• devuan-packages
  • util-linux
  • Issues
  • #29

Closed
Open
Opened 2018-03-11T15:03Z by igor80 @igor80

Latest ascii-security version 2.29.2-1+deb9u1 will not get upgraded

Hi,

The latest security update of util-linux packages will not get installed.

$ apt policy util-linux
util-linux:
  Installed: 2.29.2-1+devuan2
  Candidate: 2.29.2-1+devuan2
  Version table:
 *** 2.29.2-1+devuan2 500
        500 http://pkgmaster.devuan.org/merged ascii/main amd64 Packages
        100 /var/lib/dpkg/status
     2.29.2-1+devuan1 500
        500 http://pkgmaster.devuan.org/devuan ascii-proposed/main amd64 Packages
     2.29.2-1+deb9u1 500
        500 http://pkgmaster.devuan.org/merged ascii-security/main amd64 Packages

I am aware that util-linux is one of the core devuanized packages but I wonder if this is expected or not.

Thanks,

-- igor

Please solve the reCAPTCHA

We want to be sure it is you, please confirm you are not a robot.

  • KatolaZ
    KatolaZ @KatolaZ · 2018-03-12T11:02Z

    Any devuanised package takes precedence on the corresponding one coming from Debian. In this case, the devuanised version is the same available from ascii-security (i.e., it includes any fix introduced there), so there is nothing to worry about.

    HTH

    (I think we could close this, right?)

    Edited by KatolaZ 2018-03-12T11:03Z
  • igor80
    igor80 @igor80 · 2018-03-13T09:00Z

    Are you really sure this is the same? 2.29.2-1+deb9u1 was available on March 11 only

    https://lists.debian.org/debian-changes/2018/03/msg00068.html

    Subject: Accepted util-linux 2.29.2-1+deb9u1 (source) into proposed-updates->stable-new, proposed-updates From: Salvatore Bonaccorso carnil@debian.org Date: Sun, 11 Mar 2018 21:02:07 +0000

  • igor80
    igor80 @igor80 · 2018-03-21T10:17Z

    FYI the patch bash-completion-umount-use-findmnt-escape-a-space-in.patch is not in the devuanised package.

    Devuan ASCII is vulnerable to CVE-2018-7738.

  • KatolaZ
    KatolaZ @KatolaZ · 2018-05-04T23:16Z

    This was fixed in version 2.29.2-1+devuan2.1, already available from the repos. closing.

  • KatolaZ @KatolaZ closed · 2018-05-04T23:16Z

    closed

  • igor80
    igor80 @igor80 · 2018-05-07T15:12Z

    Thank you very much

  • igor80 @igor80 mentioned in issue procps#5 (closed) · 2018-05-23T08:21Z

    mentioned in issue procps#5 (closed)