From patchwork Sat Aug 17 19:32:37 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ian Eure X-Patchwork-Id: 2773 Return-Path: X-Original-To: patchwork@mira.cbaines.net Delivered-To: patchwork@mira.cbaines.net Received: by mira.cbaines.net (Postfix, from userid 113) id 0DD2027BBEA; Sat, 17 Aug 2024 20:33:40 +0100 (BST) X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on mira.cbaines.net X-Spam-Level: X-Spam-Status: No, score=-7.6 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,MAILING_LIST_MULTI,RCVD_IN_VALIDITY_CERTIFIED, RCVD_IN_VALIDITY_RPBL,RCVD_IN_VALIDITY_SAFE,SPF_HELO_PASS, URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.6 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mira.cbaines.net (Postfix) with ESMTPS id 3943827BBE2 for ; Sat, 17 Aug 2024 20:33:39 +0100 (BST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1sfPB4-00083p-Ip; Sat, 17 Aug 2024 15:33:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1sfPAy-00081u-AK for guix-patches@gnu.org; Sat, 17 Aug 2024 15:33:24 -0400 Received: from debbugs.gnu.org ([2001:470:142:5::43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1sfPAx-0000LX-Ta for guix-patches@gnu.org; Sat, 17 Aug 2024 15:33:23 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debbugs.gnu.org; s=debbugs-gnu-org; h=MIME-Version:Date:From:To:In-Reply-To:References:Subject; bh=NPdASBYEXFoJqLzZUxXdbk1e/bzGlhXPVCO+s3OkwwA=; b=F9Ba4UGn/1dIF+bpXC1pyHj4ZdSMhwsoN4ENhKp+jBllPTaYdOfQ0UmtN3Xq8n33ci3RhAvQmMMEB+a3i4aEM7cjtDT9ik1r5RXtE6MBYYTvZc/hOVwo9MOgXypOhVQQ5DBfZKkUFNTFx+OoaAtC1uZn3ppB0df6NJQ9iy4CeoM8YpuXK4WBLKwdCslMEKx20EHp8QTqTkuZ3OnpnZ6sH8wKnL7YfX/ubGrFyEsNc52DP+7SpGRXoBAjoZBYSvs/Q4YIah6YBVYNJ/SIcLdUUuyjpJrki3t0/+7dbL4iPlQR513lyYhMcPAEe9oHy6fPog2L50Lvb6vk7vNYyn2KPA==; Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1sfPBb-0002Qo-4e for guix-patches@gnu.org; Sat, 17 Aug 2024 15:34:03 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#71832] [PATCH v6 0/3] [SECURITY] Update LibreWolf to 129.0.1-1; add nss-rapid References: <20240629035716.21504-1-ian@retrospec.tv> In-Reply-To: <20240629035716.21504-1-ian@retrospec.tv> Resent-From: Ian Eure Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Sat, 17 Aug 2024 19:34:03 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 71832 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 71832@debbugs.gnu.org Cc: Ian Eure , guix-security@gnu.org Received: via spool by 71832-submit@debbugs.gnu.org id=B71832.17239232429331 (code B ref 71832); Sat, 17 Aug 2024 19:34:03 +0000 Received: (at 71832) by debbugs.gnu.org; 17 Aug 2024 19:34:02 +0000 Received: from localhost ([127.0.0.1]:55003 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1sfPBX-0002QA-Vd for submit@debbugs.gnu.org; Sat, 17 Aug 2024 15:34:02 -0400 Received: from fout4-smtp.messagingengine.com ([103.168.172.147]:51257) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1sfPBT-0002PM-2F for 71832@debbugs.gnu.org; Sat, 17 Aug 2024 15:33:55 -0400 Received: from phl-compute-06.internal (phl-compute-06.nyi.internal [10.202.2.46]) by mailfout.nyi.internal (Postfix) with ESMTP id 4338E13868EA; Sat, 17 Aug 2024 15:33:08 -0400 (EDT) Received: from phl-mailfrontend-01 ([10.202.2.162]) by phl-compute-06.internal (MEProxy); Sat, 17 Aug 2024 15:33:08 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=retrospec.tv; h= cc:cc:content-transfer-encoding:content-type:date:date:from:from :in-reply-to:message-id:mime-version:reply-to:subject:subject:to :to; s=fm2; t=1723923188; x=1724009588; bh=NPdASBYEXFoJqLzZUxXdb k1e/bzGlhXPVCO+s3OkwwA=; b=PsoUHTz1Y8AC+f/UM9QLOppNKxVYx8xuR0Mop jgRH8P5Ana6DY4xOLBhxxo9rOoCU20BrGl7N+U4Gj87yC1zJZE47NuJ0J1WRpBY9 EA/Aab5FN2OOuU1J10rFCl8ONycaJLW/BRTZYw5BSPb7LkrwbMvtZXRQBF2W8neN