| Summary: | xdg-open: firefox: execv: /usr/lib64/firefox/firefox: Bad address при количестве переменных > 120 | ||
|---|---|---|---|
| Product: | Sisyphus | Reporter: | Evgeny Shesteperov <alimektor> |
| Component: | firefox | Assignee: | Ajrat Makhmutov <rauty> |
| Status: | CLOSED FIXED | QA Contact: | qa-sisyphus |
| Severity: | normal | ||
| Priority: | P5 | CC: | boguslavskijbj, legion, rauty, sbolshakov |
| Version: | unstable | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
|
Description
Evgeny Shesteperov
2025-09-28 14:46:08 MSK
Воспроизводится, если переменных окружения больше 120. $ env | wc -l 120 Воспроизвёл: rauty@ajratkogda ~/git/alt/task-edu sisyphus @ env | wc -l 114 rauty@ajratkogda ~/git/alt/task-edu sisyphus @ env RAZ= DVA= TRI= CHETIRE= PYAT= SHEST= | wc -l 120 rauty@ajratkogda ~/git/alt/task-edu sisyphus @ env RAZ= DVA= TRI= CHETIRE= PYAT= SHEST= firefox 'google.com' # открылось rauty@ajratkogda ~/git/alt/task-edu sisyphus @ env RAZ= DVA= TRI= CHETIRE= PYAT= SHEST= xdg-open 'google.com' # открылось rauty@ajratkogda ~/git/alt/task-edu sisyphus @ env RAZ= DVA= TRI= CHETIRE= PYAT= SHEST= SEM= | wc -l 121 rauty@ajratkogda ~/git/alt/task-edu sisyphus [127] @ env RAZ= DVA= TRI= CHETIRE= PYAT= SHEST= SEM= firefox 'google.com' firefox: execv: /usr/lib64/firefox/firefox: Bad address env RAZ= DVA= TRI= CHETIRE= PYAT= SHEST= SEM= VOSEM= /usr/lib64/firefox/firefox 'google.com' # открылось Проблема в wrapper'е. Евгений, проверьте пожалуйста с таском https://packages.altlinux.org/en/tasks/396308/ firefox-143.0.4-alt1 -> sisyphus: Sun Oct 12 2025 Ajrat Makhmutov <rauty@altlinux> 143.0.4-alt1 - New version (143.0.4). Thu Oct 02 2025 Ajrat Makhmutov <rauty@altlinux> 143.0.3-alt1 - New version (143.0.3). - Fix the new_argv to match the standard argv format in the wrapper (Closes: 56190). - Fixes: + CVE-2025-11152: Sandbox escape due to integer overflow in the Graphics: Canvas2D component + CVE-2025-11153: JIT miscompilation in the JavaScript Engine: JIT component *** Bug 54966 has been marked as a duplicate of this bug. *** (Ответ для Ajrat Makhmutov на комментарий #3) > Евгений, проверьте пожалуйста Исправлено, спасибо! |