Bug 2021523 - rpki-client-7.5 is available
Summary: rpki-client-7.5 is available
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: rpki-client
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Robert Scheck
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-11-09 14:25 UTC by Upstream Release Monitoring
Modified: 2021-11-18 01:57 UTC (History)
2 users (show)

Fixed In Version: rpki-client-7.5-1.el8 rpki-client-7.5-1.fc34 rpki-client-7.5-1.fc35 rpki-client-7.5-1.el7 rpki-client-7.5-1.fc33
Doc Type: ---
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-11-18 00:51:09 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Upstream Release Monitoring 2021-11-09 14:25:33 UTC
Latest upstream release: 7.5
Current version/release in rawhide: 7.4-1.fc36
URL: https://www.rpki-client.org/

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://fedoraproject.org/wiki/Upstream_release_monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from anitya: https://release-monitoring.org/project/77982/

Comment 1 Fedora Update System 2021-11-09 22:31:19 UTC
FEDORA-2021-c9852f0be4 has been submitted as an update to Fedora 35. https://bodhi.fedoraproject.org/updates/FEDORA-2021-c9852f0be4

Comment 2 Fedora Update System 2021-11-09 22:31:19 UTC
FEDORA-2021-31012ee5a0 has been submitted as an update to Fedora 33. https://bodhi.fedoraproject.org/updates/FEDORA-2021-31012ee5a0

Comment 3 Fedora Update System 2021-11-09 22:31:20 UTC
FEDORA-2021-2f9642ec0c has been submitted as an update to Fedora 34. https://bodhi.fedoraproject.org/updates/FEDORA-2021-2f9642ec0c

Comment 4 Fedora Update System 2021-11-09 22:31:20 UTC
FEDORA-EPEL-2021-05dd12001e has been submitted as an update to Fedora EPEL 7. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-05dd12001e

Comment 5 Fedora Update System 2021-11-09 22:31:22 UTC
FEDORA-EPEL-2021-742db3f554 has been submitted as an update to Fedora EPEL 8. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-742db3f554

Comment 6 Fedora Update System 2021-11-10 03:23:37 UTC
FEDORA-2021-31012ee5a0 has been pushed to the Fedora 33 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2021-31012ee5a0`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2021-31012ee5a0

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 7 Fedora Update System 2021-11-10 03:32:57 UTC
FEDORA-EPEL-2021-742db3f554 has been pushed to the Fedora EPEL 8 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-742db3f554

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 8 Fedora Update System 2021-11-10 03:38:45 UTC
FEDORA-EPEL-2021-05dd12001e has been pushed to the Fedora EPEL 7 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-05dd12001e

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 9 Fedora Update System 2021-11-10 04:04:34 UTC
FEDORA-2021-2f9642ec0c has been pushed to the Fedora 34 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2021-2f9642ec0c`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2021-2f9642ec0c

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 10 Fedora Update System 2021-11-10 04:11:40 UTC
FEDORA-2021-c9852f0be4 has been pushed to the Fedora 35 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2021-c9852f0be4`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2021-c9852f0be4

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 11 ties 2021-11-14 14:41:11 UTC
Will this be indicated to be a security update?

I do not think OpenBSD requested a CVE - but 7.5 fixes multiple issues due to how input from un-trusted parties was handled; issues for which other implementations requested a CVE. There was a CVD for this (https://english.ncsc.nl/latest/news/2021/october/29/upcoming-announcement-of-rpki-cvd-procedure) - as well as a lot of comments on how the CVD was handled.

The best source to see that this is a vulnerability is https://rpki.exposed. This (marketing) site is controlled by one the rpki-client authors and acknowledges that rpki-client was vulnerable to issues that other implementations issued a CVE for.

Comment 12 ties 2021-11-14 14:44:03 UTC
Ok - unfamiliar with the Fedora release infrastructure. Turns out it _is_ a security update in testing. In which case let's hope it goes out soon :)

Comment 13 Fedora Update System 2021-11-18 00:51:09 UTC
FEDORA-EPEL-2021-742db3f554 has been pushed to the Fedora EPEL 8 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 14 Fedora Update System 2021-11-18 01:06:38 UTC
FEDORA-2021-2f9642ec0c has been pushed to the Fedora 34 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 15 Fedora Update System 2021-11-18 01:13:48 UTC
FEDORA-2021-c9852f0be4 has been pushed to the Fedora 35 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 16 Fedora Update System 2021-11-18 01:32:15 UTC
FEDORA-EPEL-2021-05dd12001e has been pushed to the Fedora EPEL 7 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 17 Fedora Update System 2021-11-18 01:57:38 UTC
FEDORA-2021-31012ee5a0 has been pushed to the Fedora 33 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.