From patchwork Sun May 18 21:43:21 2025 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ian Eure X-Patchwork-Id: 42731 Return-Path: X-Original-To: patchwork@mira.cbaines.net Delivered-To: patchwork@mira.cbaines.net Received: by mira.cbaines.net (Postfix, from userid 113) id E196027BC4A; Sun, 18 May 2025 22:44:17 +0100 (BST) X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on mira.cbaines.net X-Spam-Level: X-Spam-Status: No, score=-6.4 required=5.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,MAILING_LIST_MULTI,RCVD_IN_DNSWL_BLOCKED, RCVD_IN_VALIDITY_CERTIFIED,RCVD_IN_VALIDITY_RPBL,RCVD_IN_VALIDITY_SAFE, SPF_HELO_PASS,URIBL_BLOCKED autolearn=unavailable autolearn_force=no version=3.4.6 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mira.cbaines.net (Postfix) with ESMTPS id A62E327BC49 for ; Sun, 18 May 2025 22:44:15 +0100 (BST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1uGlnh-0004Th-Ts; Sun, 18 May 2025 17:44:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1uGlnf-0004TP-Of for guix-patches@gnu.org; Sun, 18 May 2025 17:44:04 -0400 Received: from debbugs.gnu.org ([2001:470:142:5::43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1uGlnf-0007R4-5Z for guix-patches@gnu.org; Sun, 18 May 2025 17:44:03 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debbugs.gnu.org; s=debbugs-gnu-org; h=MIME-Version:Date:From:To:Subject; bh=j0qCtQu8Uxo7xgCToHJCkGWtzMLhUUwxEavzrk3yjdQ=; b=Rumsl2OfEAfdIs3Rm3ZTMyVgb7j5gA4Qw68x2q2Rm8G8oeG7SsBCnyZLAvyXxyuzKzovNqU1LMoTh5YnKZBjUQ5LuhcpsXNM9xWgpB0oFspVlglJy4TaE01/UJlH6N3y/EcMuCTZbS0l2+PpAy2sg/6vHpgPFiw0um6CBR1G3O4tCzVGx/Px8c4xd41HsvpTKsR0o5Wpty0xSF8BPPwN85zk9i4UtEqryhPtlJwmf5u5ZcsTH7TlO7vR0SHDHPZrpjOn1uoe35CZafSL8apTCzQhXYo3Iyr+GtNRQA0y2rJlYM141p5f3Enp4jERGMRBDTdT53yPEtwZBCbVz6cf7A==; Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1uGlne-0004Zr-BC for guix-patches@gnu.org; Sun, 18 May 2025 17:44:02 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#78487] [PATCH] gnu: librewolf: Update to 138.0.4-1 [security fixes]. Resent-From: Ian Eure Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Sun, 18 May 2025 21:44:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: report 78487 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 78487@debbugs.gnu.org Cc: Ian Eure X-Debbugs-Original-To: guix-patches@gnu.org Received: via spool by submit@debbugs.gnu.org id=B.174760462217538 (code B ref -1); Sun, 18 May 2025 21:44:02 +0000 Received: (at submit) by debbugs.gnu.org; 18 May 2025 21:43:42 +0000 Received: from localhost ([127.0.0.1]:32981 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1uGlnJ-0004Yl-NK for submit@debbugs.gnu.org; Sun, 18 May 2025 17:43:42 -0400 Received: from lists.gnu.org ([2001:470:142::17]:38560) by debbugs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from ) id 1uGlnG-0004YR-CW for submit@debbugs.gnu.org; Sun, 18 May 2025 17:43:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1uGlnA-0004N6-RI for guix-patches@gnu.org; Sun, 18 May 2025 17:43:32 -0400 Received: from fhigh-a2-smtp.messagingengine.com ([103.168.172.153]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1uGln8-0007Oa-Fq for guix-patches@gnu.org; Sun, 18 May 2025 17:43:32 -0400 Received: from phl-compute-08.internal (phl-compute-08.phl.internal [10.202.2.48]) by mailfhigh.phl.internal (Postfix) with ESMTP id B34F411400F8; Sun, 18 May 2025 17:43:27 -0400 (EDT) Received: from phl-mailfrontend-01 ([10.202.2.162]) by phl-compute-08.internal (MEProxy); Sun, 18 May 2025 17:43:27 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=retrospec.tv; h= cc:cc:content-transfer-encoding:content-type:date:date:from:from :in-reply-to:message-id:mime-version:reply-to:subject:subject:to :to; s=fm2; t=1747604607; x=1747691007; bh=j0qCtQu8Uxo7xgCToHJCk GWtzMLhUUwxEavzrk3yjdQ=; b=Ic5m/4vbB1N0EDmq5xJ6yRpgDqOw5RAq1nhGR E0sRRaK7lJTAC2BP7ccwTHI2BkHNvabDSfU05PKrYg06/f/LtjM4/oJ8vpgRkE+O cDV7lZT0GKCb58LKu6/Kqx1b//u8/r7kqu+zbKuaW8wxfFszzOAz4DZtywteh/B+ c7UNzN/61+DN5Etc1aTn/0RWyEMOT3QGiagZovrqulfGxwZQqzgsSw4P6pWfFdgk /GJfTUnKqUoEtO0C8MNmswaG7opCicpLIVjqm2fiiAeJowONxbdq1tj5S4D9sDA4 JaWZXroRX2JHS0+iyQjcBLHQMRuDHtPNu3wkbYTp42sdmE4wA== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:message-id:mime-version:reply-to:subject:subject:to :to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm3; t= 1747604607; x=1747691007; bh=j0qCtQu8Uxo7xgCToHJCkGWtzMLhUUwxEav zrk3yjdQ=; b=AFsApG/9jy6j1WGWbfOBT+MFvkhPk1wejHbgmnot855qNK+t21E W2E49OAKEJ5ywBNG0AC5U1aJEBynLV9P+TPIJm1KAiNESD8BLQPSxiTo3lANy0AS uv2v+JMaW7YTdNj4cvY0XPOd35ZQPQxLoszYZoUnKJwTQVBL2bHnO4TwV18Wzgbl XY3GRP4REHLGmSkoqIf+sHH38Bg/u4SP3m5I52tQPUqmjL9Nx/fU8t5mzLRVv3us rEN71E+eWS/D0a5xKKs9YdkwyqA3k0htFYHawhFkvj3Ppz1ePs6t08c1nPtxqEAh Qs4MOaqeEZY6lnMIC1hmtQQqCKV1gWoldSw== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefvddrtddtgdefudelieduucetufdoteggodetrf dotffvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdggtfgfnhhsuhgsshgtrhhisggv pdfurfetoffkrfgpnffqhgenuceurghilhhouhhtmecufedttdenucenucfjughrpefhvf evufffkffoggfgsedtkeertdertddtnecuhfhrohhmpefkrghnucfguhhrvgcuoehirghn sehrvghtrhhoshhpvggtrdhtvheqnecuggftrfgrthhtvghrnhephfeiveeliedukeffhe fhleeijedtveelleetgefggfehkeeljeehtdeguddvvefgnecuvehluhhsthgvrhfuihii vgeptdenucfrrghrrghmpehmrghilhhfrhhomhepihgrnhesrhgvthhrohhsphgvtgdrth hvpdhnsggprhgtphhtthhopedvpdhmohguvgepshhmthhpohhuthdprhgtphhtthhopehg uhhigidqphgrthgthhgvshesghhnuhdrohhrghdprhgtphhtthhopehirghnsehrvghtrh hoshhpvggtrdhtvh X-ME-Proxy: Feedback-ID: id9014242:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Sun, 18 May 2025 17:43:26 -0400 (EDT) From: Ian Eure Date: Sun, 18 May 2025 14:43:21 -0700 Message-ID: <20250518214321.26115-1-ian@retrospec.tv> X-Mailer: git-send-email 2.49.0 MIME-Version: 1.0 Received-SPF: pass client-ip=103.168.172.153; envelope-from=ian@retrospec.tv; helo=fhigh-a2-smtp.messagingengine.com X-Spam_score_int: -37 X-Spam_score: -3.8 X-Spam_bar: --- X-Spam_report: (-3.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H5=-1, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org Sender: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org X-getmail-retrieved-from-mailbox: Patches Fixes: CVE-2025-4918: Out-of-bounds access when resolving Promise objects CVE-2025-4919: Out-of-bounds access when optimizing linear sums * gnu/packages/librewolf.scm (librewolf): Update to 138.0.4-1. Change-Id: I2c2b7b5a043b37b60f0378f115f0f31fa3993618 --- gnu/packages/librewolf.scm | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/gnu/packages/librewolf.scm b/gnu/packages/librewolf.scm index 063a89420fe..db4a7673858 100644 --- a/gnu/packages/librewolf.scm +++ b/gnu/packages/librewolf.scm @@ -207,17 +207,17 @@ (define rust-librewolf rust-1.82) ;; Update this id with every update to its release date. ;; It's used for cache validation and therefore can lead to strange bugs. ;; ex: date '+%Y%m%d%H%M%S' -(define %librewolf-build-id "20250502155055") +(define %librewolf-build-id "20250518101454") (define-public librewolf (package (name "librewolf") - (version "138.0.3-1") + (version "138.0.4-1") (source (make-librewolf-source #:version version - #:firefox-hash "1r0kam26cz5rz39n6zcc2hrbav6dxlfrsa0qhhfjlnv33ns3lzx2" - #:librewolf-hash "1bf9sa5radjr7g6ng7kqy2ss13c0q6vkq9dfzj5y998ifxw19s4c" + #:firefox-hash "0mjh2if31ibx68a66cvxh5sa20xb78gdn9wdw0wv745dinq0vlrz" + #:librewolf-hash "1g4r2k8z5i25gcc8gfspixbi21dddyk4yg6wv7nya44swy51j7r9" #:l10n firefox-l10n)) (build-system gnu-build-system) (arguments