USN-4195-1 also affects MariaDB

Bug #1852109 reported by Otto Kekäläinen
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
mariadb-10.1 (Ubuntu)
Fix Released
High
Paulo Flabiano Smorigo
mariadb-10.3 (Ubuntu)
Fix Released
High
Paulo Flabiano Smorigo

Bug Description

I am working on updates for all maintained Ubuntu versions for MariaDB 10.1 and 10.3.

CVE References

Otto Kekäläinen (otto)
Changed in mariadb-10.0 (Ubuntu):
status: New → Won't Fix
no longer affects: mariadb-10.0 (Ubuntu)
Changed in mariadb-10.1 (Ubuntu):
assignee: nobody → Otto Kekäläinen (otto)
Changed in mariadb-10.3 (Ubuntu):
assignee: nobody → Otto Kekäläinen (otto)
Changed in mariadb-10.1 (Ubuntu):
importance: Undecided → High
Changed in mariadb-10.3 (Ubuntu):
importance: Undecided → High
Changed in mariadb-10.1 (Ubuntu):
status: New → In Progress
Changed in mariadb-10.3 (Ubuntu):
status: New → In Progress
Revision history for this message
Otto Kekäläinen (otto) wrote :

In the works:
mariadb-10.1 for bionic
mariadb-10.3 for disco and eoan

Focal can just sync from Debian unstable.

Revision history for this message
Otto Kekäläinen (otto) wrote :

The 10.1 series update for 18.04 is now available.

Please use git-buildpackage to fetch and build from the ubuntu-18.04 branch at https://salsa.debian.org/mariadb-team/mariadb-10.1/tree/ubuntu-18.04

The repository uses pristine-tar, so there is no need to separately download the sources. You can just check the signature/SHA1SUM directly from the git-buildpackage generated tarball.

Test builds and testsuite passed on all platforms at
https://launchpad.net/~mysql-ubuntu/+archive/ubuntu/mariadb-10.1/+builds?build_text=&build_state=all

Debdiffs can be created directly from the repo like in a local clone with 'git diff <tag1>..<tag2> debian/'

Security sponsor note this: https://wiki.ubuntu.com/SecurityTeam/PublicationNotes#Sponsoring_MariaDB_Security_Updates

Revision history for this message
Otto Kekäläinen (otto) wrote :

The 10.3 series update for 19.04 is now available.

Please use git-buildpackage to fetch and build from the ubuntu-19.04 branch at https://salsa.debian.org/mariadb-team/mariadb-10.3/tree/ubuntu-19.04

The repository uses pristine-tar, so there is no need to separately download the sources. You can just check the signature/SHA1SUM directly from the git-buildpackage generated tarball.

Test builds and testsuite passed on all platforms at
https://launchpad.net/~mysql-ubuntu/+archive/ubuntu/mariadb-10.3/+builds?build_text=&build_state=all

Debdiffs can be created directly from the repo like in a local clone with 'git diff <tag1>..<tag2> debian/'

Security sponsor note this: https://wiki.ubuntu.com/SecurityTeam/PublicationNotes#Sponsoring_MariaDB_Security_Updates

Revision history for this message
Otto Kekäläinen (otto) wrote :

The 10.3 series update for 19.10 is now available.

Please use git-buildpackage to fetch and build from the ubuntu-19.10 branch at https://salsa.debian.org/mariadb-team/mariadb-10.3/tree/ubuntu-19.10

Changed in mariadb-10.1 (Ubuntu):
assignee: Otto Kekäläinen (otto) → Paulo Flabiano Smorigo  (pfsmorigo)
Changed in mariadb-10.3 (Ubuntu):
assignee: Otto Kekäläinen (otto) → Paulo Flabiano Smorigo  (pfsmorigo)
Revision history for this message
Otto Kekäläinen (otto) wrote :

Today https://usn.ubuntu.com/4195-1/ was released, which covers CVE-2019-2974 and CVE-2019-2938, also listed here.

summary: - CVE-2019-2974: MariaDB & MySQL
+ USN-4195-1 also affects MariaDB
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package mariadb-10.1 - 1:10.1.43-0ubuntu0.18.04.1

---------------
mariadb-10.1 (1:10.1.43-0ubuntu0.18.04.1) bionic-security; urgency=high

  * SECURITY UPDATE: New upstream version 10.1.43 includes a fix for a
    regression introduced in the previous release:
    - MDEV-20987: InnoDB fails to start when FTS table has FK relation
    Previous release 10.1.41 includes fix for the following security
    vulnerability (LP: #1852109):
    - CVE-2019-2974

 -- Otto Kekäläinen <email address hidden> Mon, 11 Nov 2019 18:49:05 +0100

Changed in mariadb-10.1 (Ubuntu):
status: In Progress → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package mariadb-10.3 - 1:10.3.20-0ubuntu0.19.10.1

---------------
mariadb-10.3 (1:10.3.20-0ubuntu0.19.10.1) eoan-security; urgency=high

  * SECURITY UPDATE: New upstream version 10.3.20 includes a fix for a
    regression introduced in the previous release:
    - MDEV-20987: InnoDB fails to start when FTS table has FK relation
    Previous release 10.3.19 includes fix for the following security
    vulnerability (LP: #1852109):
    - CVE-2019-2938
    - CVE-2019-2974
  * Update symbols to match latest libmariadb_3
  * Drop systemd service patch applied upstream
  * Update Maintainers field for Ubuntu releases
  * Remove Salsa-CI integration as not applicable in this Ubuntu branch

 -- Otto Kekäläinen <email address hidden> Tue, 12 Nov 2019 15:08:54 +0200

Changed in mariadb-10.3 (Ubuntu):
status: In Progress → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package mariadb-10.3 - 1:10.3.20-0ubuntu0.19.04.1

---------------
mariadb-10.3 (1:10.3.20-0ubuntu0.19.04.1) disco-security; urgency=high

  * SECURITY UPDATE: New upstream version 10.3.20 includes a fix for a
    regression introduced in the previous release:
    - MDEV-20987: InnoDB fails to start when FTS table has FK relation
    Previous release 10.3.19 includes fix for the following security
    vulnerability (LP: #1852109):
    - CVE-2019-2938
    - CVE-2019-2974
  * Drop systemd service patch applied upstream
  * Update symbols to match latest libmariadb_3
  * Remove Salsa-CI integration as not applicable in this Ubuntu branch

 -- Otto Kekäläinen <email address hidden> Tue, 12 Nov 2019 14:44:39 +0200

Changed in mariadb-10.3 (Ubuntu):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.