2026-04-02 14:18:08 I just emailed an awall security bug to security@lists.alpinelinux.org, but it was rejected. Was hoping to keep it private and not on a public mailing list 2026-04-02 14:19:06 anthumchris: security@alpinelinux.org 2026-04-02 14:19:21 thanks, will resend 2026-04-02 14:19:42 You can also create a confidential issue directly in the awall project 2026-04-02 14:29:00 done — thanks ikke 2026-04-02 14:30:02 Oh, I had created it for you as well :D 2026-04-02 14:30:08 I'll close that one 2026-04-03 07:38:15 https://lists.gnu.org/archive/html/info-gnu/2025-12/msg00006.html 2026-04-03 07:39:36 does that make the inetutils-syslogd 2.7 upgrade worthy of being called a security upgrade and should patches/upgrades be backported to stable releases? 2026-04-03 07:39:57 !95357 2026-04-04 03:57:47 "love" your enemies "sanction" your allies - emmy awards to us,uk,russia 2026-04-09 10:17:45 !100429 2026-04-09 10:18:01 https://cryptography.io/en/46.0.7/changelog/ 2026-04-09 10:18:30 should we backport upgrades or patches to stable branches? 2026-04-09 10:30:26 Both 45.0.0 and 46.0.0 have backwards incompatible changes 2026-04-09 10:33:14 So I suppose patching if possible 2026-04-09 10:36:28 4 security fixes in Flatpak, including critical CVE-2026-34078: Complete sandbox escape leading to host file access and code execution in the host context 2026-04-09 10:37:53 not all the backwards incompatible changes are relevant, like dropping python 3.7 support, but yeah 2026-04-09 10:41:59 Yeah, not those, but others are 2026-04-09 19:22:28 hi all, apologies if this has been discussed already, but there's a patch for musl that fixes potential remote DoS attacks against services using musl's iconv() function: https://mastodon.social/@musl@treehouse.systems/116338660226165501 2026-04-09 19:23:17 i'm happy to open and test a MR myself, but with it being such a core package, and me being inexperienced with packaging in alpine, i figure i should ask at least 2026-04-09 19:54:09 MRs are always welcome and then someone will decide if it can be merged 2026-04-09 19:54:30 and this is the right channel for the topic 2026-04-09 20:18:53 bdprom: well, seems like achill went ahead and did that =) 2026-04-09 20:33:36 ah nice :3 2026-04-09 22:49:20 ideas on !98913 and !98982 ? 2026-04-09 22:49:31 failing tests on x86* 2026-04-09 22:58:08 let's see with !100484 !100486 2026-04-09 22:58:32 (cherry-picked from the others) 2026-04-09 23:41:42 MASTER THE ART OF HACKING đŸ•šī¸... (full message at ) 2026-04-10 06:58:49 x86_64 OOMs it seems, perhaps 32-bit needs more RAM as well? 2026-04-10 07:04:04 I doubt that it's the changes in 3.12.13 vs 3.12.12 causing this: https://github.com/python/cpython/compare/v3.12.12...v3.12.13 2026-04-10 21:35:41 is irc dead now? 2026-04-10 21:40:14 havent used irc since about 1998 2026-04-11 12:24:49 !100576 !100577 !100578 2026-04-11 12:27:27 these are bigger version jumps (from 2.76, 2.71 and 2.70), would just want some extra eyes to assess there are no regressions 2026-04-11 15:03:24 the armv7 bus error is interesting. I wonder why that happens 2026-04-11 15:03:32 thanks for following up those! 2026-04-11 15:10:54 ncopa: tests are disabled on armv7 from 3.22 and onwards, I added that part to the 3.21 and 3.20 MRs 2026-04-11 15:19:42 oh.. ok 2026-04-11 15:20:11 we should probably fix it? 2026-04-11 16:34:58 I'm curious wether this is just an armv7 CI issue and, regardless, why 2026-04-15 18:48:09 ncopa: !100827 2026-04-16 03:52:39 CVE-2026-2219 should not affect our dpkg since we didn't enable libzstd support. do i still need to mention this CVE in APKBUILD? 