[Rpm-maint] [rpm-software-management/rpm] rpm 4.20.1.1 security/bugfix release (Issue #3828)

Panu Matilainen notifications at github.com
Mon Jun 23 07:18:24 UTC 2025


pmatilai created an issue (rpm-software-management/rpm#3828)

The new'ish sysusers.d `u!` operation escapes chroot, and that's always a security issue of sorts. AFAICS this would "only" cause a user account on the host to be locked so it could be much worse, but it's an unpleasant situation at any rate, and a DoS of a kind.

So we'll need 4.20.1.1 for this soon: https://github.com/rpm-software-management/rpm/pull/3823

Of course we'll want to scan for other important fixes too but lets keep this minimal - say, max 10 commits or so - and no features at all.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/issues/3828
You are receiving this because you are subscribed to this thread.

Message ID: <rpm-software-management/rpm/issues/3828 at github.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rpm.org/pipermail/rpm-maint/attachments/20250623/d16d6d2f/attachment-0001.htm>


More information about the Rpm-maint mailing list