Console Output
15:41:06 [2024-01-31T15:41:06.714Z] Handling message: [artifact:[type:koji-build-group, id:FEDORA-2024-aec80d6e8a-bd30d9f9ab2af7be149ec169a6d45da34b1e94ad, repository:https://bodhi.fedoraproject.org/updates/FEDORA-2024-aec80d6e8a, builds:[[type:koji-build, id:2395803, task_id:112626030, issuer:pfrankli, component:glibc, nvr:glibc-2.38-16.fc39, scratch:false]], release:f39], agent:pfrankli, re-trigger:true, generated_at:2024-01-31T15:40:54.599380Z, contact:[name:Bodhi, email:admin@fp.o, team:Fedora CI, docs:https://docs.fedoraproject.org/en-US/ci/], update:[autokarma:true, autotime:true, stable_karma:3, stable_days:14, unstable_karma:-3, requirements:, require_bugs:false, require_testcases:false, display_name:, notes:Security fix for CVE-2023-6246, CVE-2023-6779, and CVE-2023-6780.
15:41:06 [2024-01-31T15:41:06.714Z]
15:41:06 [2024-01-31T15:41:06.714Z] CVE-2023-6246: __vsyslog_internal did not handle a case where printing a SYSLOG_HEADER
15:41:06 [2024-01-31T15:41:06.714Z] containing a long program name failed to update the required buffer
15:41:06 [2024-01-31T15:41:06.714Z] size, leading to the allocation and overflow of a too-small buffer on
15:41:06 [2024-01-31T15:41:06.714Z] the heap.
15:41:06 [2024-01-31T15:41:06.714Z]
15:41:06 [2024-01-31T15:41:06.714Z] CVE-2023-6779: __vsyslog_internal used the return value of snprintf/vsnprintf to
15:41:06 [2024-01-31T15:41:06.714Z] calculate buffer sizes for memory allocation. If these functions (for
15:41:06 [2024-01-31T15:41:06.714Z] any reason) failed and returned -1, the resulting buffer would be too
15:41:06 [2024-01-31T15:41:06.714Z] small to hold output.
15:41:06 [2024-01-31T15:41:06.714Z]
15:41:06 [2024-01-31T15:41:06.714Z] CVE-2023-6780: __vsyslog_internal calculated a buffer size by adding two integers, but
15:41:06 [2024-01-31T15:41:06.714Z] did not first check if the addition would overflow.
15:41:06 [2024-01-31T15:41:06.714Z] , type:security, status:testing, request:null, severity:high, suggest:reboot, locked:false, pushed:true, critpath:true, critpath_groups:core critical-path-anaconda critical-path-apps critical-path-base critical-path-build critical-path-compose critical-path-deepin-desktop critical-path-gnome critical-path-kde critical-path-lxde critical-path-lxqt critical-path-server critical-path-standard critical-path-xfce, close_bugs:true, date_submitted:2024-01-30 22:14:46, date_modified:null, date_approved:null, date_testing:2024-01-31 00:51:28, date_stable:null, alias:FEDORA-2024-aec80d6e8a, test_gating_status:failed, from_tag:null, date_pushed:2024-01-31 00:51:28, meets_testing_requirements:false, url:https://bodhi.fedoraproject.org/updates/FEDORA-2024-aec80d6e8a, title:glibc-2.38-16.fc39, version_hash:bd30d9f9ab2af7be149ec169a6d45da34b1e94ad, release:[name:F39, long_name:Fedora 39, version:39, id_prefix:FEDORA, branch:f39, dist_tag:f39, stable_tag:f39-updates, testing_tag:f39-updates-testing, candidate_tag:f39-updates-candidate, pending_signing_tag:f39-signing-pending, pending_testing_tag:f39-updates-testing-pending, pending_stable_tag:f39-updates-pending, override_tag:f39-override, mail_template:fedora_errata_template, state:current, composed_by_bodhi:true, create_automatic_updates:false, package_manager:dnf, testing_repository:updates-testing, eol:2024-11-12], compose:null, comments:[[id:3369204, karma:0, karma_critpath:0, text:This update has been submitted for testing by pfrankli. , timestamp:2024-01-30 22:14:46, update_id:581933, user_id:91, bug_feedback:[], testcase_feedback:[], user:[id:91, name:bodhi, email:null, avatar:null, openid:null, groups:[]]], [id:3369205, karma:0, karma_critpath:0, text:This