn_lshift_fixed_top openssl sig-security-facility I47I56 yum升级出现dkms的错误告警打印 dkms Others I48GIM 【20.03LTS SP1 update 210901】ovirt-cockpit-sso.service服务启动失败 ovirt-cockpit-sso oVirt I490MU Uncaught exception in get_tokens_unprocessed python-pygments Programming-language I4CJX9 [20.03-LTS-SP1] 389-ds-base包下的部分命令-v参数不显示版本号 three-eight-nine-ds-base Application I4CM78 [20.03-LTS-SP1]389-ds-base和389-ds-base-legacy-tools包的部分命令执行返回No instances found in /etc/sysconfig three-eight-nine-ds-base Application I4F8YQ integer overflow in start_input_bmp libjpeg-turbo Desktop I4F8ZI heap-buffer-overflow in get_word_rgb_row libjpeg-turbo Desktop I4F903 Unexpect-exit in start_input_tga libjpeg-turbo Desktop I4F913 Timeout in tjDecompress2 libjpeg-turbo Desktop I4FRSL Undefined-shift in bitset_set augeas Desktop I4FT5J Timeout in fa_from_re augeas Desktop I4FT5U stack overflow in fa_from_re augeas Desktop I4FT61 stack overflow in re_case_expand augeas Desktop I4FT67 memleaks in ref_make_ref augeas Desktop I4FT6B SEGV in re_case_expand augeas Desktop I4FT6F stack overflow in parse_concat_exp augeas Desktop I4FT7B stack overflow in calc_eclosure_iter augeas Desktop I4FT8E stack overflow in peek_token augeas Desktop I4FT8P stack overflow in parse_path_expr augeas Desktop I4FT97 Out of memory in ns_from_locpath augeas Desktop I4FT9A SEGV in eval_expr augeas Desktop I4FT9C SEGV in tree_prev augeas Desktop I4FT9G stack overflow in check_expr augeas Desktop I4FT9I stack overflow in free_expr augeas Desktop I4G4A5 Undefine-shift in _bfd_safe_read_leb128 binutils Compiler I4G4B1 Integer overflow in print_vms_time binutils Compiler I4G4VY memleak in parse_gnu_debugaltlink binutils Compiler I4G4WF Heap-buffer-overflow in slurp_hppa_unwind_table binutils Compiler I4G4WW Use-after-free in make_qualified_name binutils Compiler I4G4X6 memleak in byte_get_little_endian binutils Compiler I4G4XF memleak in process_mips_specific binutils Compiler I4G4Y0 out-of-memory in vms_lib_read_index binutils Compiler I4G4YJ Heap-buffer-overflow in bfd_getl16 binutils Compiler I4G4YV Floating point exception in _bfd_vms_slurp_etir binutils Compiler I4G5TL stack-buffer-overflow in redisvFormatCommand hiredis Base-service I4G5U2 AddressSanitizer CHECK failed in sdscatvprintf hiredis Base-service I4G5UN SEGV in redisvFormatCommand hiredis Base-service I4G5WG AddressSanitizer CHECK failed in sdscatlen hiredis Base-service I4G5XO Attempting free wild-addr in hi_free hiredis Base-service I4J0OY 【20.03 SP1】【arm/x86】安装好libdap后,getdap4命令的-i和-k参数使用异常 libdap sig-recycle I4JMG4 【20.03 SP1】【arm/x86】robotframework包的三个命令:libdoc、rebot、robot执行--help/-h/-?