← Back to team overview

ubuntu-docker-images team mailing list archive

Re: mysql contains outdated Ubuntu packages

 

On Tuesday, October 26 2021, security-team-toolbox-bot@xxxxxxxxxxxxx wrote:

> A scan of this rock shows that it was built with packages from the Ubuntu
> archive that have since received security updates. The following lists new
> USNs for affected binary packages in each rock revision:
>
> Revision r01a5d68efb42 (ppc64le; channels: 8.0-20.04_beta, 8.0-20.04_edge)
>  * mysql-client-8.0: 5123-1
>  * mysql-client-core-8.0: 5123-1
>  * mysql-server-core-8.0: 5123-1
>
> Revision r0363e6dffb4b (amd64; channels: latest, edge, 8.0-21.04_beta, 8.0-21.04_edge)
>  * mysql-client-8.0: 5123-1
>  * mysql-client-core-8.0: 5123-1
>  * mysql-server-core-8.0: 5123-1
>
> Revision r54b60a6c940e (s390x; channels: latest, edge, 8.0-21.04_beta, 8.0-21.04_edge)
>  * mysql-client-8.0: 5123-1
>  * mysql-client-core-8.0: 5123-1
>  * mysql-server-core-8.0: 5123-1
>
> Revision r95e9d8142600 (s390x; channels: 8.0-20.04_beta, 8.0-20.04_edge)
>  * mysql-client-8.0: 5123-1
>  * mysql-client-core-8.0: 5123-1
>  * mysql-server-core-8.0: 5123-1
>
> Revision ra190110ef335 (ppc64le; channels: latest, edge, 8.0-21.04_beta, 8.0-21.04_edge)
>  * mysql-client-8.0: 5123-1
>  * mysql-client-core-8.0: 5123-1
>  * mysql-server-core-8.0: 5123-1
>
> Revision rb728175eb628 (arm64; channels: latest, edge, 8.0-21.04_beta, 8.0-21.04_edge)
>  * mysql-client-8.0: 5123-1
>  * mysql-client-core-8.0: 5123-1
>  * mysql-server-core-8.0: 5123-1
>
> Revision rd26686ff653e (arm64; channels: 8.0-20.04_beta, 8.0-20.04_edge)
>  * mysql-client-8.0: 5123-1
>  * mysql-client-core-8.0: 5123-1
>  * mysql-server-core-8.0: 5123-1
>
> Revision re9c5bb3d0f08 (amd64; channels: 8.0-20.04_beta, 8.0-20.04_edge)
>  * mysql-client-8.0: 5123-1
>  * mysql-client-core-8.0: 5123-1
>  * mysql-server-core-8.0: 5123-1
>
> Simply rebuilding the rock will pull in the new security updates and
> resolve this. If your rock also contains vendored code, now might be a
> good time to review it for any needed updates.
>
> Thank you for your rock and for attending to this matter.
>
> References:
>  * https://ubuntu.com/security/notices/USN-5123-1/

Hi guys,

I'm busy with the sprint this week, and I'm replying to this email
because Athos told me he didn't get it.  I talked to him and he'll
handle this one.

Thanks,

-- 
Sergio
GPG key ID: E92F D0B3 6B14 F1F4 D8E0  EB2F 106D A1C8 C3CB BF14