2026-04-16 04:37:13 qaqland: We can mention it under version 0 2026-04-20 04:32:32 hi 2026-04-25 11:48:55 we probably need to backport patches (not upgrade) to stable releases for main/botan3 https://botan.randombit.net/security.html 2026-04-25 12:55:40 I think the same may go for main/pjproject 2026-04-25 13:14:58 and main/strongswan 2026-04-27 08:18:58 https://gitlab.alpinelinux.org/alpine/aports/-/merge_requests/?label_name%5B%5D=tag%3Asecurity 2026-04-29 09:37:20 patches for linux: 2026-04-29 09:37:22 https://xenbits.xen.org/xsa/advisory-485.html 2026-04-29 09:37:27 https://xenbits.xen.org/xsa/advisory-487.html 2026-04-29 09:40:11 ncopa: sorry for not mentioning before you did the upgrades, perhaps there will be new patch releases real ssoon 2026-04-29 10:07:01 achill: I'm getting !101585 in 2026-04-29 10:07:29 not sure if we can just backport the upgrade to 3.23-stable or need to backport patches 2026-04-29 10:08:36 older stable releases are at 8.14.1 with patches for fixes from 8.15 2026-04-29 10:09:50 a lot of things have happened in between, support dropped for various things, so we probably want to backport patches for 3.20 through 3.22 2026-04-29 11:30:45 omni: there are breaking changes 2026-04-29 11:32:11 !101508 2026-04-29 21:11:59 i'm seeing some concerns on the busybox mailing list that the latest commits look both AI generated and low quality 2026-04-29 21:12:42 i just thought i'd let you know. since low quality for C code to me sounds like possibly risky. however, i didn't evaluate the commits myself yet 2026-04-29 22:00:03 At the same time there are more posts on the mailing list than there should be 2026-04-29 23:13:59 the mailing list has basically been token over by a nut 2026-04-29 23:14:18 i wouldn't pay much attention to it at all, the guy is operating a fork that he gives the impression to contributors is official 2026-04-29 23:14:30 i haven't seen anything indicating actual commits in busybox.git are bad 2026-04-29 23:22:16 ikke: right, I remember reading that, how about upgrading to 8.18.0 and apply patches on top? (for 3.23-stable) 2026-04-29 23:41:52 looks like we can nack several curl CVEs due to various reasons 2026-04-29 23:53:10 in case this may be unpatched in alpine still: https://copy.fail/ CVE-2026-31431 seems to be local privilege escalation using a kernel crypto api bug. the reproducer looks fishy with obfuscated code i wouldnt wanna run it, but it mentions the kernel commit with the fix: a664bf3d603d and the bug seems to be in algif_aead, which at least on my raspberry pi alpine kernel i dont see loaded but af_alg is so perhaps the module just has a 2026-04-29 23:53:10 different name. 2026-04-29 23:58:26 regarding the suspicious busybox commits, i looked at one of them now: https://github.com/vda-linux/busybox_mirror/commit/0519429ea166949f2d8bee9cdbd70bf986b7b683#diff-4c6fe480abdfc4de2c8f13234414dd92c46266731e1ab81375078a7015304676R5800-R5801 and it does look a little weird, the &&) in there 2026-04-30 00:12:48 https://github.com/torvalds/linux/commit/a664bf3d603d the commit in question @ algif_aead 2026-04-30 06:29:04 https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/T/#u (2026-04-22) says CVE-2026-31431 ("copyfail") was fixed in 6.18.22 (upgraded to 2026-04-11) 2026-04-30 06:37:50 omni: If you can find patches that apply cleanly on those branches, we could do that 2026-04-30 06:39:17 ikke: curl? I was trying with 8.19 there earlier.. perhaps there's something in other distros 2026-04-30 06:39:31 Yes, for url 2026-04-30 06:39:33 Curl 2026-04-30 08:07:33 I think linux 6.12 and 6.6 may still be vulnerable to CVE-2026-31431, so linux-lts in 3.20 through 3.22-stable 2026-04-30 08:11:28 Yeah, I've read the patches do not apply to those branches, it uses a kernel api that has been added later and thus not available in those versions 2026-04-30 08:13:30 tbh i think we can just wait what the linux-stable team comes up with 2026-04-30 08:13:48 alternatively we can say "go unload this module" or so 2026-04-30 08:14:11 Is it configured for us as a module? (Rhel has it as built-in) 2026-04-30 08:14:11 if attempting to backport, parhaps not just https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8 (the fix) but also https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=153d5520c3f9fd62e71c7e7f9e34b59cf411e555 (follow-up change) 2026-04-30 08:18:19 kernel releases are coming soon: https://www.openwall.com/lists/oss-security/2026/04/30/12 2026-04-30 08:18:20 ikke: looks like it, CONFIG_CRYPTO_AEAD=m 2026-04-30 08:21:16 And CONFIG_CRYPTO_USER_API_AEAD? 2026-04-30 08:21:32 CONFIG_CRYPTO_USER_API_AEAD=m 2026-04-30 08:22:07 We could blacklist those modules possibly? 