Nq8Hs5XG2eaYKuSIzwhuolVjvMIQSJ2KLbOw7id2DgsLPf9/qCB52F0ZEkUwVNOB NtFN0hvDHNwZJk7WkEnVDDqchZUUZen95cbWjdEA/lV51YQp66Zn+nzXBQin2yVZ ihkT9ALeFVBkQuSPbCCPQ9vRMOQ7WdNN0QCJK/K7hC2qgQ8cw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:message-id:mime-version:reply-to:subject:subject:to :to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s= fm3; t=1723923188; x=1724009588; bh=NPdASBYEXFoJqLzZUxXdbk1e/bzG lhXPVCO+s3OkwwA=; b=vlITosW6GcSuUkSaEZuwUX1r78NQSQJmM0+3sOM6IEfW XOmkDzmmHXF+afOshSsF6kKdWw1f7cFU75GBoMMi10kb9kP6eFTS2vUMv4K3SQQd FMDJBgL3DkWVjDNdX8vuwDxqnROz2GRCIPvNpA4PU5Iw9ju79MuM8hDnWcNBQhGA bWzYBEGq+AV0bc+w9LcHkeu75ocJQINOkUChq6riM7ToG1dzyh+BJPLSSmDzJypa tB2XrJCp/wtGWYWsnmZUYUGG6NzEaamuDmDl3k7a5cTnGjTCQoTEiKFsWB6DX9hO lScuIvAe1CFknvVpl6ijwSdCVSsInsoCNctDtiUKTw== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeeftddruddutddgudegtdcutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpggftfghnshhusghstghrihgsvgdp uffrtefokffrpgfnqfghnecuuegrihhlohhuthemuceftddtnecunecujfgurhephffvve fufffkofgggfestdekredtredttdenucfhrhhomhepkfgrnhcugfhurhgvuceoihgrnhes rhgvthhrohhsphgvtgdrthhvqeenucggtffrrghtthgvrhhnpefgvdejhfelhfeftdeile elfedvhfefffetfeeuteelgfdvleffleevgfefueekjeenucffohhmrghinhepmhhoiihi lhhlrgdrohhrghenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrihhlfh hrohhmpehirghnsehrvghtrhhoshhpvggtrdhtvhdpnhgspghrtghpthhtohepfedpmhho uggvpehsmhhtphhouhhtpdhrtghpthhtohepjedukeefvdesuggvsggsuhhgshdrghhnuh drohhrghdprhgtphhtthhopehguhhigidqshgvtghurhhithihsehgnhhurdhorhhgpdhr tghpthhtohepihgrnhesrhgvthhrohhsphgvtgdrthhv X-ME-Proxy: Feedback-ID: id9014242:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Sat, 17 Aug 2024 15:33:07 -0400 (EDT) From: Ian Eure Date: Sat, 17 Aug 2024 12:32:37 -0700 Message-ID: <20240817193240.27089-1-ian@retrospec.tv> X-Mailer: git-send-email 2.45.2 MIME-Version: 1.0 X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org Sender: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org X-getmail-retrieved-from-mailbox: Patches vs. the previous versions of this patch series, v6: - Updates LibreWolf to 129.0.1-1, the latest upstream. - Updates nss-rapid, to version 3.103, the latest upstream. - Adds the skr locale to all-mozilla-locales. - Backs out improvements not directly related to updating the browser version, to make review easier. In addition to the CVEs fixed in 128.0, this includes fixes for[1]: CVE-2024-7518: Fullscreen notification dialog can be obscured by document content CVE-2024-7519: Out of bounds memory access in graphics shared memory handling CVE-2024-7520: Type confusion in WebAssembly CVE-2024-7521: Incomplete WebAssembly exception handing CVE-2024-7522: Out of bounds read in editor component CVE-2024-7523: Document content could partially obscure security prompts CVE-2024-7524: CSP strict-dynamic bypass using web-compatibility shims CVE-2024-7525: Missing permission check when creating a StreamFilter CVE-2024-7526: Uninitialized memory used by WebGL CVE-2024-7527: Use-after-free in JavaScript garbage collection CVE-2024-7528: Use-after-free in IndexedDB CVE-2024-7529: Document content could partially obscure security prompts CVE-2024-7530: Use-after-free in JavaScript code coverage collection CVE-2024-7531: PK11_Encrypt using CKM_CHACHA20 can reveal plaintext on Intel Sandy Bridge [1]: https://www.mozilla.org/en-US/security/advisories/mfsa2024-33/ Ian Eure (3): gnu: gnuzilla: Add skr to all-mozilla-locales. gnu: Add nss-rapid. gnu: librewolf: Update to 129.0.1-1. gnu/packages/gnuzilla.scm | 1 + gnu/packages/librewolf.scm | 12 +++---- gnu/packages/nss.scm | 67 ++++++++++++++++++++++++++++++++++++++ 3 files changed, 74 insertions(+), 6 deletions(-) --- 2.45.2