update's test gating status has been changed to 'waiting'., timestamp:2024-01-30 22:15:03, update_id:581933, user_id:91, bug_feedback:[], testcase_feedback:[], user:[id:91, name:bodhi, email:null, avatar:null, openid:null, groups:[]]], [id:3369297, karma:1, karma_critpath:0, text:, timestamp:2024-01-30 23:33:06, update_id:581933, user_id:3703, bug_feedback:[[karma:0, comment_id:3369297, bug_id:2249053, bug:[bug_id:2249053, title:CVE-2023-6246 glibc: heap-based buffer overflow in __vsyslog_internal(), security:true, parent:true]], [karma:0, comment_id:3369297, bug_id:2254395, bug:[bug_id:2254395, title:CVE-2023-6779 glibc: off-by-one heap-based buffer overflow in __vsyslog_internal(), security:true, parent:true]], [karma:0, comment_id:3369297, bug_id:2254396, bug:[bug_id:2254396, title:CVE-2023-6780 glibc: integer overflow in __vsyslog_internal(), security:true, parent:true]]], testcase_feedback:[], user:[id:3703, name:markec, email:marko.bevc@gmail.com, avatar:null, openid:null, groups:[[name:ipausers], [name:signed_fpca]]]], [id:3369299, karma:0, karma_critpath:0, text:This update's test gating status has been changed to 'passed'., timestamp:2024-01-30 23:52:43, update_id:581933, user_id:91, bug_feedback:[], testcase_feedback:[], user:[id:91, name:bodhi, email:null, avatar:null, openid:null, groups:[]]], [id:3369419, karma:0, karma_critpath:0, text:This update has been pushed to testing., timestamp:2024-01-31 00:53:04, update_id:581933, user_id:91, bug_feedback:[], testcase_feedback:[], user:[id:91, name:bodhi, email:null, avatar:null, openid:null, groups:[]]], [id:3369423, karma:0, karma_critpath:0, text:This update's test gating status has been changed to 'failed'., timestamp:2024-01-31 00:55:41, update_id:581933, user_id:91, bug_feedback:[], testcase_feedback:[], user:[id:91, name:bodhi, email:null, avatar:null, openid:null, groups:[]]], [id:3369490, karma:0, karma_critpath:0, text:This update's test gating status has been changed to 'waiting'., timestamp:2024-01-31 01:08:20, update_id:581933, user_id:91, bug_feedback:[], testcase_feedback:[], user:[id:91, name:bodhi, email:null, avatar:null, openid:null, groups:[]]], [id:3369499, karma:0, karma_critpath:0, text:This update's test gating status has been changed to 'passed'., timestamp:2024-01-31 01:23:10, update_id:581933, user_id:91, bug_feedback:[], testcase_feedback:[], user:[id:91, name:bodhi, email:null, avatar:null, openid:null, groups:[]]], [id:3369731, karma:1, karma_critpath:0, text:Works., timestamp:2024-01-31 02:46:38, update_id:581933, user_id:198, bug_feedback:[], testcase_feedback:[], user:[id:198, name:bojan, email:bojan@rexursive.com, avatar:null, openid:null, groups:[[name:packager], [name:ipausers], [name:fedora-contributor], [name:signed_fpca], [name:fedorabugs]]]], [id:3369732, karma:0, karma_critpath:0, text:This update can be pushed to stable now if the maintainer wishes, timestamp:2024-01-31 02:49:22, update_id:581933, user_id:91, bug_feedback:[], testcase_feedback:[], user:[id:91, name:bodhi, email:null, avatar:null, openid:null, groups:[]]], [id:3369790, karma:0, karma_critpath:0, text:This update's test gating status has been changed to 'failed'., timestamp:2024-01-31 07:07:01, update_id:581933, user_id:91, bug_feedback:[], testcase_feedback:[], user:[id:91, name:bodhi, email:null, avatar:null, openid:null, groups:[]]], [id:3369875, karma:1, karma_critpath:0, text:, timestamp:2024-01-31 09:59:02, update_id:581933, user_id:3703, bug_feedback:[[karma:0, comment_id:3369875, bug_id:2249053, bug:[bug_id:2249053, title:CVE-2023-6246 glibc: heap-based buffer overflow in __vsyslog_internal(), security:true, parent:true]], [karma:0, comment_id:3369875, bug_id:2254395, bug:[bug_id:2254395, title:CVE-2023-6779 glibc: off-by-one heap-based buffer overflow in __vsyslog_internal(), security:true, parent:true]], [karma:0, comment_id:3369875, bug_id:2254396, bug:[bug_id:2254396, title:CVE-2023-6780 glibc: integer overflow in __vsyslog_internal(), security:true, parent:true]]], testcase_feedback:[], user:[id:3703, name:markec, email:marko.bevc@gmail.com, avatar:null, openid:null, groups:[[name:ipausers], [name:signed_fpca]]]], [id:3369879, karma:0, karma_critpath:0, text:Seems like one of required tests failed, timestamp:2024-01-31 09:59:33, update_id:581933, user_id:3703, bug_feedback:[[karma:0, comment_id:3369879, bug_id:2249053, bug:[bug_id:2249053, title:CVE-2023-6246 glibc: heap-based buffer overflow in __vsyslog_internal(), security:true, parent:true]], [karma:0, comment_id:3369879, bug_id:2254395, bug:[bug_id:2254395, title:CVE-2023-6779 glibc: off-by-one heap-based buffer overflow in __vsyslog_internal(), security:true, parent:true]], [karma:0, comment_id:3369879, bug_id:2254396, bug:[bug_id:2254396, title:CVE-2023-6780 glibc: integer overflow in __vsyslog_internal(), security:true, parent:true]]], testcase_feedback:[], user:[id:3703, name:markec, email:marko.bevc@gmail.com, avatar:null, openid:null, groups:[[name:ipausers], [name:signed_fpca]]]], [id:3369956, karma:1, karma_critpath:0, text:, timestamp:2024-01-31 12:43:58, update_id:581933, user_id:7096, bug_feedback:[[karma:0, comment_id:3369956, bug_id:2249053, bug:[bug_id:2249053, title:CVE-2023-6246 glibc: heap-based buffer overflow in __vsyslog_internal(), security:true, parent:true]], [karma:0, comment_id:3369956, bug_id:2254395, bug:[bug_id:2254395, title:CVE-2023-6779 glibc: off-by-one heap-based buffer overflow in __vsyslog_internal(), security:true, parent:true]], [karma:0, comment_id:3369956, bug_id:2254396, bug:[bug_id:2254396, title:CVE-2023-6780 glibc: integer overflow in __vsyslog_internal(), security:true, parent:true]]], testcase_feedback:[], user:[id:7096, name:steiner, email:daimarstein@pm.me, avatar:null, openid:null, groups:[[name:ipausers], [name:fedora-contributor], [name:signed_fpca], [name:fedora-socialmedia], [name:marketing], [name:designteam]]]], [id:3370043, karma:1, karma_critpath:0, text:, timestamp:2024-01-31 13:07:56, update_id:581933, user_id:5881, bug_feedback:[], testcase_feedback:[], user:[id:5881, name:geraldosimiao, email:geraldo.simiao.kutz@gmail.com, avatar:null, openid:null, groups:[[name:ipausers], [name:signed_fpca], [name:ambassadors], [name:advocates]]]]], builds:[[nvr:glibc-2.38-16.fc39, signed:true, release_id:70, type:rpm, epoch:0]], bugs:[[bug_id:2249053, title:CVE-2023-6246 glibc: heap-based buffer overflow in __vsyslog_internal(), security:true, parent:true, feedback:[[karma:0, comment_id:3369297, bug_id:2249053, comment:[id:3369297, karma:1, karma_critpath:0, text:, timestamp:2024-01-30 23:33:06, update_id:581933, user_id:3703, testcase_feedback:[], user:[id:3703, name:markec, email:marko.bevc@gmail.com, avatar:null, openid:null, groups:[[name:ipausers], [name:signed_fpca]]]]], [karma:0, comment_id:3369875, bug_id:2249053, comment:[id:3369875, karma:1, karma_critpath:0, text:, timestamp:2024-01-31 09:59:02, update_id:581933, user_id:3703, testcase_feedback:[], user:[id:3703, name:markec, email:marko.bevc@gmail.com, avatar:null, openid:null, groups:[[name:ipausers], [name:signed_fpca]]]]], [karma:0, comment_id:3369942, bug_id:2249053, comment:[id:3369942, karma:1, karma_critpath:0, text:works for me ( tested on Server-Cluster 10+ systems), timestamp:2024-01-31 