Re: BerkeleyDB CVEs

Jeremy Stanley <[email protected]> Fri, 26 Sep 2025 14:45:17 +0000
Newsgroups gmane.linux.debian.devel.security
Message-ID <[email protected]>
--tAKMI2NHraJlO/Qk
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On 2025-09-26 12:43:43 +0000 (+0000), Tom=C3=A1=C5=A1 Mac=C3=A1k wrote:
[...]
> They came up with list of high criticality CVEs from Oracle=20
> Berkeley DB libdb5.3 package, which on your tracker list are=20
> marked as =E2=80=9CNOT-FOR-US: Oracle=E2=80=9D. They argue that package=
=20
> libdb5.3/5.3.28 is installed which is affected accrding to Oracle=20
> (https://www.oracle.com/security-alerts/cpuapr2017.html#AppendixTOOL)=20
> thus we=E2=80=99re vulnerable
[...]

Spot checking a bunch of the ones you listed in Debian's security=20
tracker, it looks like they're either flagged as specific to=20
Oracle's closed source Berkeley DB product:

https://security-tracker.debian.org/tracker/CVE-2016-0689

=2E..or Oracle did not supply sufficient public information for anyone=20
to be able to identify what the fix was so that it could be=20
confirmed as affecting Debian much less backported:

https://security-tracker.debian.org/tracker/CVE-2015-2624

My perspective as both an upstream free/libre open source software=20
project vulnerability manager as well as a sysadmin responsible for=20
securing a vast number of Internet-connected systems is that=20
BlackDuck's scanner isn't all that useful due to woefully=20
insufficient report context, its inability to identify backported=20
fixes in distributions, and the *terrible* misconception that the=20
existence of a CVE necessarily implies an actual security risk (I've=20
given up disputing the endless flood of useless CVEs I see reported=20
any more).

And Oracle's not helping matters, they're notorious since decades=20
for being intentionally tight-lipped about any security issues they=20
fix in their products.

The other thing to pay attention to is that db5.3 is orphaned and=20
newer versions aren't suitably licensed for main, so BDB has no real=20
future in Debian:

https://bugs.debian.org/1055356

In short, I don't think you're going to get any satisfactory answer=20
to your question because the situation itself is unsatisfactory.
--=20
Jeremy Stanley

--tAKMI2NHraJlO/Qk
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQKTBAABCgB9FiEEl65Jb8At7J/DU7LnSPmWEUNJWCkFAmjWpvdfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDk3
QUU0OTZGQzAyREVDOUZDMzUzQjJFNzQ4Rjk5NjExNDM0OTU4MjkACgkQSPmWEUNJ
WCmU8xAAnNm3do5w9Fgf06y1KYYrf4jEWTocNYC97Ne0SkNZCNKQ9E4YdZGtIdcs
1V01/2E+9yLzx9GHckDlnuGgZmvCTZwhxgWwAsR8JY3XQ6f6A5BKvcYyhrbgqPOT
Aoh6ciEe553LpR3SPeBlTfiwp3PbWIvpfxcsalPg8HWif8smLGC3v5K3Xjl3eEYq
FdoXXRvi647NKK6ZKep9sR8BIDXVUSccMI9O8KNTAseYx1QJ/LEMwj/xHs6p+Vcz
5JV7Z2r+F89zky8E6w6r6svLx4L6vKo+B3u4HEOEO4PmjeMsXNBfNtIMonNRhUum
I2PCvqDeBzqyWUTj3T9LnkT1qpAtd69RVPEHapF/mjPj/LEMFQApyxE4CYx3K+T6
aPZY+a+bbMq/hU2lwa+7HNYRi+KfEFVI3GmGpWrC74/wiyaH7dQtAZq1EGAEz1b6
lA5XHKKoyBOGRmCb69HhYPcS9MDXA+4DK4eLxHh1ydiizp9UDWDAct7WUhhVCBrb
R9kzAsYhw2+CSGOBM7KILsxyTCumqA1k3QknDgKLwL8KhhCfdoNkl1QI1BwDcMi4
aGePQ/62cil73O/ku9XqsnwBRfCaswii8ARY0H5T3LXiCrZIcXNOBhh/8ZQtH8VT
QHGDH3JFBCu64JdnJaLv0iSCHq+ua0W3HGQPEo6vL4jj9tlqpFw=
=MI1n
-----END PGP SIGNATURE-----

--tAKMI2NHraJlO/Qk--