andi- changed the topic of #nixos-security to: Vulnerability Roundup Issues: + | Currently supported releases: unstable (master), 20.09, 20.03 (until 27th of November)
<hexa-> patched in linux 5.9.2
<hexa-> also in 5.4.72
<hexa-> oh well
<hexa-> Subject: Buffer Overflow in raptor widely unfixed in Linux distros
<hexa-> tl;dr: debian fixed this bug after 3y, since the upstream was unresponsive and a CVE was never requested
<hexa-> Hanno Böck, who discovered the issue, says this
<hexa-> > Maybe noteworthy is that this didn't get a CVE in 2017. It seems many
<{^_^}> error: syntax error, unexpected IN, expecting ')', at (string):359:48
<hexa-> distros rely on CVEs to get a process of backporting fixes rolling.
<hexa-> Given the fluctuating reliability of CVE assignments not sure this is
<hexa-> wise. I have now requested a CVE (CVE-2017-18926).
<hexa-> I learned of this issue from DSA and fixed it promptly in #103134, which was today merged and backported
<{^_^}> (by mweinelt, 5 days ago, merged): librdf_raptor2: add patch for CVE-2017-18926
<joepie91> "The Node.js project will release new versions of 15.x, 14.x and 12.x on or shortly after Monday, November 16th, 2020. These releases will fix: * One high severity issue"
