Message ID | 20240817193240.27089-1-ian@retrospec.tv |
---|---|
Headers |
Return-Path: <guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org> X-Original-To: patchwork@mira.cbaines.net Delivered-To: patchwork@mira.cbaines.net Received: by mira.cbaines.net (Postfix, from userid 113) id 0DD2027BBEA; Sat, 17 Aug 2024 20:33:40 +0100 (BST) X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on mira.cbaines.net X-Spam-Level: X-Spam-Status: No, score=-7.6 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,MAILING_LIST_MULTI,RCVD_IN_VALIDITY_CERTIFIED, RCVD_IN_VALIDITY_RPBL,RCVD_IN_VALIDITY_SAFE,SPF_HELO_PASS, URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.6 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mira.cbaines.net (Postfix) with ESMTPS id 3943827BBE2 for <patchwork@mira.cbaines.net>; Sat, 17 Aug 2024 20:33:39 +0100 (BST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from <guix-patches-bounces@gnu.org>) id 1sfPB4-00083p-Ip; Sat, 17 Aug 2024 15:33:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <Debian-debbugs@debbugs.gnu.org>) id 1sfPAy-00081u-AK for guix-patches@gnu.org; Sat, 17 Aug 2024 15:33:24 -0400 Received: from debbugs.gnu.org ([2001:470:142:5::43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from <Debian-debbugs@debbugs.gnu.org>) id 1sfPAx-0000LX-Ta for guix-patches@gnu.org; Sat, 17 Aug 2024 15:33:23 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debbugs.gnu.org; s=debbugs-gnu-org; h=MIME-Version:Date:From:To:In-Reply-To:References:Subject; bh=NPdASBYEXFoJqLzZUxXdbk1e/bzGlhXPVCO+s3OkwwA=; b=F9Ba4UGn/1dIF+bpXC1pyHj4ZdSMhwsoN4ENhKp+jBllPTaYdOfQ0UmtN3Xq8n33ci3RhAvQmMMEB+a3i4aEM7cjtDT9ik1r5RXtE6MBYYTvZc/hOVwo9MOgXypOhVQQ5DBfZKkUFNTFx+OoaAtC1uZn3ppB0df6NJQ9iy4CeoM8YpuXK4WBLKwdCslMEKx20EHp8QTqTkuZ3OnpnZ6sH8wKnL7YfX/ubGrFyEsNc52DP+7SpGRXoBAjoZBYSvs/Q4YIah6YBVYNJ/SIcLdUUuyjpJrki3t0/+7dbL4iPlQR513lyYhMcPAEe9oHy6fPog2L50Lvb6vk7vNYyn2KPA==; Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from <Debian-debbugs@debbugs.gnu.org>) id 1sfPBb-0002Qo-4e for guix-patches@gnu.org; Sat, 17 Aug 2024 15:34:03 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#71832] [PATCH v6 0/3] [SECURITY] Update LibreWolf to 129.0.1-1; add nss-rapid References: <20240629035716.21504-1-ian@retrospec.tv> In-Reply-To: <20240629035716.21504-1-ian@retrospec.tv> Resent-From: Ian Eure <ian@retrospec.tv> Original-Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org> Resent-CC: guix-patches@gnu.org Resent-Date: Sat, 17 Aug 2024 19:34:03 +0000 Resent-Message-ID: <handler.71832.B71832.17239232429331@debbugs.gnu.org> Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 71832 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 71832@debbugs.gnu.org Cc: Ian Eure <ian@retrospec.tv>, guix-security@gnu.org Received: via spool by 71832-submit@debbugs.gnu.org id=B71832.17239232429331 (code B ref 71832); Sat, 17 Aug 2024 19:34:03 +0000 Received: (at 71832) by debbugs.gnu.org; 17 Aug 2024 19:34:02 +0000 Received: from localhost ([127.0.0.1]:55003 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from <debbugs-submit-bounces@debbugs.gnu.org>) id 1sfPBX-0002QA-Vd for submit@debbugs.gnu.org; Sat, 17 Aug 2024 15:34:02 -0400 Received: from fout4-smtp.messagingengine.com ([103.168.172.147]:51257) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from <ian@retrospec.tv>) id 1sfPBT-0002PM-2F for 71832@debbugs.gnu.org; Sat, 17 Aug 2024 15:33:55 -0400 Received: from phl-compute-06.internal (phl-compute-06.nyi.internal [10.202.2.46]) by mailfout.nyi.internal (Postfix) with ESMTP id 