3 ms·
Took all of 30 seconds to verify it's in NixOS[1]. Another 30 seconds to see it was patched a week ago, at "Dec 8, 2023, 8:23 AM GMT+13", a day after the articl
by l0b0 3y ago
Took all of 30 seconds to verify it's in NixOS[1]. Another 30 seconds to see it was patched a week ago, at "Dec 8, 2023, 8:23 AM GMT+13", a day after the article was published (Dec 7, 2023, 10:18 AM GMT+13). :shrug:
Also, what do they even mean, if the distro announcement says to simply upgrade to fix it[2]? Do they mean that even after the upgrade you need to manually change a setting? Because the NixOS fix seems to be simply to flip the default setting. If they mean that users which have explicitly set ClassicBondedOnly=false need to change it, that could've been a lot clearer.
[1] https://github.com/NixOS/nixpkgs/blob/3dda6d5ed56af34534dd4cdcdd85627df25aec55/pkgs/os-specific/linux/bluez/default.nix#L45-L50 https://github.com/NixOS/nixpkgs/blob/3dda6d5ed56af34534dd4c...
[2] https://ubuntu.com/security/notices/USN-4311-1 https://ubuntu.com/security/notices/USN-4311-1
- amarshall 3y ago> Do they mean that even after the upgrade you need to manually change a setting? Yes, that’s what “the fix was left disabled by default” would mean. It’s good that it’s fixed by default now, but now is not 2020.
- yencabulator 3y agoThe NixOS change seems to be still stuck in staging-23.11, and not released: $ git log --grep=CVE-2023-45866 origin/nixos-23.11 $ git log --grep=CVE-2023-45866 origin/staging-23.11 ^origin/nixos-23.11 commit 8ba508ba10d27f61fe9f40eb8513d8d0864fbe14 Merge: f5cf92f30bd7 8fb1486901a3 Author: Martin Weinelt <hexa@darmstadt.ccc.de> Date: 2023-12-11 13:02:10 +0100 Merge pull request #272751 from leona-ya/backport-272672-to-staging-23.11 [Backport staging-23.11] bluez: apply patch for CVE-2023-45866 commit 8fb1486901a3f4e7cbdee5616f7d1a39a5dc7a99 Author: Leona Maroni <dev@leona.is> Date: 2023-12-07 13:44:59 +0100 bluez: apply patch for CVE-2023-45866 (cherry picked from commit 7d7f66dfba9f239f15aaec6512afb3443bbae915)