/--version,查看帮助信息和版本信息,返回值为251 python-robotframework sig-ROS I4K6ES stack-buffer-overflow in UINT32_Marshal libtpms sig-security-facility I4K6FU global-buffer-overflow in Array_Marshal libtpms sig-security-facility I4K6R7 memleak in wrap_nettle_mpi_init gnutls sig-security-facility I4K6UI Timeout in _asn1_find_up gnutls sig-security-facility I4KT2A integer overflow in luaV_execute lua Base-service I4KT3D integer overflow in intarith lua Base-service I4KT3Q Division by zero in luaV_execute lua Base-service I4KT40 Timeout in luaV_finishget lua Base-service I4NNTR [SP1][x86/arm]执行isula pull busybox,报错"fetch and parse manifest failed" iSulad iSulad I4NO1Z 【SP1-arm/x86】openhpi升级有报错信息 openhpi System-tool I4O16Z 【SP1_update/arm】安装kernel-4.19.90-2108版本有错误提示信息 kernel Kernel I4QV6N 【openEuler-20.03-LTS-SP1】flink命令执行失败 flink sig-bigdata I5G81X 【20.03 SP1】selinux-policy卸载异常 selinux-policy sig-security-facility I5GT2K 【20.03-SP1】【arm/x86】pcp-system-tools包下的pcp-mpstat命令执行报错 pcp Application I5IG1V 【20.03-SP1】【x86/arm】epol源下的efl、efl-devel软件包安装报错,gpg检查失败 efl sig-compat-winapp I5IG6K 【20.03-SP1】【x86/arm】epol源下的opencryptoki、opencryptoki-devel软件包安装报错,gpg检查失败 opencryptoki dev-utils I5JHX2 【20.03 SP1 update 20220727】ovirt-engine在update 20220727版本安装失败 ovirt-engine oVirt I5JNSL 【20.03 SP1 update 20220727】【arm】htcacheclean.service服务启动之后,日志中提示”Can't open PID file /run/httpd/htcacheclean/pid“ httpd Networking I5O40D 【20.03 SP1】linux-sgx-driver在20.03 SP1分支安装有异常告警 linux-sgx-driver sig-confidential-computing I5Q5D1 【20.03 SP1】ibus在sp1分支安装有异常告警 ibus Desktop openEuler-20.03-LTS-SP3 Update 20221012 经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP3修复版本已知问题10个,已知漏洞24个。目前版本分支剩余待修复缺陷15个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库 openEuler-20.03-LTS-SP3 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I5UQZ3?from=project-i…
CVE修复: 需求类型 软件包 CVSS评分 CVE-2022-39842 kernel 7.8 CVE-2022-38178 bind 7.5 CVE-2022-38177 bind 7.5 CVE-2022-3352 vim 7.8 CVE-2022-3303 kernel 4.7 CVE-2022-3296 vim 7.8 CVE-2022-3172 kubernetes 5.1 CVE-2022-30767 uboot-tools 9.8 CVE-2022-2906 bind 7.5 CVE-2022-2881 bind 8.2 CVE-2022-2795 bind 7.5 CVE-2022-2663 kernel 5.3 CVE-2022-1184 kernel 5.5 CVE-2021-3638 qemu 6.5 CVE-2021-25220 dhcp 6.8 CVE-2021-25219 dhcp 5.3 CVE-2021-25215 dhcp 7.5 CVE-2021-25214 dhcp 6.5 CVE-2019-14584 edk2 7.8 CVE-2019-11098 edk2 6.8 CVE-2022-37797 lighttpd 7.5 CVE-2022-30550 dovecot 6.8 CVE-2022-21797 python-joblib 7.3 CVE-2022-3213 ImageMagick 5.5 Bugfix: issue 仓库 #I5P7EI:【openEuler-22.09-RC3】【arm/x86】lxc 软件包 "-?" 参数执行返回"invalid option" lxc #I5S705:设置rootfs maskedpath与设置rootfs ro顺序错误 lxc #I5UTFY:告警处理 lcr #I5PY6W:isula 启动容器内执行env,缺少HOSTNAME变量,且直接获取HOSTNAME变量均为localhost iSulad #I5TIEF:isulad使用devicemapper,磁盘处理较慢时可能出现踩内存 iSulad #I5TK7K:Submit yaml file into this repository: oec-hardware oec-hardware #I5TY3L:【openEuler-1.0-LTS】bd_link_disk_holder创建sysfs触发unable to handle page fault kernel #I5TTB0:net-snmp补丁回合,修复snmpd命令偶现core问题 net-snmp #I5VEOW:20.03 spc3 abseil-cpp安装后,缺少absl_dynamic_annotations库 grpc #I5VEOZ:openeuler 20.03 sp3 aarch64 使用pcs控制HA集群,服务无法自动漂移问题 pacemaker openEuler-20.03-LTS-SP3版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3:Epol
openEuler-20.03-LTS-SP3 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/EPOL/update/main/
