Bug 264170 - databases/mariadb103-server: Update to 10.3.35 (includes security fixes)
Summary: databases/mariadb103-server: Update to 10.3.35 (includes security fixes)
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Many People
Assignee: Bernard Spil
URL: https://mariadb.com/kb/en/mariadb-103...
Keywords: needs-qa, security
Depends on:
Blocks:
 
Reported: 2022-05-23 08:46 UTC by vincent.jancso
Modified: 2022-05-24 18:47 UTC (History)
1 user (show)

See Also:
bugzilla: maintainer-feedback? (brnrd)
koobs: merge-quarterly?


Attachments
Patch file (1.65 KB, patch)
2022-05-23 08:46 UTC, vincent.jancso
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description vincent.jancso 2022-05-23 08:46:44 UTC
Created attachment 234137 [details]
Patch file

Version 10.3.35 has been released:
https://mariadb.com/kb/en/mariadb-10335-release-notes/

Provides fixes for the following security vulnerabilities:
CVE-2022-21427
CVE-2022-27376
CVE-2022-27377
CVE-2022-27378
CVE-2022-27379
CVE-2022-27380
CVE-2022-27381
CVE-2022-27383
CVE-2022-27384
CVE-2022-27386
CVE-2022-27387
CVE-2022-27445
CVE-2022-27447
CVE-2022-27448
CVE-2022-27449
CVE-2022-27452
CVE-2022-27456
CVE-2022-27458
Comment 1 Kubilay Kocak freebsd_committer freebsd_triage 2022-05-24 01:15:35 UTC
@Bernard Since we don't have existing reports for mariadb10{4,5} server ports yet (same security fix releases), if you'd like to track all server port updates here, please update the title accordingly, else let's create those separate issues.

MariaDB 10.4: https://mariadb.com/kb/en/mariadb-10425-release-notes/
MariaDB 10.5: https://mariadb.com/kb/en/mariadb-10516-release-notes/
MariaDB 10.6: port already updated
Comment 2 Bernard Spil freebsd_committer freebsd_triage 2022-05-24 12:18:49 UTC
Got poudriere logs of building this?

Both 10.6 and 10.5 need pkg-plist mods
Comment 3 Bernard Spil freebsd_committer freebsd_triage 2022-05-24 12:34:48 UTC
(In reply to Kubilay Kocak from comment #1)

I pick up the updates as soon as I get notification from MariaDB that there's new versions. That goes for all versions in ports
Comment 4 commit-hook freebsd_committer freebsd_triage 2022-05-24 15:43:37 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=6202520020d9c4f553a2c522a8004521dfa20418

commit 6202520020d9c4f553a2c522a8004521dfa20418
Author:     Bernard Spil <brnrd@FreeBSD.org>
AuthorDate: 2022-05-24 15:40:12 +0000
Commit:     Bernard Spil <brnrd@FreeBSD.org>
CommitDate: 2022-05-24 15:42:48 +0000

    databases/mariadb103-server: Security update to 10.3.35

    PR:             264170
    Submitted by:   Vincent Jancso <vincent jancso outlook com>
    Security:       04fecc47-dad2-11ec-8fbd-d4c9ef517024
    MFH:            2022Q2

 databases/mariadb103-server/Makefile                           | 10 +++++-----
 databases/mariadb103-server/distinfo                           |  6 +++---
 .../files/patch-scripts_wsrep__sst__mariabackup.sh             |  8 ++++----
 databases/mariadb103-server/pkg-plist                          |  1 +
 4 files changed, 13 insertions(+), 12 deletions(-)
Comment 5 commit-hook freebsd_committer freebsd_triage 2022-05-24 15:54:39 UTC
A commit in branch 2022Q2 references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=f194935cd9b9c0b5aa196b4e8a0b7fcd1dc3fd65

commit f194935cd9b9c0b5aa196b4e8a0b7fcd1dc3fd65
Author:     Bernard Spil <brnrd@FreeBSD.org>
AuthorDate: 2022-05-24 15:40:12 +0000
Commit:     Bernard Spil <brnrd@FreeBSD.org>
CommitDate: 2022-05-24 15:54:25 +0000

    databases/mariadb103-server: Security update to 10.3.35

    PR:             264170
    Submitted by:   Vincent Jancso <vincent jancso outlook com>
    Security:       04fecc47-dad2-11ec-8fbd-d4c9ef517024
    MFH:            2022Q2

    (cherry picked from commit 6202520020d9c4f553a2c522a8004521dfa20418)

 databases/mariadb103-server/Makefile               | 24 +++++++++++++---------
 databases/mariadb103-server/distinfo               |  6 +++---
 .../files/patch-scripts_wsrep__sst__mariabackup.sh |  8 ++++----
 databases/mariadb103-server/pkg-plist              |  1 +
 4 files changed, 22 insertions(+), 17 deletions(-)
Comment 6 Bernard Spil freebsd_committer freebsd_triage 2022-05-24 18:47:56 UTC
Making good on promises...