Bug#1103833: rust-protobuf: CVE-2024-7254

2025-04-30 Thread NoisyCoil
Because of this bug, rust-protobuf is now marked for autoremoval together with the following packages: rust-erbium, rust-erbium-core, rust-pprof, rust-prometheus, rust-protobuf-codegen, rust-protobuf-codegen-pure, rust-protoc-rust, rust-ttrpc, scaphandre. scaphandre was already decoupled fro

Bug#1103833: rust-protobuf: CVE-2024-7254

2025-04-26 Thread NoisyCoil
I decoupled handlebars from the rest and filed [1] to also decouple prometheus: erbium (its only (transitive) reverse dependency application) doesn't use protobuf's functionality. This however is not a small change, so it needs consensus from the team (hence the MR). Pros and cons are detailed

Bug#1103833: [Pkg-rust-maintainers] Bug#1103833: rust-protobuf: CVE-2024-7254

2025-04-25 Thread NoisyCoil
On 25/04/25 07:05, Jonas Smedegaard wrote: Scaphande is now (pending upload) patched to no longer build-depend on the protobuf crate. Turns out it was optional and already unused for other reasons (will file a bug about that upstream). Thanks Jonas! As for erbium (via erbium-core), it looks l

Bug#1103833: rust-protobuf: CVE-2024-7254

2025-04-24 Thread Jonas Smedegaard
Quoting NoisyCoil (2025-04-25 03:02:57) > - scaphandre (leaf, no rdeps) Scaphande is now (pending upload) patched to no longer build-depend on the protobuf crate. Turns out it was optional and already unused for other reasons (will file a bug about that upstream). Thanks! - Jonas -- * Jonas

Bug#1103833: rust-protobuf: CVE-2024-7254

2025-04-24 Thread NoisyCoil
Source: rust-protobuf Followup-For: Bug #1103833 X-Debbugs-Cc: noisyc...@tutanota.com, jel...@debian.org, infini...@debian.org, d...@jones.dk Control: forwarded -1 https://github.com/stepancheg/rust-protobuf/issues/763 I looked into this, I will try to summarize the situation to the best of my kn