4338E13868EA; Sat, 17 Aug 2024 15:33:08 -0400 (EDT) Received: from phl-mailfrontend-01 ([10.202.2.162]) by phl-compute-06.internal (MEProxy); Sat, 17 Aug 2024 15:33:08 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=retrospec.tv; h= cc:cc:content-transfer-encoding:content-type:date:date:from:from :in-reply-to:message-id:mime-version:reply-to:subject:subject:to :to; s=fm2; t=1723923188; x=1724009588; bh=NPdASBYEXFoJqLzZUxXdb k1e/bzGlhXPVCO+s3OkwwA=; b=PsoUHTz1Y8AC+f/UM9QLOppNKxVYx8xuR0Mop jgRH8P5Ana6DY4xOLBhxxo9rOoCU20BrGl7N+U4Gj87yC1zJZE47NuJ0J1WRpBY9 EA/Aab5FN2OOuU1J10rFCl8ONycaJLW/BRTZYw5BSPb7LkrwbMvtZXRQBF2W8neN Nq8Hs5XG2eaYKuSIzwhuolVjvMIQSJ2KLbOw7id2DgsLPf9/qCB52F0ZEkUwVNOB NtFN0hvDHNwZJk7WkEnVDDqchZUUZen95cbWjdEA/lV51YQp66Zn+nzXBQin2yVZ ihkT9ALeFVBkQuSPbCCPQ9vRMOQ7WdNN0QCJK/K7hC2qgQ8cw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:message-id:mime-version:reply-to:subject:subject:to :to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s= fm3; t=1723923188; x=1724009588; bh=NPdASBYEXFoJqLzZUxXdbk1e/bzG lhXPVCO+s3OkwwA=; b=vlITosW6GcSuUkSaEZuwUX1r78NQSQJmM0+3sOM6IEfW XOmkDzmmHXF+afOshSsF6kKdWw1f7cFU75GBoMMi10kb9kP6eFTS2vUMv4K3SQQd FMDJBgL3DkWVjDNdX8vuwDxqnROz2GRCIPvNpA4PU5Iw9ju79MuM8hDnWcNBQhGA bWzYBEGq+AV0bc+w9LcHkeu75ocJQINOkUChq6riM7ToG1dzyh+BJPLSSmDzJypa tB2XrJCp/wtGWYWsnmZUYUGG6NzEaamuDmDl3k7a5cTnGjTCQoTEiKFsWB6DX9hO lScuIvAe1CFknvVpl6ijwSdCVSsInsoCNctDtiUKTw== X-ME-Sender: <xms:9PrAZriEcYmWhukGa-G9AHE36VhqnhvqOL5jqSgZkBoqhHLBwX8w2w> <xme:9PrAZoDuKLS2EA9b_hwhmDg3sOwWWBVCZ8cHHD6XkS6-Gs4i8ZPd8fc58NKqXKncs hRwnledmUZHPG9Lgw> X-ME-Received: <xmr:9PrAZrHkFFEKLq64xd67BptiyGWyRrifLQGdsW23ozRhN_M9LxPvT7mWlY2Aln71loriwT9g0ro66oT0j4XgM0YdezdQYom8MnxgRWKGxykh_MBImEM> X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeeftddruddutddgudegtdcutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpggftfghnshhusghstghrihgsvgdp uffrtefokffrpgfnqfghnecuuegrihhlohhuthemuceftddtnecunecujfgurhephffvve fufffkofgggfestdekredtredttdenucfhrhhomhepkfgrnhcugfhurhgvuceoihgrnhes rhgvthhrohhsphgvtgdrthhvqeenucggtffrrghtthgvrhhnpefgvdejhfelhfeftdeile elfedvhfefffetfeeuteelgfdvleffleevgfefueekjeenucffohhmrghinhepmhhoiihi lhhlrgdrohhrghenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrihhlfh hrohhmpehirghnsehrvghtrhhoshhpvggtrdhtvhdpnhgspghrtghpthhtohepfedpmhho uggvpehsmhhtphhouhhtpdhrtghpthhtohepjedukeefvdesuggvsggsuhhgshdrghhnuh drohhrghdprhgtphhtthhopehguhhigidqshgvtghurhhithihsehgnhhurdhorhhgpdhr tghpthhtohepihgrnhesrhgvthhrohhsphgvtgdrthhv X-ME-Proxy: <xmx:9PrAZoTRa-GskbtS1vWpdGbWwBZ0Rq7Ul7xw-U0ZByXlmkYQH6W_lg> <xmx:9PrAZoyRGLOtRgTbtnfsZxwpCGjzJQS0jQBc5yanXSCWYhzTTkMTRg> <xmx:9PrAZu5cMGq9PhIuHyXbONUeUeGOQhuwg9RsvmxucqWdWvRHMbOCzQ> <xmx:9PrAZtz2GizKs2QrK0tIXQ-zufhRIkDGITORRanrSx-cEzKSpq90MQ> <xmx:9PrAZk8yAuDpXuRIoTNXXs3b74_vAB2tSCt9HrOqZUKVR3UkcKmqBGpn> Feedback-ID: id9014242:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Sat, 17 Aug 2024 15:33:07 -0400 (EDT) From: Ian Eure <ian@retrospec.tv> Date: Sat, 17 Aug 2024 12:32:37 -0700 Message-ID: <20240817193240.27089-1-ian@retrospec.tv> X-Mailer: git-send-email 2.45.2 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: <guix-patches.gnu.org> List-Unsubscribe: <https://lists.gnu.org/mailman/options/guix-patches>, <mailto:guix-patches-request@gnu.org?subject=unsubscribe> List-Archive: <https://lists.gnu.org/archive/html/guix-patches> List-Post: <mailto:guix-patches@gnu.org> List-Help: <mailto:guix-patches-request@gnu.org?subject=help> List-Subscribe: <https://lists.gnu.org/mailman/listinfo/guix-patches>, <mailto:guix-patches-request@gnu.org?subject=subscribe> Errors-To: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org Sender: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org X-getmail-retrieved-from-mailbox: Patches |
