multipath-tools 0.8.8-1ubuntu1.22.04.1 source package in Ubuntu

Changelog

multipath-tools (0.8.8-1ubuntu1.22.04.1) jammy-security; urgency=medium

  * SECURITY UPDATE: symlink attack
    - debian/patches/CVE-2022-41973.patch: use /run instead of /dev/shm in
      .gitignore, Makefile.inc, libmultipath/defaults.h,
      multipath/Makefile, multipath/multipath.rules.in,
      multipath/tmpfiles.conf.in.
    - debian/multipath-tools.install: install tmpfiles.d/multipath.conf.
    - debian/rules: copy udev rule after build.
    - CVE-2022-41973
  * SECURITY UPDATE: authorization bypass
    - debian/patches/CVE-2022-41974-pre1.patch: fix command completion in
      interactive mode in multipathd/callbacks.c, multipathd/cli.c,
      multipathd/cli_handlers.c, multipathd/main.c.
    - debian/patches/CVE-2022-41974.patch: more robust command parsing in
      multipathd/callbacks.c, multipathd/cli.c, multipathd/cli.h,
      multipathd/cli_handlers.c, multipathd/uxlsnr.c.
    - debian/patches/CVE-2022-41974-2.patch: fix command completion with
      robust parser in multipathd/cli.c, multipathd/cli.h,
      multipathd/uxlsnr.c.
    - debian/patches/CVE-2022-41974-3.patch: add test for command parsing
      in Makefile.inc, tests/Makefile, tests/cli.c, multipathd/cli.h,
      multipathd/cli.c.
    - debian/patches/CVE-2022-41974-4.patch: fix memory leak handling
      invalid commands in multipathd/uxlsnr.c.
    - CVE-2022-41974

 -- Marc Deslauriers <email address hidden>  Fri, 28 Oct 2022 14:43:41 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Jammy
Original maintainer:
Ubuntu Developers
Architectures:
linux-any all
Section:
admin
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Jammy security main admin

Downloads

File Size SHA-256 Checksum
multipath-tools_0.8.8.orig.tar.gz 515.1 KiB ff45ddb18a1effbfbe5712f513dd3b7146c68141091fc1c2489af8d6197026ef
multipath-tools_0.8.8-1ubuntu1.22.04.1.debian.tar.xz 58.6 KiB df2863851c1ba02e0636013b5d29ef9008956274d1d7f594bbe3c950fea8f4f8
multipath-tools_0.8.8-1ubuntu1.22.04.1.dsc 2.7 KiB ba4665548fd7ed479d90a423aa9665bb2b9f7a5594b88998f8edb10633ff8b39

View changes file

Binary packages built by this source

kpartx: create device mappings for partitions

 Kpartx can be used to set up device mappings for the partitions of any
 partitioned block device.
 .
 It is part of the Linux multipath-tools, but is useful on any
 device-mapper using system.

kpartx-boot: Provides kpartx during boot

 This package makes kpartx available during boot to activate partitions

kpartx-dbgsym: debug symbols for kpartx
multipath-tools: maintain multipath block device access

 These tools are in charge of maintaining the disk multipath device maps and
 react to path and map events.
 .
 If you install this package you may have to change the way you address block
 devices. See README.Debian for details.

multipath-tools-boot: Support booting from multipath devices

 This package contains the necessary support for booting from a multipath
 device:
 .
  * copy over multipath.conf and persistent bindings if necessary
  * load the necessary kernel modules
  * detect multipath block devices
 .
 Don't install this package if you're not booting from a multipath device.

multipath-tools-dbgsym: debug symbols for multipath-tools