Latest ascii-security version 2.29.2-1+deb9u1 will not get upgraded
The latest security update of util-linux packages will not get installed.
$ apt policy util-linux util-linux: Installed: 2.29.2-1+devuan2 Candidate: 2.29.2-1+devuan2 Version table: *** 2.29.2-1+devuan2 500 500 http://pkgmaster.devuan.org/merged ascii/main amd64 Packages 100 /var/lib/dpkg/status 2.29.2-1+devuan1 500 500 http://pkgmaster.devuan.org/devuan ascii-proposed/main amd64 Packages 2.29.2-1+deb9u1 500 500 http://pkgmaster.devuan.org/merged ascii-security/main amd64 Packages
I am aware that util-linux is one of the core devuanized packages but I wonder if this is expected or not.
Any devuanised package takes precedence on the corresponding one coming from Debian. In this case, the devuanised version is the same available from ascii-security (i.e., it includes any fix introduced there), so there is nothing to worry about.
(I think we could close this, right?)Edited by KatolaZ
Are you really sure this is the same? 2.29.2-1+deb9u1 was available on March 11 only
Subject: Accepted util-linux 2.29.2-1+deb9u1 (source) into proposed-updates->stable-new, proposed-updates From: Salvatore Bonaccorso email@example.com Date: Sun, 11 Mar 2018 21:02:07 +0000
FYI the patch bash-completion-umount-use-findmnt-escape-a-space-in.patch is not in the devuanised package.
Devuan ASCII is vulnerable to CVE-2018-7738.
This was fixed in version 2.29.2-1+devuan2.1, already available from the repos. closing.
Thank you very much