Fedora Linux 8567 Published by

A galera security update has been released for Fedora 31.



SECURITY: Fedora 31 Update: galera-25.3.31-1.fc31


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2020-ac2d47d89a
2020-11-11 01:31:11.923446
--------------------------------------------------------------------------------

Name : galera
Product : Fedora 31
Version : 25.3.31
Release : 1.fc31
URL :   http://galeracluster.com/
Summary : Synchronous multi-master wsrep provider (replication engine)
Description :
Galera is a fast synchronous multi-master wsrep provider (replication engine)
for transactional databases and similar applications. For more information
about wsrep API see   http://launchpad.net/wsrep. For a description of Galera
replication engine see   http://www.codership.com.

--------------------------------------------------------------------------------
Update Information:

**MariaDB 10.3.26** **MariaDB connector C/C++ 3.1.11** **Galera 25.3.26**
Release notes:   https://mariadb.com/kb/en/mariadb-10326-release-notes/
  https://mariadb.com/kb/en/mariadb-connector-c-3111-release-notes/ ----
**MariaDB 10.3.25** Release notes:
  https://mariadb.com/kb/en/mariadb-10325-release-notes/
--------------------------------------------------------------------------------
ChangeLog:

* Wed Nov 4 2020 Michal Schorm - 25.3.31-1
- Rebase to 25.3.31
* Mon Oct 26 2020 Michal Schorm - 25.3.30-1
- Rebase to 25.3.30
* Fri Jun 5 2020 Michal Schorm - 25.3.29-1
- Rebase to 25.3.29
Resolves: rhbz#1546787
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #1830119 - CVE-2020-2752 CVE-2020-2760 CVE-2020-2812 CVE-2020-2814 mariadb:10.3/mariadb: various flaws [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1830119
[ 2 ] Bug #1843796 - CVE-2020-13249 mariadb:10.3/mariadb: mariadb-connector-c: Improper validation of content in a OK packet received from server [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1843796
[ 3 ] Bug #1846527 - CVE-2020-2780 mariadb:10.3/mariadb: mysql: Server: DML unspecified vulnerability (CPU Apr 2020) [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1846527
[ 4 ] Bug #1894078 - CVE-2020-14765 CVE-2020-14776 CVE-2020-14789 CVE-2020-14812 mariadb: various flaws [fedora-31]
  https://bugzilla.redhat.com/show_bug.cgi?id=1894078
[ 5 ] Bug #1894663 - mariadb-connector-c-3.1.11 is available
  https://bugzilla.redhat.com/show_bug.cgi?id=1894663
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2020-ac2d47d89a' at the command
line. For more information, refer to the dnf documentation available at
  http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
  https://fedoraproject.org/keys