CVE-2021-2389 & CVE-2021-2372 affect MariaDB in Ubuntu

Bug #1939188 reported by Otto Kekäläinen
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
mariadb-10.5 (Ubuntu)
Fix Released
Medium
Paulo Flabiano Smorigo

Bug Description

According to https://mariadb.com/kb/en/security/ the latest minor MariaDB releases include security fixes.

I am working on updates for all maintained Ubuntu versions for MariaDB:
- mariadb-10.3 in Focal
- mariadb-10.5 in Hirsute

MariaDB 10.5 in Impish will automatically import the new version from Debian Sid once available.

Security sponsor note this: https://wiki.ubuntu.com/SecurityTeam/PublicationNotes#Sponsoring_MariaDB_Security_Updates

CVE References

Otto Kekäläinen (otto)
information type: Public → Public Security
Revision history for this message
Otto Kekäläinen (otto) wrote :

The 10.3 series update for 20.04 is now available.

Please use git-buildpackage to fetch and build from the ubuntu-20.04 branch at https://salsa.debian.org/mariadb-team/mariadb-10.3/tree/ubuntu-20.04

The repository uses pristine-tar, so there is no need to separately download the sources. You can just check the signature/SHA1SUM directly from the git-buildpackage generated tarball.

Test builds and testsuite passed on all platforms at
https://launchpad.net/~mysql-ubuntu/+archive/ubuntu/mariadb-10.3/+builds?build_text=&build_state=all

Debdiffs can be created directly from the repo like in a local clone with 'git diff <tag1>..<tag2> debian/'

Changelog:

mariadb-10.3 (1:10.3.31-0ubuntu0.20.04.1) focal-security; urgency=medium

  * SECURITY UPDATE: New upstream version 10.3.31 includes fixes for the
    following security vulnerabilities (LP: #1939188):
    - CVE-2021-2389
    - CVE-2021-2372

 -- Otto Kekäläinen <email address hidden> Fri, 06 Aug 2021 22:19:19 -0700

Revision history for this message
Otto Kekäläinen (otto) wrote (last edit ):

The 10.5 series update for 21.04 is now available.

Please use git-buildpackage to fetch and build from the ubuntu-21.04 branch at https://salsa.debian.org/mariadb-team/mariadb-10.5/tree/ubuntu-21.04

The repository uses pristine-tar, so there is no need to separately download the sources. You can just check the signature/SHA1SUM directly from the git-buildpackage generated tarball.

Test builds and testsuite passed on all platforms at
https://launchpad.net/~mysql-ubuntu/+archive/ubuntu/mariadb-10.5/+builds?build_text=&build_state=all

Debdiffs can be created directly from the repo like in a local clone with 'git diff <tag1>..<tag2> debian/'

Changelog:

mariadb-10.5 (1:10.5.12-0ubuntu0.21.04.1) hirsute-security; urgency=medium

  * New upstream version 10.5.12. Includes security fixes for:
    - CVE-2021-2389
    - CVE-2021-2372
  * Drop patches applied upstream in MariaDB S3 plugin

 -- Otto Kekäläinen <email address hidden> Sun, 08 Aug 2021 20:59:22 -0700

description: updated
Revision history for this message
Otto Kekäläinen (otto) wrote :

Groovy went out of support in July, so I will not prepare any update of mariadb-10.3 for Groovy.

Bionic has mariadb-10.1, which is no longer maintained by upstream.

I am all done. Please take it from here security sponsors!

Changed in mariadb-10.5 (Ubuntu):
assignee: nobody → Paulo Flabiano Smorigo (pfsmorigo)
Revision history for this message
Paulo Flabiano Smorigo (pfsmorigo) wrote :

Both 10.3 (focal) and 10.5 (hirsute) updates were released yesterday
https://ubuntu.com/security/notices/USN-5022-2

Changed in mariadb-10.5 (Ubuntu):
importance: Undecided → Medium
status: New → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.