Activity log for bug #1939396

Date Who What changed Old value New value Message
2021-08-10 11:37:02 Christian Ehrhardt  bug added bug
2021-08-10 11:38:11 Christian Ehrhardt  postgresql-10 (Ubuntu Bionic): status New Triaged
2021-08-10 11:38:13 Christian Ehrhardt  postgresql-12 (Ubuntu): status New Invalid
2021-08-10 11:38:15 Christian Ehrhardt  postgresql-12 (Ubuntu Focal): status New Triaged
2021-08-10 11:38:17 Christian Ehrhardt  postgresql-13 (Ubuntu Hirsute): status New Triaged
2021-08-10 11:38:20 Christian Ehrhardt  postgresql-13 (Ubuntu Impish): status New Triaged
2021-08-10 12:03:24 Christian Ehrhardt  information type Private Private Security
2021-08-10 12:08:51 Christian Ehrhardt  description [Impact] * MRE for latest stable fixes of Postgres released on May 2021 [Test Case] * The Postgres MREs traditionally rely on the large set of autopkgtests to run for verification. In a PPA those are all already pre-checked to be good for this upload. [Regression Potential] * Upstreams tests are usually great and in additon in the Archive there are plenty of autopkgtests that in the past catched issues before being released. But never the less there always is a risk for something to break. Since these are general stable releases I can't pinpoint them to a most-likely area. - usually this works smoothly except a few test hickups (flaky) that need to be clarified to be sure. Pre-checks will catch those to be discussed upfront (as last time) [Other Info] * This is a reoccurring MRE, see below and all the references * AFAICS no CVEs this time --- Current versions in supported releases that got updates: postgresql-13 | 13.3-1build1 | impish | source, amd64, arm64, armhf, i386, ppc64el, riscv64, s390x postgresql-13 | 13.3-0ubuntu0.21.04.1 | hirsute-updates | source, amd64, arm64, armhf, i386, ppc64el, riscv64, s390x postgresql-12 | 12.7-0ubuntu0.20.04.1 | focal-updates | source, amd64, arm64, armhf, i386, ppc64el, riscv64, s390x postgresql-10 | 10.17-0ubuntu0.18.04.1 | bionic-updates | source, amd64, arm64, armhf, i386, ppc64el, s390x Special cases: - Impish is soon synced from Debian as usual. Standing MRE - Consider last updates as template: - pad.lv/1637236 - pad.lv/1664478 - pad.lv/1690730 - pad.lv/1713979 - pad.lv/1730661 - pad.lv/1747676 - pad.lv/1752271 - pad.lv/1786938 - pad.lv/1815665 - pad.lv/1828012 - pad.lv/1833211 - pad.lv/1839058 - pad.lv/1863108 - pad.lv/1892335 - pad.lv/1915254 - pad.lv/1928773 As usual we test and prep from the PPA and then push through SRU/Security as applicable. [Impact]  * MRE for latest stable fixes of Postgres released on May 2021 [Test Case]  * The Postgres MREs traditionally rely on the large set of autopkgtests    to run for verification. In a PPA those are all already pre-checked to    be good for this upload. [Regression Potential]  * Upstreams tests are usually great and in additon in the Archive there    are plenty of autopkgtests that in the past catched issues before being    released.    But never the less there always is a risk for something to break. Since    these are general stable releases I can't pinpoint them to a most-likely    area.    - usually this works smoothly except a few test hickups (flaky) that need to be      clarified to be sure. Pre-checks will catch those to be discussed upfront (as last time) [Other Info]  * This is a reoccurring MRE, see below and all the references  * CVEs this time - CVE-2021-3677 (v13) - Fix related to CVE-2021-3449 (v10, v12, v13) - while being an openssl issue it affects derived programs built against 1.1.0h and newer which translates into >=bionic thereby (v10, v12, v13) - related to CVE-2006-2313 (v10, v12, v13) - this is only "similar" but not the same so the changelog will not reference it --- Current versions in supported releases that got updates:  postgresql-13 | 13.3-1build1 | impish | source, amd64, arm64, armhf, i386, ppc64el, riscv64, s390x  postgresql-13 | 13.3-0ubuntu0.21.04.1 | hirsute-updates | source, amd64, arm64, armhf, i386, ppc64el, riscv64, s390x  postgresql-12 | 12.7-0ubuntu0.20.04.1 | focal-updates | source, amd64, arm64, armhf, i386, ppc64el, riscv64, s390x  postgresql-10 | 10.17-0ubuntu0.18.04.1 | bionic-updates | source, amd64, arm64, armhf, i386, ppc64el, s390x Special cases: - Impish is soon synced from Debian as usual. Standing MRE - Consider last updates as template: - pad.lv/1637236 - pad.lv/1664478 - pad.lv/1690730 - pad.lv/1713979 - pad.lv/1730661 - pad.lv/1747676 - pad.lv/1752271 - pad.lv/1786938 - pad.lv/1815665 - pad.lv/1828012 - pad.lv/1833211 - pad.lv/1839058 - pad.lv/1863108 - pad.lv/1892335 - pad.lv/1915254 - pad.lv/1928773 As usual we test and prep from the PPA and then push through SRU/Security as applicable.
2021-08-11 08:04:40 Christian Ehrhardt  postgresql-10 (Ubuntu Bionic): status Triaged Fix Committed
2021-08-12 16:18:59 Christian Ehrhardt  information type Private Security Public Security
2021-08-12 17:11:14 Launchpad Janitor postgresql-10 (Ubuntu Bionic): status Fix Committed Fix Released
2021-08-12 17:11:14 Launchpad Janitor cve linked 2021-3449
2021-08-12 17:11:16 Launchpad Janitor postgresql-12 (Ubuntu Focal): status Triaged Fix Released
2021-08-13 07:12:46 Christian Ehrhardt  postgresql-13 (Ubuntu Hirsute): status Triaged Fix Released
2021-08-13 07:12:48 Christian Ehrhardt  postgresql-13 (Ubuntu Impish): status Triaged Fix Committed