You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Production SBOM confirms rsync 3.4.4, while Gentoo tracks 33 new rsync CVEs fixed in 3.5.0; open issue #229 already covers rsync but not these CVEs or the new critical daemon/path-handling context.
Proposed additive update for action disc-ca252c4e466e90b31f5c (issue #229)
Action Needed (only applied if currently TBD): TBD
Summary (only applied if currently TBD): Rsync 3.5.0 fixes 33 security issues involving symlink and path traversal races, daemon protocol access-control and denial-of-service flaws, command or argument injection, TLS authentication, memory corruption, and related robustness issues.
Comment to post:
Gentoo Bugzilla has new or changed upstream context for this advisory.
Recommended review items:
- Add CVEs: CVE-2026-53783, CVE-2026-53784, CVE-2026-53785, CVE-2026-53786, CVE-2026-53788, CVE-2026-53789, CVE-2026-53790, CVE-2026-53791, CVE-2026-53792, CVE-2026-53793, CVE-2026-53794, CVE-2026-53795, CVE-2026-53796, CVE-2026-53797, CVE-2026-53798, CVE-2026-53799, CVE-2026-53800, CVE-2026-53801, CVE-2026-53802, CVE-2026-53803, CVE-2026-70452, CVE-2026-70453, CVE-2026-70454, CVE-2026-70455, CVE-2026-70456, CVE-2026-70457, CVE-2026-70458, CVE-2026-70459, CVE-2026-70460, CVE-2026-70461, CVE-2026-70462, CVE-2026-70463, CVE-2026-70464
- Add Gentoo aliases/CVEs: CVE-2026-53783, CVE-2026-53784, CVE-2026-53785, CVE-2026-53786, CVE-2026-53788, CVE-2026-53789, CVE-2026-53790, CVE-2026-53791, CVE-2026-53792, CVE-2026-53793, CVE-2026-53794, CVE-2026-53795, CVE-2026-53796, CVE-2026-53797, CVE-2026-53798, CVE-2026-53799, CVE-2026-53800, CVE-2026-53801, CVE-2026-53802, CVE-2026-53803, CVE-2026-70452, CVE-2026-70453, CVE-2026-70454, CVE-2026-70455, CVE-2026-70456, CVE-2026-70457, CVE-2026-70458, CVE-2026-70459, CVE-2026-70460, CVE-2026-70461, CVE-2026-70462, CVE-2026-70463, CVE-2026-70464
- Add upstream context: Rsync 3.5.0 fixes 33 security issues involving symlink and path traversal races, daemon protocol access-control and denial-of-service flaws, command or argument injection, TLS authentication, memory corruption, and related robustness issues.
- Review Gentoo severity: critical
- Review upstream references: http://bugs.gentoo.org/show_bug.cgi?id=978280, http://bugs.gentoo.org/show_bug.cgi?id=975525, http://bugs.gentoo.org/show_bug.cgi?id=948106
- Review Bugzilla description: https://download.samba.org/pub/rsync/NEWS#3.5.0
"""
SECURITY FIXES:
This release fixes 33 security issues found during a focused audit of rsync's path handling and daemon protocol, a companion daemon-protocol fuzzing pass, and reports from external researchers -- plus several robustness harde...
- Review Bugzilla comment #1 by sam at 2026-08-13T00:33:23Z: Continued:
"""
CVE-2026-70456 (HIGH): an out-of-bounds heap write in read_args() when the peer's argument count lands exactly on maxargs -- the trailing NULL went one past the end of the array.
CVE-2026-70457 (MEDIUM): an attacker-chosen-offset write in parse_size_arg()'s error formatt...
- Review Bugzilla comment #2 by infra-gitbot at 2026-08-13T00:46:59Z: The bug has been referenced in the following commit(s):
https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=513c488fcaedcdfe09261cea8540065c93eb33c0
commit 513c488fcaedcdfe09261cea8540065c93eb33c0
Author: Sam James <sam@gentoo.org>
AuthorDate: 2026-08-13 00:43:51 +0000
Commit: Sam Jame...
- Review Bugzilla comment #3 by sam at 2026-08-14T01:50:20Z: Need to wait for https://github.com/RsyncProject/rsync/issues/1053 and https://github.com/RsyncProject/rsync/issues/1050 to be fixed at least, as well as the https://github.com/RsyncProject/rsync/issues/1045 test bug.
New Bugzilla comments in the processing window:
- Review Bugzilla comment #1 by sam at 2026-08-13T00:33:23Z: Continued:
"""
CVE-2026-70456 (HIGH): an out-of-bounds heap write in read_args() when the peer's argument count lands exactly on maxargs -- the trailing NULL went one past the end of the array.
CVE-2026-70457 (MEDIUM): an attacker-chosen-offset write in parse_size_arg()'s error formatt...