Series |
Update LibreWolf to 129.0.1-1; add nss-rapid
|
|
Message
Ian Eure
Aug. 17, 2024, 7:32 p.m. UTC
vs. the previous versions of this patch series, v6: - Updates LibreWolf to 129.0.1-1, the latest upstream. - Updates nss-rapid, to version 3.103, the latest upstream. - Adds the skr locale to all-mozilla-locales. - Backs out improvements not directly related to updating the browser version, to make review easier. In addition to the CVEs fixed in 128.0, this includes fixes for[1]: CVE-2024-7518: Fullscreen notification dialog can be obscured by document content CVE-2024-7519: Out of bounds memory access in graphics shared memory handling CVE-2024-7520: Type confusion in WebAssembly CVE-2024-7521: Incomplete WebAssembly exception handing CVE-2024-7522: Out of bounds read in editor component CVE-2024-7523: Document content could partially obscure security prompts CVE-2024-7524: CSP strict-dynamic bypass using web-compatibility shims CVE-2024-7525: Missing permission check when creating a StreamFilter CVE-2024-7526: Uninitialized memory used by WebGL CVE-2024-7527: Use-after-free in JavaScript garbage collection CVE-2024-7528: Use-after-free in IndexedDB CVE-2024-7529: Document content could partially obscure security prompts CVE-2024-7530: Use-after-free in JavaScript code coverage collection CVE-2024-7531: PK11_Encrypt using CKM_CHACHA20 can reveal plaintext on Intel Sandy Bridge [1]: https://www.mozilla.org/en-US/security/advisories/mfsa2024-33/ Ian Eure (3): gnu: gnuzilla: Add skr to all-mozilla-locales. gnu: Add nss-rapid. gnu: librewolf: Update to 129.0.1-1. gnu/packages/gnuzilla.scm | 1 + gnu/packages/librewolf.scm | 12 +++---- gnu/packages/nss.scm | 67 ++++++++++++++++++++++++++++++++++++++ 3 files changed, 74 insertions(+), 6 deletions(-) -- 2.45.2
Comments
On 2024-08-17, Ian Eure wrote: > - Updates LibreWolf to 129.0.1-1, the latest upstream. > - Updates nss-rapid, to version 3.103, the latest upstream. > - Adds the skr locale to all-mozilla-locales. > - Backs out improvements not directly related to updating the browser version, to make review easier. It builds and runs fine for me, so overall I think this should be merged sooner than later (despite some of my minor comments on the nss-rapid patch)... given the previous iterations of patches over several months and the growing list of CVE fixes... If there are no strong objections and nobody beats me to it, I will merge these patches in the next couple days. Thanks for working on librewolf! Sorry the update process has been lagging! live well, vagrant
On 2024-08-17, Vagrant Cascadian wrote: > On 2024-08-17, Ian Eure wrote: >> - Updates LibreWolf to 129.0.1-1, the latest upstream. >> - Updates nss-rapid, to version 3.103, the latest upstream. >> - Adds the skr locale to all-mozilla-locales. >> - Backs out improvements not directly related to updating the browser version, to make review easier. > > It builds and runs fine for me, so overall I think this should be merged > sooner than later (despite some of my minor comments on the nss-rapid > patch)... given the previous iterations of patches over several months > and the growing list of CVE fixes... > > If there are no strong objections and nobody beats me to it, I will > merge these patches in the next couple days. Pushed as 58faaf4eaadafa09a97ab31103eb54bd2076a699. live well, vagrant