• Bug#1101775: bookworm-pu: package varnish/7.1.1-1.1+deb12u1

    From Adrian Bunk@21:1/5 to All on Mon Mar 31 23:20:01 2025
    XPost: linux.debian.bugs.dist

    This is a multi-part MIME message sent by reportbug.


    Package: release.debian.org
    Severity: normal
    Tags: bookworm moreinfo
    User: [email protected]
    Usertags: pu
    X-Debbugs-Cc: [email protected], Varnish Package Maintainers <[email protected]>

    * CVE-2025-30346: HTTP/1 client-side desync vulnerability

    Tagged moreinfo, as question to the security team whether they want
    this in pu or as DSA.

    diffstat for varnish-7.1.1 varnish-7.1.1

    changelog | 7 +
    patches/0001-req_fsm-Close-the-connection-on-a-malformed-request.patch | 53 ++++++++++
    patches/series | 1
    3 files changed, 61 insertions(+)

    diff -Nru varnish-7.1.1/debian/changelog varnish-7.1.1/debian/changelog
    --- varnish-7.1.1/debian/changelog 2023-01-09 23:09:31.000000000 +0200
    +++ varnish-7.1.1/debian/changelog 2025-03-31 16:06:56.000000000 +0300
    @@ -1,3 +1,10 @@
    +varnish (7.1.1-1.1+deb12u1) bookworm; urgency=medium
    +
    + * Non-maintainer upload.
    + * CVE-2025-30346: HTTP/1 client-side desync vulnerability
    +
    + -- Adrian Bunk <[email protected]> Mon, 31 Mar 2025 16:06:56 +0300
    +
    varnish (7.1.1-1.1) unstable; urgency=medium

    * Non-maintainer upload.
    diff -Nru varnish-7.1.1/debian/patches/0001-req_fsm-Close-the-connection-on-a-malformed-request.patch varnish-7.1.1/debian/patches/0001-req_fsm-Close-the-connection-on-a-malformed-request.patch
    --- varnish-7.1.1/debian/patches/0001-req_fsm-Close-the-connection-on-a-malformed-request.patch 1970-01-01 02:00:00.000000000 +0200
    +++ varnish-7.1.1/debian/patches/0001-req_fsm-Close-the-connection-on-a-malformed-request.patch 2025-03-31 16:06:35.000000000 +0300
    @@ -0,0 +1,53 @@
    +From 07c5b24e265b2b852c23ec492fe425b575fd43cb Mon Sep 17 00:00:00 2001
    +From: D
  • From Debian Bug Tracking System@21:1/5 to All on Mon Apr 14 22:00:01 2025
    Processing control commands:

    tag -1 confirmed
    Bug #1101775 [release.debian.org] bookworm-pu: package varnish/7.1.1-1.1+deb12u1
    Added tag(s) confirmed.

    --
    1101775: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1101775
    Debian Bug Tracking System
    Contact [email protected] with problems

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Debian Bug Tracking System@21:1/5 to All on Sat May 17 11:50:17 2025
    This is a multi-part message in MIME format...

    Your message dated Sat, 17 May 2025 09:37:58 +0000
    with message-id <[email protected]>
    and subject line Close 1101775
    has caused the Debian Bug report #1101775,
    regarding bookworm-pu: package varnish/7.1.1-1.1+deb12u1
    to be marked as done.

    This means that you claim that the problem has been dealt with.
    If this is not the case it is now your responsibility to reopen the
    Bug report if necessary, and/or fix the problem forthwith.

    (NB: If you are a system administrator and have no idea what this
    message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected]
    immediately.)


    --
    1101775: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1101775
    Debian Bug Tracking System
    Contact [email protected] with problems

    Received: (at submit) by bugs.debian.org; 31 Mar 2025 21:13:55 +0000 X-Spam-Checker-Version: SpamAssassin 3.4.6-bugs.debian.org_2005_01_02
    (2021-04-09) on buxtehude.debian.org
    X-Spam-Level:
    X-Spam-Status: No, score=-122.3 required=4.0 tests=BAYES_00,
    BODY_INCLUDES_PACKAGE,DKIMWL_WL_HIGH,DKIM_SIGNED,DKIM_VALID,
    DKIM_VALID_AU,DKIM_VALID_EF,FOURLA,FROMDEVELOPER,HAS_PACKAGE,
    MD5_SHA1_SUM,SPF_HELO_NONE,SPF_NONE,UNPARSEABLE_RELAY,
    USER_IN_DKIM_WELCOMELIST,USER_IN_DKIM_WHITELIST,XMAILER_REPORTBUG
    autolearn=ham autolearn_force=no
    version=3.4.6-bugs.debian.org_2005_01_02
    X-Spam-Bayes: score:0.0000 Tokens: new, 81; hammy, 150; neutral, 134; spammy,
    0. spammytokens:
    hammytokens:0.000-+--Hx-spam-relays-external:sk:stravin,
    0.000-+--H*RT:sk:stravin, 0.000-+--Hx-spam-relays-external:311,
    0.000-+--H*RT:311, 0.000-+--H*RT:108
    Return-path: <[email protected]