Pillow icon indicating copy to clipboard operation
Pillow copied to clipboard

Updated xz to 5.6.2

Open radarhere opened this issue 1 year ago • 8 comments

https://github.com/tukaani-project/xz/releases/tag/v5.4.6

radarhere avatar Mar 29 '24 22:03 radarhere

I'm assuming you are aware of CVE-2024-3094 and didn't upgrade to 5.6.1 for that reason. Perhaps it is an overreaction at this point, but I'm wondering if we should consider completely removing liblzma from the wheels for the upcoming release. liblzma is only an indirect optional dependency via libtiff and users could just install from source if they need it.

nulano avatar Mar 30 '24 07:03 nulano

Yes, we're aware. I'd like to hold off on merging this until more clarity comes out of this from the experts. Xz is deeply in use in debian (e.g. dpkg) so they're digging pretty heavily now (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024).

wiredfool avatar Mar 30 '24 09:03 wiredfool

xz 5.6.2 has now been released - https://github.com/tukaani-project/xz/releases/tag/v5.6.2

https://tukaani.org/xz-backdoor/

There was discussion if the 5.6.x version numbers shouldn’t be used further and the next release could be 5.8.0. However, it felt clearer to make XZ Utils 5.6.2 as a cleanup step. There are a few small improvements planned which could become 5.8.0 in shorter time than usual, hopefully replacing 5.6.x somewhat soon.

radarhere avatar May 29 '24 23:05 radarhere

Should we also switch to using the GitHub release instead of SourceForge? https://github.com/python-pillow/Pillow/blob/114e01701ac92d6bd1df7df771a2be8abcc0ae33/winbuild/build_prepare.py#L179

Multibuild uses https://tukaani.org/xz/xz-5.6.2.tar.gz which is a redirect to the GitHub release:

C:\Users\Nulano>curl --head https://tukaani.org/xz/xz-5.6.2.tar.gz
HTTP/1.1 302 Found
Server: nginx
Date: Wed, 12 Jun 2024 18:51:24 GMT
Content-Type: text/html; charset=iso-8859-1
Content-Length: 262
Connection: keep-alive
Location: https://github.com/tukaani-project/xz/releases/download/v5.6.2/xz-5.6.2.tar.gz
X-Proxy-Cache: BYPASS
X-Powered-By: Zoner

nulano avatar Jun 12 '24 18:06 nulano

Ok, GitHub does look to be the primary repository. I've pushed a commit.

radarhere avatar Jun 13 '24 01:06 radarhere

My thinking on this: I don't see anything particularly urgent/important in the changelog to merge this right now, so maybe we hold off for another release or so?

hugovk avatar Jun 13 '24 05:06 hugovk

Another release or so of ours, or of xz? I'm guessing you mean xz, as a way of increasing confidence that they have reviewed their code thoroughly.

radarhere avatar Jun 13 '24 06:06 radarhere

Of ours, but that could also include of xz :)

Yeah, I don't think we're in a rush to upgrade, and it gives some more time for the dust to settle.

hugovk avatar Jun 13 '24 08:06 hugovk

More time has passed and things have settled. Any objections to merging this for our release next month?

hugovk avatar Sep 04 '24 10:09 hugovk

No objections.

radarhere avatar Sep 04 '24 11:09 radarhere