[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

Fantu 1912060 at bugs.launchpad.net
Wed Jan 27 21:39:44 UTC 2021


the newer upstream changes you linked is bigger, for security update only small build fix of first patch absolutely necessary I suppose ubuntu security team would consider (along with the third patch with security fix).
however it would be good to have a certain answer before continuing to invest time and see days go by. also probably before the weekend I will not have time to test new builds (for groovy I also have to create a new vm, I have no system or vm with it at the moment)
and from what I understand for now they will not consider fixes for focal if there isn't be also fixes for all later supported versions
I would also like to go without fail with the next patches and tests (and waste time), I would like to spend as much time as possible to do more tests and possible fixes to the packages that I help to maintan in debian before the bullseye freeze in the free time of the next days

-- 
You received this bug notification because you are a member of Ubuntu
Sponsors Team, which is subscribed to the bug report.
https://bugs.launchpad.net/bugs/1912060

Title:
  [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
  cause security issue for cinnamon

Status in caribou package in Ubuntu:
  Fix Released
Status in caribou source package in Focal:
  In Progress
Status in caribou source package in Groovy:
  In Progress
Status in caribou source package in Hirsute:
  Fix Released
Status in caribou package in Debian:
  Unknown

Bug description:
  [Impact]
  There is a regression after solving CVE-2020-25712 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25712) in xserver (https://gitlab.freedesktop.org/xorg/xserver/-/commit/87c64fc5b0db9f62f4e361444f4b60501ebf67b9) that make caribou crash pressing ē.

  In cinnamon-screensaver (>=4.2 where integrated the virtual keyboard)
  crash of caribou cause also screensaver crash and make possible access
  without insert the correct password, this introduced a security issue.

  [Test Case]
  In cinnamon-screensaver (>=4.2) pressing ē (after long press on e) in virtual keyboard (button at the bottom of the screen in the center) make caribou (and the screensaver) crash and access without insert the correct password.

  [Where problems could occur]
  The following versions of ubuntu are affected by the security caused by caribou crash of this issue:
  - Focal (cinnamon 4.4)
  - Groovy (cinnamon 4.6)
  - Hirsute (bug solved with 0.4.21-7.1)

  The patch attached in comment #10 (for Focal) have the same changes of 0.4.21-7.1 (debian unstable, debian testing and Hirsute) and same patches are used also in some other distros that already applied the fix faster (as security issue) and 1 week or more went by without experiencing regressions at the moment.
  The patch is already tested in Focal, can be used also in Groovy (only changing focal->groovy).

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions



More information about the Ubuntu-sponsors mailing list