Debian Patches
Status for libreoffice/4:25.2.3-2+deb13u8
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| CVE-2026-6040.diff | process loext:blank-width-char better | Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-04-09 | ||
| disable-flaky-tests.diff | 14:13 < mst__> _rene_, the toolkit unoapi tests are known to be flaky (in some system dependent way) e.g. on the Win@6 tinderbox it always crashes 14:14 < mst__> _rene_, sc.ScAccessible* tests also fail on some systems some of the time diff --git a/toolkit/Module_toolkit.mk b/toolkit/Module_toolkit.mk index 25db0b6..14e507c 100644 |
no | ||||
| fix-internal-hsqldb-build.diff | diff -urN hsqldb.old/patches/use-system-servlet-api.jar.diff hsqldb/patches/use-system-servlet-api.jar.diff | no | ||||
| javadoc-optional.diff | Gemeinsame Unterverzeichnisse: odk-old/config und odk/config. Gemeinsame Unterverzeichnisse: odk-old/docs und odk/docs. Gemeinsame Unterverzeichnisse: odk-old/examples und odk/examples. diff --git a/odk/Module_odk.mk b/odk/Module_odk.mk index 693885322115..5fcb39306a0b 100644 |
no | ||||
| no-packagekit-per-default.diff | diff --git a/officecfg/registry/data/org/openoffice/Office/Common.xcu b/officecfg/registry/data/org/openoffice/Office/Common.xcu index 3d138551b593..9cb9831f3236 100644 |
no | ||||
| system-officeotron-and-odfvalidator.diff | diff --git a/bin/odfvalidator.sh.in b/bin/odfvalidator.sh.in index 56e2f29..9415ef6 100644 |
no | ||||
| cppunit-optional.diff | diff --git a/configure.ac b/configure.ac index c12fe95a561c..66d327ae8fb8 100644 |
no | ||||
| apparmor-complain.diff | diff --git a/sysui/desktop/apparmor/program.oosplash b/sysui/desktop/apparmor/program.oosplash index fef54b7ee384..9dde31a63615 100644 |
no | ||||
| hide-math-desktop-file.patch | Hide startcenter and math from the shell | Olivier Tilloy <olivier.tilloy@canonical.com> | not-needed | |||
| appstream-ignore-startcenter.diff | no | |||||
| disable-java-in-odk-build-examples-on-zero-vm.diff | diff --git a/config_host.mk.in b/config_host.mk.in index 6cea6ccf795e..d08fac922239 100644 |
no | ||||
| do-not-hide-test-output.diff | diff --git a/odk/build-examples_common.mk b/odk/build-examples_common.mk index abcb3a3e2593..35d45ad23413 100644 |
no | ||||
| apparmor-allow-java.security.diff | diff --git a/sysui/desktop/apparmor/program.soffice.bin b/sysui/desktop/apparmor/program.soffice.bin index 2fc7fd6b5735..3fd82b08431e 100644 |
no | ||||
| apparmor-cleanups.diff | apparmor: use dri-enumerate abstraction Remove backported rule and use new dri-enumerate abstraction instead. dri-enumerate is available in AppArmor 2.13, which recently migrated into Debian Buster. |
Vincas Dargis <vindrg@gmail.com> | no | 2018-08-04 | ||
| apparmor-mesa.diff | no | |||||
| disableClassPathURLCheck.diff | no | |||||
| use-mariadb-java-instead-of-mysql-java.diff | mariadb | Markus Koschany <apo@debian.org> | no | 2018-11-09 | ||
| apparmor-opencl.diff | AppArmor in Debian Buster now has OpenCL abstractions. Include OpenCL abstractions to fix OpenCL usage in Calc. =================================================================== |
no | ||||
| fix-flaky-bridgetest.diff | Add safer float comparisons to bridgetest equals() | Marcus Tomlinson <marcus.tomlinson@canonical.com> | no | |||
| add-access2base-doc.diff | no | |||||
| disable-shortcuts_tab_navigation-uitest.diff | no | |||||
| no-opencl-per-default.diff | Resolves: rhbz#1432468 disable opencl by default | Caolán McNamara <caolanm@redhat.com> | no | 2017-03-27 | ||
| apparmor-updates.diff | diff --git a/sysui/desktop/apparmor/program.soffice.bin b/sysui/desktop/apparmor/program.soffice.bin index 42053db2abef..bf48bdb1e44d 100644 |
no | ||||
