oss-sec mailing list archives

Re: ncurses fixes upstream


From: Sam James <sam () gentoo org>
Date: Thu, 13 Apr 2023 02:07:48 +0100


"Jonathan Bar Or (JBO)" <jobaror () microsoft com> writes:

Hello oss-security,

Our team has worked with the maintainer of the ncurses library (used by several software packages in Linux) to fix 
several memory corruption vulnerabilities.
They are now fixed at commit 20230408 - see details here 
(https://invisible-island.net/ncurses/NEWS.html#index-t20230408)
A CVE was assigned (CVE-2023-29491) - it's still under a "reserved" status.

How can we ensure those fixes get deployed upstream, in major Linux distributions?

Try emailing the distributions mailing list at lists.linux.dev too?

We've reached out to Arch, RedHat, Canonical and other popular distros independently.

Thanks!
                             JBO

Attachment: signature.asc
Description:


Current thread: