Re: Strange DNS SRV traffic resulting from stat() in 1.8.13.2
Jeffrey Altman <[email protected]> Thu, 28 Aug 2025 20:42:43 -0400
| Newsgroups | gmane.comp.file-systems.openafs.general |
|---|---|
| Message-ID | <[email protected]> |
> On Aug 28, 2025, at 4:30=E2=80=AFPM, Cheyenne Wills = <[email protected]> wrote: >=20 > The patches for OpenAFS have been submitted for the master branch and > are currently under review. They will be included in an upcomming > 1.8.14pre1, that is still being finalized. >=20 > Again thank's to Jeffery and Marc for their investigative work. S/Jeffery/Jeffrey/ > I do want to mention that the commit that introduced the bug wasn't = yet > in a tagged stable release (though it was in the pending stack for the > upcoming 1.8.14 work). OpenAFS 0306f3fdac736e15620f5802bdce510d25bb2450 was included in = packaged and tagged =E2=80=9Copenafs" releases from both OpenSUSE, Debian, Ubuntu = and Fedora. Although it is true that the OpenAFS release team has not tagged a = release=20 within the openafs git repository that it manages, Debian, Ubuntu, = OpenSUSE and Fedora took 0306f3fdac73 as part of the stack of changes necessary = to support 6.14 kernels based upon advice received from openafs developers: = https://lists.openafs.org/pipermail/openafs-devel/2025-April/021060.html In my opinion a CVE should be published by OpenAFS referencing the = commit=20 which can be referenced by all of the downstream distributions which = included it. Jeffrey Altman