Merge frr from Debian unstable for mantic

Bug #2018072 reported by Bryce Harrington
12
This bug affects 2 people
Affects Status Importance Assigned to Milestone
frr (Ubuntu)
Fix Released
Undecided
Andreas Hasenack

Bug Description

Scheduled-For: Backlog
Upstream: tbd
Debian: 8.4.2-1
Ubuntu: 8.4.2-1ubuntu1

There is nothing yet to merge for frr currently, but this ticket is filed prospectfully for tracking purposes in case a merge does become available later this cycle.

If it turns out this needs a sync rather than a merge, please change the tag 'needs-merge' to 'needs-sync', and (optionally) update the title as desired.

### New Debian Changes ###

frr (8.4.2-1) unstable; urgency=medium

  * new upstream release FRR 8.4.2
  * drop all patches in debian/patches/, they got merged upstream

 -- David Lamparter <email address hidden> Mon, 23 Jan 2023 17:32:02 +0100

frr (8.4.1-2) unstable; urgency=medium

  * commit to git tarball as source instead of dist tarball
  * ditch unneeded sphinx missing files patch
  * fix clippy symbol lookup issue (build SEGV on mips64el)
  * correctly mark :native for libelf-dev & libpython3-dev to fix cross-build
  * use mutex for zserv stats (atomic uint64_t is too wide for 32-bit archs)

 -- David Lamparter <email address hidden> Fri, 06 Jan 2023 14:59:57 +0100

frr (8.4.1-1) unstable; urgency=medium

  * New upstream release FRR 8.4.1 (closes: #1017518)
  * New frr@ systemd service unit to run inside network namespace
  * egrep to grep -E
  * upstream fix ospfd crash (PR 8876) (closes: #981139)
  * upstream fix isisd parsing issues CVE-2022-26125, CVE-2022-26126 and
    babeld parsing issues CVE-2022-26127, CVE-2022-26128, CVE-2022-26129
    (closes: #1008010)
  * upstream fix bgpd out-of-bounds read CVE-2022-37032 (closes: #1021016)
  * upstream fix bgpd UAF CVE-2022-37035 (closes: #1016978)
  * libyang-related pcre3 dep replaced with pcre2 (closes: #1000032)
  * disable ELF magic on mips64el
  * fixed texinfo figure installation directory
  * enable dh_sphinxdoc to get rid of embedded javascript in frr-doc
  * removed bogus iproute dependency choice

 -- David Lamparter <email address hidden> Mon, 02 Jan 2023 14:46:06 +0100

frr (8.1-1) unstable; urgency=medium

  * New upstream release FRR 8.1
  * Upload to unstable.

 -- Ondřej Surý <email address hidden> Sat, 13 Nov 2021 13:32:48 +0100

frr (7.5.1-1) unstable; urgency=medium

  * Update the d/gbp.conf for 7.5.1 release
  * Use wrap-and-sort -a to unify debian/ wrapping and sorting
  * Work around the sphinx-build error that doesn't copy images to texinfo
  * Change the upstream-tag in d/gbp.conf to track the upstream tarballs

 -- Ondřej Surý <email address hidden> Mon, 08 Mar 2021 09:40:19 +0100

frr (7.5-1) unstable; urgency=medium

  * New upstream version 7.5

 -- Ondřej Surý <email address hidden> Sun, 14 Feb 2021 21:38:50 +0100

frr (7.4-2) unstable; urgency=medium

  * Bump libyang dependency to >= 1.0.184-1~
  * Make the autopkgtest more resilient (Closes: #980111)
  * Adjust the ax_python.m4 to hardcode python3.9

 -- Ondřej Surý <email address hidden> Sun, 07 Feb 2021 13:15:07 +0100

frr (7.4-1.1) unstable; urgency=medium

  * Non-maintainer upload.
  * Backport upstream fix for FTBFS with Python 3.9. (Closes: #972767)

 -- Adrian Bunk <email address hidden> Thu, 21 Jan 2021 16:06:12 +0200

frr (7.4-1) unstable; urgency=medium

  [ Ondřej Surý ]
  * Use dh_installinit capabilities to install frr.tmpfile
  * Remove unused debian/watchfrr.rc file
  * Add missing lsof dependency
  * Remove mention of pkg.frr.snmp build profile from debian/README.Debian
  * Make lsb-base a hard dependency
  * Update gbp.conf for 7.4 release
  * Update and simplify d/watch
  * Change the debian source format from 3.0 (git) to 3.0 (quilt)
  * Convert the package to dh compat level 10
  * Add myself to Uploaders
  * Bump standards version to 4.5.0.2 (latest) - no change
  * Use wrap-and-sort -a to unify debian/ wrapping and sorting
  * Work around the sphinx-build error that doesn't copy images to texinfo
    (Properly closes: #955067)
  * Depend on debhelper >= 9.20160709 and drop dh-systemd dependency
    (Closes: #958626)

 -- Ondřej Surý <email address hidden> Mon, 10 Aug 2020 11:50:45 +0200

frr (7.3.1-1) unstable; urgency=medium

  [ David Lamparter ]
  * allow cross-compile with sbuild --host

### Old Ubuntu Delta ###

frr (8.4.2-1ubuntu1) lunar; urgency=medium

  * Merge with Debian unstable. Remaining changes:
    - Fix logging with Ubuntu's unprivileged rsyslog (LP #1958162):
      + d/frr.postinst: change log files ownership
      + d/frr.logrotate: change rotated log file ownership

 -- Andreas Hasenack <email address hidden> Sun, 29 Jan 2023 15:28:40 -0300

Related branches

CVE References

Bryce Harrington (bryce)
Changed in frr (Ubuntu):
status: New → Incomplete
Changed in frr (Ubuntu):
assignee: nobody → Andreas Hasenack (ahasenack)
Revision history for this message
Andreas Hasenack (ahasenack) wrote :

Debian now has 8.4.4-1

Changed in frr (Ubuntu):
status: Incomplete → Triaged
milestone: none → ubuntu-23.07
Changed in frr (Ubuntu):
status: Triaged → In Progress
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package frr - 8.4.4-1ubuntu1

---------------
frr (8.4.4-1ubuntu1) mantic; urgency=medium

  * Merge with Debian unstable (LP: #2018072). Remaining changes:
    - Fix logging with Ubuntu's unprivileged rsyslog (LP #1958162):
      + d/frr.postinst: change log files ownership
      + d/frr.logrotate: change rotated log file ownership
  * Dropped:
    - SECURITY UPDATE: denial of service via bgp_capability_llgr()
      + debian/patches/CVE-2023-31489.patch: check 7 bytes for Long-lived
        Graceful-Restart capability in bgpd/bgp_open.c.
      + CVE-2023-31489
        [Fixed upstream in 8.4.4]
    - SECURITY UPDATE: denial of service via bgp_attr_psid_sub()
      + debian/patches/CVE-2023-31490.patch: ensure stream received has
        enough data in bgpd/bgp_attr.c.
      + CVE-2023-31490
        [Fixed upstream in version 8.4.4]

 -- Andreas Hasenack <email address hidden> Wed, 26 Jul 2023 17:43:05 -0300

Changed in frr (Ubuntu):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.