Commit Graph

1929 Commits

Author SHA1 Message Date
fnv
9a02c10f76 openssh: update package location to CDN repo 2021-07-31 18:35:16 +00:00
heitbaum
111da88831 samba: update to 4.13.9
update 4.13.8 (2021-04-29) to 4.13.9 (2021-05-11)
release notes: https://www.samba.org/samba/history/samba-4.13.9.html

This is the latest stable release of the Samba 4.13 release series.

Changes since 4.13.8
--------------------

o  Jeremy Allison <jra@samba.org>
   * BUG 14696: s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success.

o  Andrew Bartlett <abartlet@samba.org>
   * BUG 14689: Add documentation for dsdb_group_audit and dsdb_group_json_audit
     to "log level", synchronise "log level" in smb.conf with the code.

o  Ralph Boehme <slow@samba.org>
   * BUG 14672: Fix smbd panic when two clients open same file.
   * BUG 14675: Fix memory leak in the RPC server.
   * BUG 14679: s3: smbd: Fix deferred renames.

o  Samuel Cabrero <scabrero@samba.org>
   * BUG 14675: s3-iremotewinspool: Set the per-request memory context.

o  Volker Lendecke <vl@samba.org>
   * BUG 14675: rpc_server3: Fix a memleak for internal pipes.

o  Stefan Metzmacher <metze@samba.org>
   * BUG 11899: third_party: Update socket_wrapper to version 1.3.2.
   * BUG 14640: third_party: Update socket_wrapper to version 1.3.3.

o  Christof Schmitt <cs@samba.org>
   * BUG 14663: idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid
     conflict.

o  Martin Schwenke <martin@meltin.net
   * BUG 14288: Fix the build on OmniOS.
2021-05-13 09:55:14 +00:00
CvH
1cc0e3a8aa Merge pull request #5343 from heitbaum/samba
samba: update to 4.13.8
2021-05-09 18:58:40 +02:00
heitbaum
f44dac9d67 netbase: update to 6.3
update 6.2 to 6.3
diff: https://salsa.debian.org/md/netbase/-/compare/v6.2...v6.3
2021-04-30 23:53:22 +00:00
heitbaum
4c499faaf0 samba: update to 4.13.8
update 4.1.7 (2021-03-24) to 4.18.8 (2021-04-29)
release notes: https://www.samba.org/samba/history/samba-4.13.8.html

==

This is a security release in order to address the following defect:

o CVE-2021-20254: Negative idmap cache entries can cause incorrect group entries
  in the Samba file server process token.

=======
Details
=======

o  CVE-2021-20254:
   The Samba smbd file server must map Windows group identities (SIDs) into unix
   group ids (gids). The code that performs this had a flaw that could allow it
   to read data beyond the end of the array in the case where a negative cache
   entry had been added to the mapping cache. This could cause the calling code
   to return those values into the process token that stores the group
   membership for a user.

   Most commonly this flaw caused the calling code to crash, but an alert user
   (Peter Eriksson, IT Department, Linköping University) found this flaw by
   noticing an unprivileged user was able to delete a file within a network
   share that they should have been disallowed access to.

   Analysis of the code paths has not allowed us to discover a way for a
   remote user to be able to trigger this flaw reproducibly or on demand,
   but this CVE has been issued out of an abundance of caution.

