Fedora alert FEDORA-2021-4a91649cf3 (tcmu-runner)
From: | updates@fedoraproject.org | |
To: | package-announce@lists.fedoraproject.org | |
Subject: | [SECURITY] Fedora 33 Update: tcmu-runner-1.5.2-7.fc33 | |
Date: | Wed, 03 Feb 2021 01:55:35 +0000 | |
Message-ID: | <20210203015535.D68E7309CEF1@bastion01.iad2.fedoraproject.org> | |
Archive-link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2021-4a91649cf3 2021-02-03 01:54:49.296884 -------------------------------------------------------------------------------- Name : tcmu-runner Product : Fedora 33 Version : 1.5.2 Release : 7.fc33 URL : https://github.com/open-iscsi/tcmu-runner Summary : A daemon that supports LIO userspace backends Description : A daemon that handles the complexity of the LIO kernel target's userspace passthrough interface (TCMU). It presents a C plugin API for extension modules that handle SCSI requests in ways not possible or suitable to be handled by LIO's in-kernel backstores. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2020-28374 See tcmu-runner commit 2b16e96e6b63d0419d857f53e4cc67f0adb383fd tcmu-runner can't determine whether the device(s) referred to in XCOPY Copy Source/Copy Destination (CSCD) descriptors should be accessible to the initiator via transport settings, ACLs, etc. Consequently, fail XCOPY requests with CSCD descriptors which refer to any device other than where the XCOPY request is processed. -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 25 2021 Maurizio Lombardi <mlombard@redhat.com> - 1.5.2-7 - Fixes CVE-2020-28374 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-4a91649cf3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann...