Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1203718 > unrolled thread

Bug#1076016: bullseye-pu: package dropbear/2020.81-3+deb11u2

Started byGuilhem Moulin <guilhem@debian.org>
First post2024-07-09 17:30 +0200
Last post2024-08-16 22:50 +0200
Articles 3 — 3 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#1076016: bullseye-pu: package dropbear/2020.81-3+deb11u2 Guilhem Moulin <guilhem@debian.org> - 2024-07-09 17:30 +0200
    Bug#1076016: bullseye-pu: package dropbear/2020.81-3+deb11u2 "Adam D. Barratt" <adam@adam-barratt.org.uk> - 2024-08-14 21:40 +0200
    Bug#1076016: dropbear 2020.81-3+deb11u2 flagged for acceptance Adam D Barratt <adam@adam-barratt.org.uk> - 2024-08-16 22:50 +0200

#1203718 — Bug#1076016: bullseye-pu: package dropbear/2020.81-3+deb11u2

FromGuilhem Moulin <guilhem@debian.org>
Date2024-07-09 17:30 +0200
SubjectBug#1076016: bullseye-pu: package dropbear/2020.81-3+deb11u2
Message-ID<IYkX0-VMN-13@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Package: release.debian.org
Severity: normal
Tags: bullseye
X-Debbugs-Cc: dropbear@packages.debian.org
Control: affects -1 + src:dropbear
User: release.debian.org@packages.debian.org
Usertags: pu

[ Reason ]

Keepalive packets are being ignored when the ‛-k’ flag (or
‛no-port-forwarding’ authorized_keys(5) restriction) is used.

AFAICT buster is affected as well, so this is not a regression in
bullseye.

[ Impact ]

dropbear-initramfs users unlocking the root file system remotely with
message keepalive enabled (ssh -oServerAliveInterval≠0) might lock
themselves out, see #1069768.

[ Tests ]

I did manually tests that dropbear-bin=2020.81-3+deb11u2 replies to
message keepalives even when remote TCP forwarding is disabled.

[ Risks ]

The patch is trivial and was cleanly cherry-picked from upstream.
With 2020.81-3+deb11u1, the workarounds to prevent being locked out
is to either disable message keepalives on the SSH client, or not to
disable remote TCP forwarding on the SSH server (dropbear).

[ Checklist ]

  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in oldstable
  [x] the issue is verified as fixed in unstable

[ Changes ]

Cherry-pick upstream patch to fix noremotetcp behavior.  Keepalive
packets were being ignored when the ‛-k’ flag (or ‛no-port-forwarding’
authorized_keys(5) restriction) was used.  (Closes: #1069768)

-- 
Guilhem.

[toc] | [next] | [standalone]


#1208392

From"Adam D. Barratt" <adam@adam-barratt.org.uk>
Date2024-08-14 21:40 +0200
Message-ID<Jbs0F-51cG-1@gated-at.bofh.it>
In reply to#1203718
Control: tags -1 + confirmed

On Tue, 2024-07-09 at 17:20 +0200, Guilhem Moulin wrote:
> Keepalive packets are being ignored when the ‛-k’ flag (or
> ‛no-port-forwarding’ authorized_keys(5) restriction) is used.

Please go ahead.

Regards,

Adam

[toc] | [prev] | [next] | [standalone]


#1208654 — Bug#1076016: dropbear 2020.81-3+deb11u2 flagged for acceptance

FromAdam D Barratt <adam@adam-barratt.org.uk>
Date2024-08-16 22:50 +0200
SubjectBug#1076016: dropbear 2020.81-3+deb11u2 flagged for acceptance
Message-ID<Jcc3w-5uk8-31@gated-at.bofh.it>
In reply to#1203718
package release.debian.org
tags 1076016 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==============

Package: dropbear
Version: 2020.81-3+deb11u2

Explanation: fix "noremotetcp" behaviour of keepalive packets in combination with the ‛no-port-forwarding’ authorized_keys(5) restriction

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web