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP3 Update版本待修复问题清单公示: 任务ID 任务标题 关联仓库 SIG I4QV7S 【openEuler-20.03-LTS-SP3】flink run 命令执行失败 flink sig-bigdata I4RVHE losetup : 当loop设备编号超过7位时,losetup命令无法操作该设备 util-linux Base-service I4UMEV [openEuler 20.03-LTS SP3]openEuler开启crash_kexec_post_notifiers后,panic通知链无法完全遍历 openEuler/kernel Kernel I5IGAS 【20.03-SP3】【x86/arm】epol源下的opencryptoki、opencryptoki-devel软件包安装报错,gpg检查失败 opencryptoki dev-utils I5IGOR 【20.03-SP3】【x86/arm】epol源下的fluidsynth、fluidsynth-devel、fluidsynth-help软件包安装报错,gpg检查失败 fluidsynth Application I5JBJ9 【20.03 SP3_EPOL_update20220727】ovirt-engine-backend包卸载过程的告警信息需要优化 ovirt-engine oVirt I5JLNF 【20.03 SP3 update 20220727】【arm/x86】ovirt-websocket-proxy.service服务启动失败 ovirt-engine oVirt I5JLRQ 【20.03 SP3 update 20220727】【arm/x86】ovirt-engine-notifier.service服务启动失败 ovirt-engine oVirt I5KXUY 【20.03 LTS SP3 update 20220803】【arm/x86】ovirt-cockpit-sso.service服务启动失败 ovirt-cockpit-sso oVirt I5KY4S 【20.03 LTS SP3 update 20220803】【arm/x86】vdsmd.service服务启动失败,导致mom-vdsm.service服务无法启动成功 vdsm oVirt I5LYJK 【20.03-sp3_update20220801】【x86】对内核版进行升级后,TCP_option_address安装异常 TCP_option_address Kernel I5PT12 [20.03-LTS-SP3]spec文件存在软件包编译依赖自身,且打包包含系统环境文件 ima-evm-utils Base-service I5PUIA [20.03-LTS-SP3]spec文件存在软件包编译依赖自身,且打包包含系统环境文件 qrencode Desktop I5RHBG 【20.03_SP3】【arm/x86】iSulad降级时依赖包未同步降级,导致依赖包版本不匹配出现报错 iSulad iSulad I5SCLC 【20.03 SP3】selinux-policy卸载异常 selinux-policy sig-security-facility openEuler-22.03-LTS Update 20221012 经各SIG及社区开发者贡献,本周openEuler-22.03-LTS修复版本已知问题12个,已知漏洞23个。目前版本分支剩余待修复缺陷10个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库 openEuler-22.03-LTS Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I5UQZ4?from=project-i…
CVE修复: CVE 仓库 CVSS评分 CVE-2022-3296 vim 7.8 CVE-2022-3352 vim 7.8 CVE-2022-30767 uboot-tools 9.8 CVE-2021-3638 qemu 6.5 CVE-2022-2962 qemu 7.8 CVE-2022-3172 kubernetes 5.1 CVE-2022-3239 kernel 7.8 CVE-2019-11098 edk2 6.8 CVE-2021-25214 dhcp 6.5 CVE-2021-25215 dhcp 7.5 CVE-2021-25219 dhcp 5.3 CVE-2021-25220 dhcp 6.8 CVE-2022-2795 bind 7.5 CVE-2022-2881 bind 8.2 CVE-2022-2906 bind 7.5 CVE-2022-3080 bind 7.5 CVE-2022-38177 bind 7.5 CVE-2022-38178 bind 7.5 CVE-2022-3190 wireshark 5.5 CVE-2022-21797 python-joblib 7.3 CVE-2022-37797 lighttpd 7.5 CVE-2022-30550 dovecot 6.8 CVE-2022-3213 ImageMagick 5.5 Bugfix: issue 仓库 #I5PY6W:isula 启动容器内执行env,缺少HOSTNAME变量,且直接获取HOSTNAME变量均为localhost iSulad #I5TIEF:isulad使用devicemapper,磁盘处理较慢时可能出现踩内存 iSulad #I5U7EU:优化prep处理逻辑,将libtoolize以及autoreconf移到build中 pcre #I5TK7K:Submit yaml file into this repository: oec-hardware oec-hardware #I5MGRL:[22.09 LTS][Train][Wallaby]openstack-dashboard默认使用/usr/bin/python,导致httpd无法启动 openstack-horizon #I5UYZK:优化prep处理逻辑,将tzdataxxxx-rearguard.tar.gz文件内容的生成移到build中 tzdata #I5TTB0:net-snmp补丁回合,修复snmpd命令偶现core问题 net-snmp #I5DZV6:255个cpu的虚拟机,触发softlockup复位后vmcore-dmesg日志未能生成 kexec-tools #I5AN49: 升级到openEuler-22.03-LTS,kdump服务异常,错误提示存在非法参数kbox_mem kexec-tools #I5U64B:优化kexec-tools的patch,将ARM场景的宏开关移到代码中 kexec-tools #I5KIZ2:rsyslog上游社区补丁回合并使能%check rsyslog #I5TP3M:rsyslog的prep中移除文档的build操作 rsyslog openEuler-22.03-LTS版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:22.03:LTS
