Sync etcd 3.4.30-1 (universe) from Debian unstable (main)

Bug #2055357 reported by Shengjing Zhu
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
etcd (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Please sync etcd 3.4.30-1 (universe) from Debian unstable (main)

Explanation of the Ubuntu delta and why it can be dropped:
  * No-change rebuild with Go 1.21.
  * No-change rebuild with Go 1.21.
  * SECURITY UPDATE: debug leaks credentials
    - debian/patches/CVE-2021-28235.patch: blanks out password
    - CVE-2021-28235

CVE-2021-28235 is fixed in upstream version 3.4.25.

Changelog entries since current noble version 3.4.23-4ubuntu2:

etcd (3.4.30-1) unstable; urgency=medium

  * Team upload
  * New upstream version 3.4.30
    + CVE-2021-28235 (fixed in 3.4.25): Clearing password after authenticating
      the user.
    + CVE-2023-32082 (fixed in 3.4.26): LeaseTimeToLive API may return keys to
      clients which have no read permission on the keys

 -- Shengjing Zhu <email address hidden> Wed, 28 Feb 2024 17:43:49 +0800

etcd (3.4.23-6) unstable; urgency=medium

  * Team upload
  * Add a patch to skip flaky test that failed on 3/10 buildds

 -- Mathias Gibbens <email address hidden> Sat, 17 Feb 2024 00:31:39 +0000

etcd (3.4.23-5) unstable; urgency=medium

  * Team upload
  * d/control:
    - Replace transitional golang-goprotobuf-dev package
    - Allow golang-github-golang-protobuf-1-5-dev as optional Depends
  * Add a patch to skip tests that fail in some environments

 -- Mathias Gibbens <email address hidden> Fri, 16 Feb 2024 22:07:53 +0000

CVE References

Shengjing Zhu (zhsj)
Changed in etcd (Ubuntu):
importance: Undecided → Wishlist
Revision history for this message
Sergio Durigan Junior (sergiodj) wrote :

This bug was fixed in the package etcd - 3.4.30-1
Sponsored for Shengjing Zhu (zhsj)

---------------
etcd (3.4.30-1) unstable; urgency=medium

  * Team upload
  * New upstream version 3.4.30
    + CVE-2021-28235 (fixed in 3.4.25): Clearing password after authenticating
      the user.
    + CVE-2023-32082 (fixed in 3.4.26): LeaseTimeToLive API may return keys to
      clients which have no read permission on the keys

 -- Shengjing Zhu <email address hidden> Wed, 28 Feb 2024 17:43:49 +0800

etcd (3.4.23-6) unstable; urgency=medium

  * Team upload
  * Add a patch to skip flaky test that failed on 3/10 buildds

 -- Mathias Gibbens <email address hidden> Sat, 17 Feb 2024 00:31:39 +0000

etcd (3.4.23-5) unstable; urgency=medium

  * Team upload
  * d/control:
    - Replace transitional golang-goprotobuf-dev package
    - Allow golang-github-golang-protobuf-1-5-dev as optional Depends
  * Add a patch to skip tests that fail in some environments

 -- Mathias Gibbens <email address hidden> Fri, 16 Feb 2024 22:07:53 +0000

Changed in etcd (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.