Skip to content

Commit f222a71

Browse files
Flatcar Buildbotdongsupark
authored andcommitted
portage-stable/metadata: Monthly GLSA metadata updates
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Signed-off-by: Dongsu Park <[email protected]>
1 parent ade059d commit f222a71

File tree

5 files changed

+61
-19
lines changed

5 files changed

+61
-19
lines changed
Lines changed: 18 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -1,23 +1,24 @@
11
-----BEGIN PGP SIGNED MESSAGE-----
22
Hash: SHA512
33

4-
MANIFEST Manifest.files.gz 605865 BLAKE2B bcadc158253762e9f24c9e6b055b713a9641d9bfc450941217534a559d82b06bbcb49cffa8d81ca2f49f67ef4ee9530b6f3fe207bd5cb748ba4d010bf5f05a43 SHA512 0a179d9b6436cf36bf8fe75f2d424c5e5a2787d4f2be30bec99d500009833c9172e6703303a8e695c1b53afa286a8aeaa479d0807e86f5b0a383be84bc9c6bbe
5-
TIMESTAMP 2025-12-01T06:40:11Z
4+
MANIFEST Manifest.files.gz 606026 BLAKE2B f642a7d3238c8998aee627a1b7086431eb88df4678fdf42f7ddf8d8bb6de107a02fae7c557568660cc9f04cb9ed135534cc32f129482ba4da102bb96be7e68a9 SHA512 aa4b68d334da5329457cfc76655ce927a51c26cff8774aed431df0f4711bf41c231eea1647511c9cabfd8eabec4b84637a0f0f2ccc3d138d509d72522dbd32d7
5+
TIMESTAMP 2026-01-01T06:40:27Z
66
-----BEGIN PGP SIGNATURE-----
77