- Review Bugzilla comment #2 by infra-gitbot at 2026-08-13T00:46:59Z: The bug has been referenced in the following commit(s):
https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=513c488fcaedcdfe09261cea8540065c93eb33c0
commit 513c488fcaedcdfe09261cea8540065c93eb33c0
Author: Sam James <sam@gentoo.org>
AuthorDate: 2026-08-13 00:43:51 +0000
Commit: Sam Jame...
- Review Bugzilla comment #3 by sam at 2026-08-14T01:50:20Z: Need to wait for https://github.com/RsyncProject/rsync/issues/1053 and https://github.com/RsyncProject/rsync/issues/1050 to be fixed at least, as well as the https://github.com/RsyncProject/rsync/issues/1045 test bug.
Source: https://bugs.gentoo.org/980780
This is a guarded automation recommendation; maintainers should review before editing the advisory body.
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Flatpak is a desktop-oriented application sandbox/runtime and there is no evidence that it is shipped or used by Flatcar; no production SBOM match exists.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 266: www-client/chromium and listed Chromium-based browser packages (discovery, source: gentoo)
Production SBOM contains dev-libs/openssl 3.5.7, which is in the affected OpenSSL 3.5 branch for CVE-2026-14456; no existing matching issue was provided.
Exact proposed issue for action disc-35908800c0c10272f68a
Title: update: dev-libs/openssl
Name: dev-libs/openssl
CVEs: CVE-2026-14456
CVSSs: n/a
Action Needed: TBD
Summary: OpenSSL QUIC listeners can experience unbounded memory growth when processing many valid Initial packets for unknown destination connection IDs, potentially causing denial of service. OpenSSL 4.0, 3.6, and 3.5 are affected; 3.4 and older listed branches are not affected.
refmap.gentoo: https://bugs.gentoo.org/980809
Labels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Create new advisory issue: update: dev-libs/openssl
LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 270: zip (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/980838
CVEs / upstream IDs: TBD
CVSS: n/a
Flatcar relevance: relevant (scope: production)
Recommendation: create_issue (confidence: high)
SBOM matches: app-arch/zip 3.0-r7 (exact_name)
Existing issue matches: none
The production SBOM contains app-arch/zip 3.0-r7, which is within Gentoo's affected range (<3.0_p16). The issue is a command injection in zip -T when processing an attacker-controlled archive filename; no existing Flatcar issue match is present.
Exact proposed issue for action disc-700b69c6e3d779fa76f7
Title: update: zip
Name: zip
CVEs: TBD
CVSSs: n/a
Action Needed: TBD
Summary: Info-ZIP zip command injection in the -T integrity-test option when an attacker controls the archive filename.
refmap.gentoo: https://bugs.gentoo.org/980838
Labels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Create new advisory issue: update: zip
Group 271: graphicsmagick (discovery, source: gentoo)
GraphicsMagick is not evidenced in the Flatcar production SBOM or other Flatcar package/usage evidence; it is a graphics/image-processing package and the source issue includes X11/display-related context.
Choose at most one (leave all unchecked to take no action for this group):
Open issue #64 already tracks dev-lang/go; this source adds ten distinct CVEs, updated affected/fixed versions (before 1.25.13 and 1.26.6), and new Gentoo/Openwall references that should be incorporated rather than creating a duplicate.
Proposed additive update for action disc-021d58320efd8cf9f15b (issue #64)
Action Needed (only applied if currently TBD): update target
Summary (only applied if currently TBD): Go 1.25.13 and 1.26.6 fix ten vulnerabilities affecting module transparency verification, XML/ASN.1 recursion, HTTP/2 timeout handling, URL path resolution, DNS SVCB parsing, TLS handshakes, JavaScript templating, and IDNA processing.
Comment to post:
Gentoo Bugzilla has new or changed upstream context for this advisory.
Recommended review items:
- Add CVEs: CVE-2026-33818, CVE-2026-39821, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862, CVE-2026-56864, CVE-2026-56865
- Add Gentoo aliases/CVEs: CVE-2026-33818, CVE-2026-39821, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862, CVE-2026-56864, CVE-2026-56865
- Add upstream context: Go 1.25.13 and 1.26.6 fix ten vulnerabilities affecting module transparency verification, XML/ASN.1 recursion, HTTP/2 timeout handling, URL path resolution, DNS SVCB parsing, TLS handshakes, JavaScript templating, and IDNA processing.
- Review Gentoo severity: normal (source: https://www.openwall.com/lists/oss-security/2026/08/13/13)
- Review upstream references: https://www.openwall.com/lists/oss-security/2026/08/13/13
- Review Bugzilla description: """
Hello gophers,
We have just released Go versions 1.26.6 and 1.25.13, minor point releases.
These releases include 10 security fixes following the security policy
<https://go.dev/doc/security/policy>:
* x/mod/sumdb/tlog: fix transparency log tile verification bypass
A malicious GO...