2026-04-30 08:22:28 Not sure about the consequences. I think there is some IPSEC feature that relies on it 2026-04-30 08:22:35 (I read about it) 2026-04-30 08:24:22 seems like iwd does =( 2026-04-30 08:25:00 Oh yeah, read about it indeed 2026-04-30 09:51:40 linux 6.12.85 and 6.6.137 just dropped, with fixes for CVE-2026-31431 2026-04-30 09:52:16 as well as XSA-485 and XSA-487 2026-04-30 09:58:21 oh the fix was never in 6.12 and 6.6 2026-04-30 09:58:22 nasty 2026-04-30 09:58:25 Yes 2026-04-30 09:58:33 im working on it 2026-04-30 09:58:54 ncopa: I read suggestions to even completely disable CONFIG_CRYPTO_USER_API_* config settings 2026-04-30 09:59:15 i suppose that will break things like dmcrypt? 2026-04-30 09:59:44 From what I read, it's only used by IPSEC, and only affects high-traffic (25gbit) servers 2026-04-30 10:14:56 https://lkml.org/lkml/2026/4/29/2166 2026-04-30 11:24:24 I wonder if we can disable crypto user api, due to iwd 2026-04-30 11:54:47 WhyNotHugo: https://tpaste.us/ZKoa 2026-04-30 11:59:53 I have algif_aead blacklisted and iwd works for me. 2026-04-30 12:00:13 Will check if some niche scenario relies on it. 2026-04-30 12:02:17 WhyNotHugo: what about CONFIG_CRYPTO_USER_API_AEAD? 2026-04-30 12:02:36 well, that's a config, but talking about the respective module 2026-04-30 12:14:28 dm-crypt calls the kernel crypto API directly. It doesn't depend on CONFIG_CRYPTO_USER_API at all. 2026-04-30 12:24:54 iwd requires the following: https://git.kernel.org/pub/scm/network/wireless/iwd.git/tree/tools/test_runner_kernel_config 2026-04-30 12:25:08 CONFIG_CRYPTO_USER_API_AEAD is used for EAP-TLS and EAP-PEAP 2026-04-30 14:58:22 !101656 2026-04-30 15:39:02 ncopa: are the currently available kernels in 3.19-3.23/edge fixed now? 2026-04-30 15:39:12 (to extract the list from fixed kernel versions) 2026-04-30 15:42:01 yes, I think so 2026-04-30 15:42:09 im working on arm builder right now 2026-04-30 15:45:16 ok 2026-04-30 15:59:07 Sertonix[m]: I'll likely do a release of fortify-headers next week, if that's ok with you :) 2026-04-30 15:59:45 alpine edge is anyway in a toolchain freeze right now 2026-04-30 16:00:14 not sure what changes you have, but only if they are trivial they'll reach 3.24 2026-04-30 16:00:45 bugfixes and low-impact stuff 2026-04-30 16:01:19 I don't want to implement anything major/groundbreaking before having it in Alpine without any patches and running without issues for a handful of months 2026-04-30 16:01:33 not that there is anything major nor groundbreaking to add to be honest, it's a pretty boring software 2026-04-30 16:02:13 okay 2026-04-30 16:02:50 (maybe some Microsoft Copilot integration. "it looks like you're trying to use strcpy, please consider using the safer strcpy_s variant, and to save your files on OneDrive") 2026-04-30 16:04:51 lol 2026-04-30 16:05:22 yeah lets do that 2026-04-30 18:13:51 just a reminder that CVE-2026-31431 was fixed for linux-lts in edge and 3.23 the 11th of April with 6.18.22 2026-04-30 18:14:24 omni: was a patch applied? 2026-04-30 18:14:44 or was that version already fixed? 2026-04-30 18:14:54 it was in the release 2026-04-30 18:14:56 ok 2026-04-30 18:15:11 https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/T/#u 2026-04-30 18:15:38 Thanks, updating my fixed kernel versions list 2026-04-30 18:16:01 it just took till today to be backported to older longterm branches (where 6.12 and 6.6 are relevant to us) 2026-04-30 18:17:18 also in the changelog https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.18.22 but didn't have a public CVE nor vanity name yet