12:26:50, update_id:581932, user_id:6075, testcase_feedback:[], user:[id:6075, name:mschwarz, email:fedoradev@cloud-foo.de, avatar:null, openid:null, groups:[[name:ipausers], [name:signed_fpca]]]]], [karma:0, comment_id:3369956, bug_id:2249053, comment:[id:3369956, karma:1, karma_critpath:0, text:, timestamp:2024-01-31 12:43:58, update_id:581933, user_id:7096, testcase_feedback:[], user:[id:7096, name:steiner, email:daimarstein@pm.me, avatar:null, openid:null, groups:[[name:ipausers], [name:fedora-contributor], [name:signed_fpca], [name:fedora-socialmedia], [name:marketing], [name:designteam]]]]], [karma:0, comment_id:3370005, bug_id:2249053, comment:[id:3370005, karma:1, karma_critpath:0, text:works, timestamp:2024-01-31 12:57:38, update_id:581932, user_id:1579, testcase_feedback:[], user:[id:1579, name:rdtcustomercare, email:customercare@resellerdesktop.de, avatar:null, openid:null, groups:[[name:ipausers]]]]], [karma:0, comment_id:3373876, bug_id:2249053, comment:[id:3373876, karma:1, karma_critpath:0, text:, timestamp:2024-01-31 14:26:05, update_id:581932, user_id:1725, testcase_feedback:[], user:[id:1725, name:jwakely, email:jwakely@redhat.com, avatar:null, openid:null, groups:[[name:packager], [name:provenpackager], [name:ipausers], [name:fedora-contributor], [name:signed_fpca], [name:fedorabugs], [name:packaging-committee]]]]], [karma:0, comment_id:3369879, bug_id:2249053, comment:[id:3369879, karma:0, karma_critpath:0, text:Seems like one of required tests failed, timestamp:2024-01-31 09:59:33, update_id:581933, user_id:3703, testcase_feedback:[], user:[id:3703, name:markec, email:marko.bevc@gmail.com, avatar:null, openid:null, groups:[[name:ipausers], [name:signed_fpca]]]]]]], [bug_id:2254395, title:CVE-2023-6779 glibc: off-by-one heap-based buffer overflow in __vsyslog_internal(), security:true, parent:true, feedback:[[karma:0, comment_id:3369297, bug_id:2254395, comment:[id:3369297, karma:1, karma_critpath:0, text:, timestamp:2024-01-30 23:33:06, update_id:581933, user_id:3703, testcase_feedback:[], user:[id:3703, name:markec, email:marko.bevc@gmail.com, avatar:null, openid:null, groups:[[name:ipausers], [name:signed_fpca]]]]], [karma:0, comment_id:3369875, bug_id:2254395, comment:[id:3369875, karma:1, karma_critpath:0, text:, timestamp:2024-01-31 09:59:02, update_id:581933, user_id:3703, testcase_feedback:[], user:[id:3703, name:markec, email:marko.bevc@gmail.com, avatar:null, openid:null, groups:[[name:ipausers], [name:signed_fpca]]]]], [karma:0, comment_id:3369942, bug_id:2254395, comment:[id:3369942, karma:1, karma_critpath:0, text:works for me ( tested on Server-Cluster 10+ systems), timestamp:2024-01-31 12:26:50, update_id:581932, user_id:6075, testcase_feedback:[], user:[id:6075, name:mschwarz, email:fedoradev@cloud-foo.de, avatar:null, openid:null, groups:[[name:ipausers], [name:signed_fpca]]]]], [karma:0, comment_id:3369956, bug_id:2254395, comment:[id:3369956, karma:1, karma_critpath:0, text:, timestamp:2024-01-31 12:43:58, update_id:581933, user_id:7096, testcase_feedback:[], user:[id:7096, name:steiner, email:daimarstein@pm.me, avatar:null, openid:null, groups:[[name:ipausers], [name:fedora-contributor], [name:signed_fpca], [name:fedora-socialmedia], [name:marketing], [name:designteam]]]]], [karma:0, comment_id:3370005, bug_id:2254395, comment:[id:3370005, karma:1, karma_critpath:0, text:works, timestamp:2024-01-31 12:57:38, update_id:581932, user_id:1579, testcase_feedback:[], user:[id:1579, name:rdtcustomercare, email:customercare@resellerdesktop.de, avatar:null, openid:null, groups:[[name:ipausers]]]]], [karma:0, comment_id:3373876, bug_id:2254395, comment:[id:3373876, karma:1, karma_critpath:0, text:, timestamp:2024-01-31 