https://build.openeuler.org/project/show/openEuler:22.03:LTS:Epol
openEuler-22.03-LTS Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS/update/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
openEuler-22.03-LTS Update版本待修复问题清单公示: 任务ID 任务标题 关联仓库 SIG I5G9CY 升级iinstall-scripts包会导致系统启动异常 install-scripts sig-OS-Builder I5JIA6 【22.03 LTS update 20220727】ovirt-engine在update 20220727版本安装失败 ovirt-engine oVirt I5JPII 【22.03_update20220727】【x86/arm】ovirt-engine源码包本地自编译失败,缺少编译依赖ovirt-jboss-modules-maven-plugin ovirt-engine oVirt I5LKKX libbluray build problem in openEuler:22.03:LTS libbluray Desktop I5LKM6 libxshmfence build problem in openEuler:22.03:LTS libxshmfence Desktop I5LKY8 yaffs2 build problem in openEuler:22.03:LTS yaffs2 sig-embedded I5QKGT 【22.03LTS_update0907】【arm/x86】kmod-drbd90软件包安装之后文件有缺失 kmod-drbd90 sig-Ha I5RHYO 【22.09 RC4】【arm/x86】package.ini中的redis_host配置为不存在的ip,重启pkgship服务失败,服务一直在尝试重启 pkgship sig-EasyLife I5TM41 [22.03-LTS]先安装mariadb-server,卸载后再安装mysql-server,mysqld服务启动失败 mysql Others I5TMFF [22.03-LTS]先安装mysql-server,卸载后再安装mariadb-server,mariadb服务启动失败 mariadb DB 社区待修复漏洞: openEuler社区根据漏洞严重等级采取差异化的修复策略,请各个SIG 关注涉及CVE组件的修复情况。 严重等级(Severity Rating) 漏洞修复时长 致命(Critical) 7天 高(High) 14天 中(Medium) 30天 低(Low) 30天
可参考社区安全委员会漏洞:https://gitee.com/openeuler/security-committee/wikis/%E7%A4%BE…
近14天将超期CVE: 漏洞编号 Issue ID 剩余天数 CVSS评分 软件包 责任SIG CVE-2022-40626 I5R4GB 0.17 4 zabbix Base-service CVE-2022-21222 I5U305 0.44 7.5 pcs sig-Ha CVE-2022-40476 I5R4K9 0.45 5.5 risc-v-kernel sig-RISC-V CVE-2021-4127 I5R6GY 0.58 thunderbird sig-desktop-apps CVE-2022-36402 I5RJWC 2.21 5.5 risc-v-kernel sig-RISC-V CVE-2022-34169 I5HV9H 4.37 7.5 openjdk-1.8.0 Compiler CVE-2022-42004 I5U706 4.56 7.5 jackson-databind sig-Java CVE-2022-20421 I5U713 4.57 7.8 kernel Kernel CVE-2022-42003 I5U709 4.57 7.5 jackson-databind sig-Java CVE-2022-20422 I5U71M 4.58 7 kernel Kernel CVE-2022-2928 I5U80N 5.08 7.5 dhcp Networking CVE-2021-34337 I5S654 6.37 mailman Application CVE-2022-23084 I5S79U 6.55 risc-v-kernel sig-RISC-V CVE-2022-23086 I5S7L9 6.56 risc-v-kernel sig-RISC-V CVE-2022-23085 I5S7KN 6.56 risc-v-kernel sig-RISC-V CVE-2022-34305 I5SD31 6.86 6.1 tomcat Application CVE-2022-41218 I5SDEB 6.87 5.5 risc-v-kernel sig-RISC-V CVE-2022-3171 I5UBLT 6.96 7.5 protobuf sig-CloudNative CVE-2022-31008 I5UBQ6 7 7.5 rabbitmq-server Application CVE-2022-35957 I5SELV 7.08 6.6 grafana Application CVE-2022-36062 I5SELR 7.08 3.8 grafana Application CVE-2022-3155 I5SELN 7.08 CVE-2022-3297 I5T0SC 7.12 7.8 vim Base-service CVE-2022-1941 I5SV4T 7.12 7.5 protobuf sig-CloudNative CVE-2022-3277 I5SNDX 8.45 openstack-neutron sig-openstack CVE-2022-2785 I5SVBG 9 5.5 risc-v-kernel sig-RISC-V CVE-2022-2785 I5SVBF 9 5.5 kernel Kernel CVE-2022-21824 