Bug#863277: systemd: CVE-2017-9217: systemd-resolved crashed with SIGSEGV in dns_packet_is_reply_for()

Michael Biebl biebl at debian.org
Mon May 29 13:17:52 BST 2017


Am 29.05.2017 um 14:10 schrieb Salvatore Bonaccorso:
> On Mon, May 29, 2017 at 02:04:17PM +0200, Michael Biebl wrote:

>> As for the bug itself: We don't enable resolved by default in Debian: Do
>> you think this bug is important enough that we should get this into 9.0?
>> I'd have to ask for an unlock request then.
>>
>> Otherwise I'd just queue this fix in the stretch branch and try to get
>> this into 9.1.
> 
> *If* you have other fixes which should go in stretch, then it might be
> good to include it. Otherwise I agree, can be fixed in buster and then
> in stretch via a point release!

There are a few fixes in the stretch branch which aren't uploaded yet.
They are not terribly urgent. That said, I'll just ask the release / d-i
team if they are ok with the upload, I guess.
If they have concerns, I'm happy to defer this to 9.1

Regards,
Michael
-- 
Why is it that all of the instruments seeking intelligent life in the
universe are pointed away from Earth?

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <http://alioth-lists.debian.net/pipermail/pkg-systemd-maintainers/attachments/20170529/c6fda58a/attachment-0002.sig>


More information about the Pkg-systemd-maintainers mailing list