Bug 2332075 (CVE-2019-12900) - CVE-2019-12900 bzip2: bzip2: Data integrity error when decompressing (with data integrity tests fail).
Summary: CVE-2019-12900 bzip2: bzip2: Data integrity error when decompressing (with da...
Keywords:
Status: NEW
Alias: CVE-2019-12900
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2332077
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-12-12 14:02 UTC by OSIDB Bzimport
Modified: 2025-05-14 17:56 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2025:0760 0 None None None 2025-01-28 09:18:26 UTC
Red Hat Product Errata RHBA-2025:0772 0 None None None 2025-01-28 17:01:55 UTC
Red Hat Product Errata RHBA-2025:0796 0 None None None 2025-01-29 16:25:38 UTC
Red Hat Product Errata RHBA-2025:0852 0 None None None 2025-01-30 19:11:04 UTC
Red Hat Product Errata RHBA-2025:0886 0 None None None 2025-02-03 09:36:55 UTC
Red Hat Product Errata RHBA-2025:0887 0 None None None 2025-02-03 09:26:46 UTC
Red Hat Product Errata RHBA-2025:0896 0 None None None 2025-02-03 16:36:08 UTC
Red Hat Product Errata RHBA-2025:0901 0 None None None 2025-02-03 15:28:11 UTC
Red Hat Product Errata RHBA-2025:1103 0 None None None 2025-02-05 21:55:31 UTC
Red Hat Product Errata RHBA-2025:1148 0 None None None 2025-02-06 16:18:03 UTC
Red Hat Product Errata RHBA-2025:1208 0 None None None 2025-02-10 08:45:18 UTC
Red Hat Product Errata RHBA-2025:1257 0 None None None 2025-02-10 22:29:39 UTC
Red Hat Product Errata RHBA-2025:1259 0 None None None 2025-02-10 22:38:41 UTC
Red Hat Product Errata RHBA-2025:1260 0 None None None 2025-02-10 22:38:08 UTC
Red Hat Product Errata RHBA-2025:1302 0 None None None 2025-02-11 16:03:17 UTC
Red Hat Product Errata RHBA-2025:1431 0 None None None 2025-02-13 14:17:43 UTC
Red Hat Product Errata RHBA-2025:1432 0 None None None 2025-02-13 14:19:51 UTC
Red Hat Product Errata RHBA-2025:1699 0 None None None 2025-02-19 19:20:40 UTC
Red Hat Product Errata RHBA-2025:1939 0 None None None 2025-02-27 18:32:14 UTC
Red Hat Product Errata RHBA-2025:1989 0 None None None 2025-03-03 08:44:47 UTC
Red Hat Product Errata RHBA-2025:3084 0 None None None 2025-03-20 14:24:11 UTC
Red Hat Product Errata RHBA-2025:7578 0 None None None 2025-05-14 09:45:58 UTC
Red Hat Product Errata RHBA-2025:7627 0 None None None 2025-05-14 17:56:54 UTC
Red Hat Product Errata RHSA-2025:0733 0 None None None 2025-01-28 01:09:21 UTC
Red Hat Product Errata RHSA-2025:0925 0 None None None 2025-02-04 09:15:11 UTC
Red Hat Product Errata RHSA-2025:1154 0 None None None 2025-02-06 16:42:57 UTC

Description OSIDB Bzimport 2024-12-12 14:02:15 UTC
There were several "Security Fixes" for bzip2: out-of-bounds
write in function BZ2_decompress (CVE-2019-12900). e.g. RHSA-2024:8922
and RHSA-2024:10803.

The problem is that CVE-2019-12900 is 5 years old and bogus. The
applied patch causes a change in behavior which causes some bz2 files
to no longer decompress.

Upstream did a better fix for bzip2 1.0.8. Full story is here:
https://gnu.wildebeest.org/blog/mjw/2019/08/02/bzip2-and-the-cve-that-wasnt/

You can see check that the new bzip2 is broken by running the
upstream bzip2 testsuite:

$ git clone https://sourceware.org/git/bzip2-tests.git
$ cd bzip2-tests
$ ./run-tests.sh
[...]
bzip2: Data integrity error when decompressing.
FAIL: ./lbzip2/32767.bz2 Decompress
[...]
Bad results, look for FAIL and !!! in the logs above
 - ./lbzip2/32767.bz2 bad decompress result

There should obviously be no FAILs.

Please revert this patch or apply the followup patch from 1.0.8:
https://inbox.sourceware.org/bzip2-devel/f9230fc65a3529b59b31f13494c72a1c01a6148e.camel@klomp.org/
https://sourceware.org/cgit/bzip2/commit/?id=b07b105d1b66e32760095e3602261738443b9e13

Upstream reminder to Please don't "fix" CVE-2019-12900:
https://inbox.sourceware.org/bzip2-devel/20241108214034.GC8315@gnu.wildebeest.org

Comment 2 errata-xmlrpc 2025-01-28 01:09:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:0733 https://access.redhat.com/errata/RHSA-2025:0733

Comment 3 errata-xmlrpc 2025-02-04 09:15:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:0925 https://access.redhat.com/errata/RHSA-2025:0925

Comment 4 errata-xmlrpc 2025-02-06 16:42:56 UTC
This issue has been addressed in the following products:

  RHINT Camel-K 1.10.9

Via RHSA-2025:1154 https://access.redhat.com/errata/RHSA-2025:1154


Note You need to log in before you can comment on or make changes to this bug.