I5USM1 9.57 8.2 mysql Others CVE-2022-3303 I5T9C4 12.2 4.7 risc-v-kernel sig-RISC-V CVE-2022-3303 I5T9C3 12.2 4.7 kernel Kernel CVE-2022-39282 I5VGTX 12.58 7.5 freerdp Application CVE-2022-39283 I5VGTP 12.58 7.5 freerdp Application CVE-2021-3481 I5TEAF 12.78 5.4 qt5 Desktop CVE-2022-41083 I5VK2C 12.8 7.8 jupyter sig-bigdata CVE-2022-3078 I5TEMI 12.8 5.5 risc-v-kernel sig-RISC-V CVE-2020-10136 I5TF8O 12.83 5.3 kernel Kernel CVE-2019-2101 I5TF8C 12.83 5.5 kernel Kernel CVE-2022-21233 I5TF80 12.83 5.5 risc-v-kernel sig-RISC-V CVE-2020-26143 I5TGQO 12.94 6.5 kernel Kernel CVE-2020-26140 I5TGQL 12.94 6.5 kernel Kernel CVE-2022-39835 I5THMV 13.35 5.3 gajim sig-mate-desktop CVE-2022-35255 I5TOU4 13.95 nodejs sig-nodejs CVE-2022-35256 I5TOU1 13.95 CVE-2021-27854 I5TP92 14.05 4.7 risc-v-kernel sig-RISC-V CVE-2021-27854 I5TP8Z 14.05 4.7 kernel Kernel CVE-2021-27861 I5TPBD 14.06 4.7 risc-v-kernel sig-RISC-V CVE-2021-27861 I5TPB2 14.06 4.7 kernel Kernel CVE-2022-3287 I5TPE8 14.07 6.5 fwupd System-tool CVE-2021-27853 I5TPCA 14.07 4.7 risc-v-kernel sig-RISC-V CVE-2021-27853 I5TPC2 14.07 4.7 kernel Kernel CVE-2021-27862 I5TPEG 14.08 CVE-2022-31629 I5TPJZ 14.46 6.5 php Base-service CVE-2021-43980 I5TQD3 14.53 5.3 tomcat Application CVE-2022-31628 I5TRIM 14.58 5.5 php Base-service CVE-2022-31628 I5TSDJ 14.62 5.5 php Base-service CVE-2022-1520 I5TUGK 14.79 thunderbird sig-desktop-apps CVE-2022-2805 I5TUGD 14.79 ovirt-engine oVirt CVE-2022-1736 I5TUG3 14.79 gnome-remote-desktop GNOME CVE-2022-28289 I5TUET 14.79 firefox Application CVE-2022-3306 I5TUZS 14.82 chromium Application CVE-2022-1834 I5TUWK 14.82 thunderbird sig-desktop-apps openEuler 社区指导文档及开放平台链接: openEuler 版本分支维护规范:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E7%89%…
openEuler release-management 版本分支PR指导:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E5%BC%…
社区QA 版本测试提单规范
https://gitee.com/openeuler/QA/blob/839f952696f271f83c018ccf3218cf493b92d65…
社区QA 测试平台 radiates
https://radiatest.openeuler.org
<
https://radiatest.openeuler.org/
> 车明道(openEuler release SIG) Mobile: +86 15345431107 中国(China)-杭州(Hangzhou)-滨江区江淑路360号华为杭州研发中心 HUAWEI , Jiangshu Road., Binjiang District, Hangzhou, P.R.China E-mail: chemingdao(a)huawei.com<mailto:chemingdao@huawei.com> [cid:image004.png@01D8E00D.08AB7280]Open Source OS for Digital Infrastructure 本邮件及其附件含有华为公司的保密信息,仅限于发送给上面地址中列出的个人或群组。禁止任何其他人以任何形 式使用(包括但不限于全部或部分地泄露、复制、或散发)本邮件中的信息。如果您错收了本邮件,请您立即电话 或邮件通知发件人并删除本邮件! This e-mail and its attachments contain confidential information from HUAWEI, which is intended only for the person or entity whose address is listed above. Any use of the information contained herein in any way (including, but not limited to, total or partial disclosure, reproduction, or dissemination) by persons other than the intended recipient(s) is prohibited. If you receive this e-mail in error, please notify the sender by phone or email immediately and delete it
1
0
0
0
Results per page:
10
25
50
100
200