8-
iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAmktOEtfFIAAAAAALgAo
9-
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEUx
10-
RDZBQkI2M0JGQ0ZCNEJBMDJGREYxQ0VDNTkwRUVBQzkxODkyNTAACgkQ7FkO6skY
11-
klDI2A//f1DEIxwY5RAteoK8kAD1VUen5rTkm8/Ed7BQleONRh4qnYK6ic9G05Ei
12-
nleWa6HgOpMPUPv4AR+xx6vxwBH06sKb2Nwc+dLX0KgMolBryTLz50N1ZDJ6FvLf
13-
CagByOIXykQt0q6ktR3Px+F6nHupywQxquJnMAUMH8sf1UPD2qAMG6peBXc0BIeJ
14-
sJ9+lm8ZCU0SAS1jQeLdwoLTfqlOuIMHjdtRYNbqqXc/KVebVl+rzDWadOUCD938
15-
P2idhdguAtBYc2KtV+XHKdQfSPsujLoWRsS3/nxBj7qAwIobT8o48hDOdQ8vlldE
16-
ktXxWIdtT2IZL0RbHfwNa9oh7etO/63nGWfZ9/WVoXj5m2MnqM4ZqNINfCpyk4R8
17-
jtfnQ8YEPk06yfwn/gk4iTgsjU8BTKtQJ8HvIwxQqbCQUXBxeebAPY6wEcO3sN9L
18-
j4dxu1d9gRBtOdzIngnqhLDVc12gDQQYZsmI0WcF8gYRLD3INyyzUBkOQHYCP39q
19-
kGy3x7er7vEPbHWgvmY5FI6twYyGBJRC01Bl7023JAk3s+AKKShiUi1nFyLb26ix
20-
Gwh/vijlztJ5eoqz+MvBosojhKJLaQ5XRMha8z3Hnm26o0dA2h/gW3RDMdzwFFRj
21-
I3YXZvYvS8Fr/vzzlrdQ3mf2nhjS0j8y2kf/qeG3H3eFpW3zWvo=
22-
=4q7u
8+
iQKuBAEBCgCZFiEE4dartjv8+0ugL98c7FkO6skYklAFAmlWFtsbFIAAAAAABAAO
9+
bWFudTIsMi41KzEuMTEsMiwyXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25z
10+
Lm9wZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRFMUQ2QUJCNjNCRkNGQjRCQTAyRkRG
11+
MUNFQzU5MEVFQUM5MTg5MjUwAAoJEOxZDurJGJJQGU0P+Mj6Fa4IzlNvGfztJ3vt
12+
Mgacid6hW8pHl6WnEcBrVUsMw+QXVZmJNeC1erVZ7duOu/VUDD/y787YPM5CAwYN
13+
fKI5DIrbUvb4vl8r71O6cC0a+7d8t5FERwYkqBwQEHlCJZzy6BIfOswaPdUqyl0m
14+
FS12GwelAZ6vHM1BqFzwA2vcUcREsaSpos9+QUCKRPeQRG7PGb5pWqiLIa+fgnoz
15+
pabOe3fSzVY+SqSVZ2ZzC7QVNPLdmjk5JTK7yp+KQRwNY5Tx0DEGkDFtPv5Lxo+R
16+
zRTCdzL+KmXlpfAYeV21hNbYqCYNJl+/IWts7rr0ykONvHwQpY4qUAtlvsBsTqLg
17+
dJvfIOkV8ILr5vlW+MoPyyuV5ATWdLQow3SkWNUpXuBBH/h6vpM8CGH5gg+eMpwB
18+
v8vVKfc87XdPa+OhBwy+DJCyyWG4weFK5sOZbT1mM0K72ZoHCNuolVwFIfKJvJ3Z
19+
8DWkAq+w6U4ft1nx25TRs0o9/uXkTsLIkJgbeThccuEo5EYLykEmRJ0V8BH4Y5Hc
20+
VhFtafFPtg87bQx8h2M/f0LsFcr6X2R58FIWyt/WRHdfG7G3q6OxF/nFO/djQF2t
21+
0R7XXtN3UTQ+XvSzNG25s6QUP8LL2wGKbLsmaU5fBXTW/44Zn9wDdKMdSVNQaAmi
22+
G6SqbKPoKyQY4uI2gWyvxl0=
23+
=tC7e
2324
-----END PGP SIGNATURE-----
Binary file not shown.
Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
<?xml version="1.0" encoding="UTF-8"?>
2+
<!DOCTYPE glsa SYSTEM "http://www.gentoo.org/dtd/glsa.dtd">
3+
<glsa id="202512-01">
4+
<title>GnuPG: Arbitrary Code Execution</title>
5+
<synopsis>A vulnerability has been discovered in GnuPG, which can lead to arbitrary code execution.</synopsis>
6+
<product type="ebuild">gnupg</product>
7+
<announced>2025-12-27</announced>
8+
<revised count="1">2025-12-27</revised>
9+
<bug>967884</bug>
10+
<access>remote</access>
11+
<affected>
12+
<package name="app-crypt/gnupg" auto="yes" arch="*">
13+
<unaffected range="ge">2.5.14</unaffected>
14+
<vulnerable range="lt">2.5.14</vulnerable>
15+
</package>
16+
</affected>
17+
<background>
18+
<p>The GNU Privacy Guard, GnuPG, is a free replacement for the PGP suite of cryptographic software.</p>
19+
</background>
20+
<description>
21+
<p>A vulnerability has been discovered in GnuPG&#39;s armor parser.</p>
22+
</description>
23+
<impact type="high">
24+
<p>A remote attacker could entice a user or automated system to process a specially crafted signature file, possibly resulting in execution of arbitrary commands with the privileges of the process.</p>
25+
</impact>
26+
<workaround>
27+
<p>There is no known workaround at this time.</p>
28+
</workaround>
29+
<resolution>
30+
<p>All GnuPG users should upgrade to the latest version:</p>
31+
32+
<code>
33+
# emerge --sync
34+
# emerge --ask --oneshot --verbose ">=app-crypt/gnupg-2.5.14"
35+
</code>
36+
</resolution>
37+
<references>
38+
</references>
39+
<metadata tag="requester" timestamp="2025-12-27T21:32:04.569640Z">sam</metadata>
40+
<metadata tag="submitter" timestamp="2025-12-27T21:32:04.576671Z">sam</metadata>
41+
</glsa>
Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
Mon, 01 Dec 2025 06:40:07 +0000
1+
Thu, 01 Jan 2026 06:40:24 +0000
Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
ec936f5c1002deb9283d4febda05f013db58790c 1764120273 2025-11-26T01:24:33Z
1+
9e297cd21fe68d36a7180cf1ead3745d99567474 1766871224 2025-12-27T21:33:44Z

0 commit comments

Comments
 (0)