- Review Bugzilla comment #1 by infra-gitbot at 2026-08-15T00:20:32Z: The bug has been referenced in the following commit(s):
https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c45cbced5d30bb660923ee14e58ef5d871653658
commit c45cbced5d30bb660923ee14e58ef5d871653658
Author: Sam James <sam@gentoo.org>
AuthorDate: 2026-08-15 00:11:34 +0000
Commit: Sam Jame...
New Bugzilla comments in the processing window:
- Review Bugzilla comment #1 by infra-gitbot at 2026-08-15T00:20:32Z: The bug has been referenced in the following commit(s):
https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c45cbced5d30bb660923ee14e58ef5d871653658
commit c45cbced5d30bb660923ee14e58ef5d871653658
Author: Sam James <sam@gentoo.org>
AuthorDate: 2026-08-15 00:11:34 +0000
Commit: Sam Jame...
Source: https://bugs.gentoo.org/980862
This is a guarded automation recommendation; maintainers should review before editing the advisory body.
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
The production SBOM contains app-arch/unzip 6.0_p29-r2, and the Gentoo vulnerability entry identifies multiple CVEs affecting app-arch/unzip versions before 6.0_p31. No existing matching issue is present.
Exact proposed issue for action disc-ef4645ac11530e8975f3
Title: update: app-arch/unzip
Name: app-arch/unzip
CVEs: CAN-2026-2034440, CAN-2026-2034442, CAN-2026-2034443
CVSSs: n/a
Action Needed: TBD
Summary: Multiple unzip vulnerabilities associated with version 6.0_p31; issues were moved from Gentoo bug 980838.
refmap.gentoo: https://bugs.gentoo.org/980955
Labels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Create new advisory issue: update: app-arch/unzip
Group 278: net-analyzer/tcpreplay (discovery, source: gentoo)
Automated Flatcar security-triage review batch
32105957657, part 14 of 20.Run metadata
flatcar/security-triageflatcar/security-triagec90928f96af109865771b8b7539bf11c4d2f2ba4Summary
This part contains 17 decision group(s).
Whole batch: 420 decision group(s) across 20 part(s).
How to use this review
Decision groups
Group 264: net-misc/rsync (discovery, source: gentoo)
https://bugs.gentoo.org/980780Proposed additive update for action
disc-ca252c4e466e90b31f5c(issue #229)Comment to post:
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Group 265: flatpak (discovery, source: gentoo)
https://bugs.gentoo.org/980781Choose at most one (leave all unchecked to take no action for this group):
Group 266: www-client/chromium and listed Chromium-based browser packages (discovery, source: gentoo)
https://bugs.gentoo.org/980799Choose at most one (leave all unchecked to take no action for this group):
Group 267: net-im/zoom (discovery, source: gentoo)
https://bugs.gentoo.org/980808Choose at most one (leave all unchecked to take no action for this group):
Group 268: dev-libs/openssl (discovery, source: gentoo)
https://bugs.gentoo.org/980809Exact proposed issue for action
disc-35908800c0c10272f68aTitle:
update: dev-libs/opensslLabels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 269: libgit2 (discovery, source: gentoo)
https://bugs.gentoo.org/980827Choose at most one (leave all unchecked to take no action for this group):
Group 270: zip (discovery, source: gentoo)
https://bugs.gentoo.org/980838Exact proposed issue for action
disc-700b69c6e3d779fa76f7Title:
update: zipLabels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 271: graphicsmagick (discovery, source: gentoo)
https://bugs.gentoo.org/980840Choose at most one (leave all unchecked to take no action for this group):
Group 272: croc (discovery, source: gentoo)
https://bugs.gentoo.org/980854Choose at most one (leave all unchecked to take no action for this group):
Group 273: dev-lang/go (discovery, source: gentoo)
https://bugs.gentoo.org/980862Proposed additive update for action
disc-021d58320efd8cf9f15b(issue #64)Comment to post:
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Group 274: dev-libs/botan (discovery, source: gentoo)
https://bugs.gentoo.org/980865Exact proposed issue for action
disc-6fbbb09c82dfa2f7d8f6Title:
update: dev-libs/botanLabels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 275: dev-libs/xapian (discovery, source: gentoo)
https://bugs.gentoo.org/980873Choose at most one (leave all unchecked to take no action for this group):
Group 276: dev-perl/DBI (discovery, source: gentoo)
https://bugs.gentoo.org/980944Choose at most one (leave all unchecked to take no action for this group):
Group 277: app-arch/unzip (discovery, source: gentoo)
https://bugs.gentoo.org/980955Exact proposed issue for action
disc-ef4645ac11530e8975f3Title:
update: app-arch/unzipLabels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 278: net-analyzer/tcpreplay (discovery, source: gentoo)
https://bugs.gentoo.org/980956Choose at most one (leave all unchecked to take no action for this group):
Group 279: putty (discovery, source: gentoo)
https://bugs.gentoo.org/980976Choose at most one (leave all unchecked to take no action for this group):
Group 280: htop (discovery, source: gentoo)
https://bugs.gentoo.org/980985Choose at most one (leave all unchecked to take no action for this group):
This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.