14:26:05, update_id:581932, user_id:1725, testcase_feedback:[], user:[id:1725, name:jwakely, email:jwakely@redhat.com, avatar:null, openid:null, groups:[[name:packager], [name:provenpackager], [name:ipausers], [name:fedora-contributor], [name:signed_fpca], [name:fedorabugs], [name:packaging-committee]]]]], [karma:0, comment_id:3369879, bug_id:2254395, comment:[id:3369879, karma:0, karma_critpath:0, text:Seems like one of required tests failed, timestamp:2024-01-31 09:59:33, update_id:581933, user_id:3703, testcase_feedback:[], user:[id:3703, name:markec, email:marko.bevc@gmail.com, avatar:null, openid:null, groups:[[name:ipausers], [name:signed_fpca]]]]]]], [bug_id:2254396, title:CVE-2023-6780 glibc: integer overflow in __vsyslog_internal(), security:true, parent:true, feedback:[[karma:0, comment_id:3369297, bug_id:2254396, comment:[id:3369297, karma:1, karma_critpath:0, text:, timestamp:2024-01-30 23:33:06, update_id:581933, user_id:3703, testcase_feedback:[], user:[id:3703, name:markec, email:marko.bevc@gmail.com, avatar:null, openid:null, groups:[[name:ipausers], [name:signed_fpca]]]]], [karma:0, comment_id:3369875, bug_id:2254396, comment:[id:3369875, karma:1, karma_critpath:0, text:, timestamp:2024-01-31 09:59:02, update_id:581933, user_id:3703, testcase_feedback:[], user:[id:3703, name:markec, email:marko.bevc@gmail.com, avatar:null, openid:null, groups:[[name:ipausers], [name:signed_fpca]]]]], [karma:0, comment_id:3369942, bug_id:2254396, comment:[id:3369942, karma:1, karma_critpath:0, text:works for me ( tested on Server-Cluster 10+ systems), timestamp:2024-01-31 12:26:50, update_id:581932, user_id:6075, testcase_feedback:[], user:[id:6075, name:mschwarz, email:fedoradev@cloud-foo.de, avatar:null, openid:null, groups:[[name:ipausers], [name:signed_fpca]]]]], [karma:0, comment_id:3369956, bug_id:2254396, comment:[id:3369956, karma:1, karma_critpath:0, text:, timestamp:2024-01-31 12:43:58, update_id:581933, user_id:7096, testcase_feedback:[], user:[id:7096, name:steiner, email:daimarstein@pm.me, avatar:null, openid:null, groups:[[name:ipausers], [name:fedora-contributor], [name:signed_fpca], [name:fedora-socialmedia], [name:marketing], [name:designteam]]]]], [karma:0, comment_id:3370005, bug_id:2254396, comment:[id:3370005, karma:1, karma_critpath:0, text:works, timestamp:2024-01-31 12:57:38, update_id:581932, user_id:1579, testcase_feedback:[], user:[id:1579, name:rdtcustomercare, email:customercare@resellerdesktop.de, avatar:null, openid:null, groups:[[name:ipausers]]]]], [karma:0, comment_id:3373876, bug_id:2254396, comment:[id:3373876, karma:1, karma_critpath:0, text:, timestamp:2024-01-31 14:26:05, update_id:581932, user_id:1725, testcase_feedback:[], user:[id:1725, name:jwakely, email:jwakely@redhat.com, avatar:null, openid:null, groups:[[name:packager], [name:provenpackager], [name:ipausers], [name:fedora-contributor], [name:signed_fpca], [name:fedorabugs], [name:packaging-committee]]]]], [karma:0, comment_id:3369879, bug_id:2254396, comment:[id:3369879, karma:0, karma_critpath:0, text:Seems like one of required tests failed, timestamp:2024-01-31 09:59:33, update_id:581933, user_id:3703, testcase_feedback:[], user:[id:3703, name:markec, email:marko.bevc@gmail.com, avatar:null, openid:null, groups:[[name:ipausers], [name:signed_fpca]]]]]]]], user:[id:1006, name:pfrankli, email:pfrankli@redhat.com, avatar:null, openid:null, groups:[[name:packager], [name:ipausers], [name:fedora-contributor], [name:signed_fpca], [name:fedorabugs]]], updateid:FEDORA-2024-aec80d6e8a, karma:4, content_type:rpm, test_cases:[]], version:0.2.2]