Changes since 4.13.7
--------------------

o  Volker Lendecke <vl@samba.org>
   * BUG 14571: CVE-2021-20254: Fix buffer overrun in sids_to_unixids().
2021-04-30 10:19:04 +00:00
Ian Leonard
a170ab9bce wireless-regdb: update checksum for 2021.04.21 release
Signed-off-by: Ian Leonard <antonlacon@gmail.com>
2021-04-22 06:59:30 +00:00
heitbaum
e03c555284 wireless-regdb: update to 2021.04.21
update 2020.11.20 to 2021.04.21
announcement: http://lists.infradead.org/pipermail/wireless-regdb/2021-April/001242.html
2021-04-22 00:32:27 +00:00
Christian Hewitt
be300d893a connman: bump to 1.39 + 27/3/2021 2021-03-29 12:55:14 +00:00
heitbaum
2ca6482365 samba: update to 4.13.7
update 4.13.5 to 4.13.7
changelog:
- https://www.samba.org/samba/history/samba-4.13.6.html
- https://www.samba.org/samba/history/samba-4.13.7.html
2021-03-25 08:47:57 +00:00
CvH
57e0578cd8 Merge pull request #5240 from heitbaum/samba
samba: update to 4.13.5
2021-03-20 10:23:04 +01:00
SupervisedThinking
af30a00ce5 bluez: add patch "Fix removing all remote SEPs when loading from cache"
- Fixes: https://github.com/bluez/bluez/issues/102
2021-03-12 13:49:30 +01:00
heitbaum
7f82a9c80f samba: update to 4.13.5
update 4.13.4 to 4.13.5
changelog: https://www.samba.org/samba/history/samba-4.13.5.html
2021-03-10 07:51:46 +00:00
probonopd
3547d20ffe avahi: do not delete ssh.service 2021-03-10 08:31:06 +01:00
Christian Hewitt
78cea639e3 Merge pull request #5189 from heitbaum/wg
wireguard-tools: update to 1.0.20210223
2021-03-08 15:57:32 +04:00
heitbaum
e6ea0cf6a5 openssh: update to 8.5p1
update 8.4p1 (2020-09-27) to 8.5p1 (2021-03-03)
release notes: http://www.openssh.com/txt/release-8.5

update patches - reverting openssh-portable patch:
- acadbb3402
2021-03-04 11:58:32 +00:00
SupervisedThinking
d1b7799981 bluez: set JustWorksRepairing=always
https://patchwork.kernel.org/project/bluetooth/patch/20200214114350.Bluez.v3.1.I333a90ad3c75882c6f008c94a28ca7d3e8f6c76e@changeid/
2021-03-01 17:37:33 +01:00
SupervisedThinking
24c3d53f8a bluez: update to bluez-5.56 2021-03-01 17:29:35 +01:00
mglae
67e97dc822 connman: update to 69a221f9 2021-02-27 14:19:39 +01:00
heitbaum
1ab6b066ce wireguard-tools: update to 1.0.20210223
update 1.0.20200827 to 1.0.20210223
log: https://git.zx2c4.com/wireguard-tools/log/
announce: https://www.mail-archive.com/wireguard@lists.zx2c4.com/msg06037.html

--

A new version, v1.0.20210223, of wireguard-tools has been tagged in the git
repository, containing various required userspace utilities, such as the
wg(8) and wg-quick(8) commands and documentation.

== Changes ==

  * wg-quick: android: do not free iterated pointer
  * wg-quick: openbsd: no use for userspace support
  * embeddable-wg-library: sync latest from netlink.h
  * wincompat: recent mingw has inet_ntop/inet_pton
  * wincompat: add resource and manifest and enable lto
  * wincompat: do not elevate by default
  * completion: add help and syncconf completions
  * sticky-sockets: do not use SO_REUSEADDR
  * man: LOG_LEVEL variables changed name
  * ipc: do not use fscanf with trailing \n
  * ipc: read trailing responses after set operation

This release contains commits from: Jason A. Donenfeld.
2021-02-27 09:27:48 +00:00
mglae
b4a18fae4f connman: update to 1.39 2021-02-08 18:23:52 +01:00
CvH
830f248903 Merge pull request #5021 from heitbaum/b4
Update netfilter packages
2021-01-27 21:00:57 +01:00
heitbaum
87fe8d153e samba: update to 4.13.4
update 4.13.3 to 4.13.4
changelog: https://www.samba.org/samba/history/samba-4.13.4.html
2021-01-26 11:38:45 +00:00
heitbaum
5c6d918ddf iptables: update to 1.8.7
update 1.8.6 to 1.8.7
changelog: https://git.netfilter.org/iptables/log/
2021-01-24 11:12:03 +00:00
heitbaum
bfb06ce4ff libnftnl: update to 1.1.9
update 1.1.8 to 1.1.9
changelog: https://git.netfilter.org/libnftnl/log/
2021-01-24 11:11:42 +00:00
Ian Leonard
3baf91e87d network: automated code cleanup
Signed-off-by: Ian Leonard <antonlacon@gmail.com>
2021-01-19 19:34:12 +00:00