| apparmor-gnupg-tofu.diff | Support tofu+pgp trust model in GnuPG GnuPG supports a trust-on-first-use layer that sits on top of the standard PGP trust model. If this is enabled, 'gpg --list-keys' needs write and lock permissions on the TOFU database to return any useful data. Allow this access through AppArmor. |
Benjamin Barenblat <bbaren@google.com> | no | debian | ||
| arm-fp-mode.diff | Explicitly set fpu mode on armhf diff --git a/bridges/source/cpp_uno/gcc3_linux_arm/armhelper.S b/bridges/source/cpp_uno/gcc3_linux_arm/armhelper.S index 4eff3ff0a012..7996b9c5b3f0 100644 |
Rico Tzschichholz <ricotz@ubuntu.com> | no | |||
| moreIconsDialog-accesses-internet.diff | diff --git a/cui/source/dialogs/AdditionsDialog.cxx b/cui/source/dialogs/AdditionsDialog.cxx index a8eabf6d369c..676add18204e 100644 |
no | ||||
| do-not-abort-on-NON_APPLICATION_FONT_USE.diff | diff --git a/solenv/gbuild/CppunitTest.mk b/solenv/gbuild/CppunitTest.mk index b16e3d0e5417..33bdde04b072 100644 |
no | ||||
| we-dont-have-the-needed-fonts.diff | diff --git a/sw/qa/core/text/text.cxx b/sw/qa/core/text/text.cxx index a4d4540ab228..46d262f6f0b8 100644 |
no | ||||
| adapt-for-new-carlito.diff | diff --git a/sw/qa/extras/layout/layout3.cxx b/sw/qa/extras/layout/layout3.cxx index 7f62a3a9d6b8..ec1567a564dc 100644 |
no | ||||
| pdfium-ports.diff | no | |||||
| CVE-2026-6039.diff | stay within max Polygon points | Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-04-09 | ||
| debian-opt.diff | diff --git a/configure.ac b/configure.ac index f06ef8e..91ce612 100644 |
no | ||||
| jurt-soffice-location.diff | commit b71107fb12e3c3125e0cb62c5a4f6636a80c6408 on debian-based systems, we know where our soffice binary is diff --git a/jurt/com/sun/star/lib/util/NativeLibraryLoader.java b/jurt/com/sun/star/lib/util/NativeLibraryLoader.jav index da22980..36664ca 100644 |
Bjoern Michaelsen <bjoern.michaelsen@canonical.com> | no | |||
| splits-adapt-registry.diff | diff --git a/scp2/source/gnome/file_gnome.scp b/scp2/source/gnome/file_gnome.scp index c7a13c8..a3f59a6 100644 |
no | ||||
| debian-debug.diff | diff --git a/solenv/gbuild/platform/com_GCC_defs.mk b/solenv/gbuild/platform/com_GCC_defs.mk index 9de88a2..9161a4e 100644 |
no | ||||
| build-against-shared-lpsolve.diff | diff --git a/configure.ac b/configure.ac index cdae8b5..49f3ba2 100644 |
no | ||||
| install-fixes.diff | diff --git a/bin/distro-install-file-lists b/bin/distro-install-file-lists index eaabf9c..c1b1ec6 100755 |
no | ||||
| mention-java-common-package.diff | diff --git a/jvmfwk/plugins/sunmajor/javaenvsetup/javaldx.cxx b/jvmfwk/plugins/sunmajor/javaenvsetup/javaldx.cxx index 718902caba6f..3c8499b5a42c 100644 |
no | ||||
| help-msg-add-package-info.diff | diff --git a/include/sfx2/strings.hrc b/include/sfx2/strings.hrc index 1b0ea6ccb2ff..630f4330552a 100644 |
no | ||||
| sensible-lomua.diff | =================================================================== | no | ||||
| reportdesign-mention-package.diff | diff --git a/dbaccess/inc/strings.hrc b/dbaccess/inc/strings.hrc index 47068f43d09e..1f8b9a2331b6 100644 |
no | ||||
| jdbc-driver-classpaths.diff | diff --git a/officecfg/registry/data/org/openoffice/Office/DataAccess.xcu b/officecfg/registry/data/org/openoffice/Office/DataAccess.xcu index 9be30a2..59c87cb 100644 |
no | ||||
| make-package-modules-not-suck.diff | diff --git a/scp2/InstallModule_draw.mk b/scp2/InstallModule_draw.mk index a7c02be..d48edf2 100644 |
no | ||||
| mediwiki-oor-replace.diff | diff --git a/swext/mediawiki/src/registry/data/org/openoffice/Office/OptionsDialog.xcu b/swext/mediawiki/src/registry/data/org/openoffice/Office/OptionsDialog.xcu index 2b35ced08f31..0c96070dd4f0 100644 |
no | ||||
| debian-hardened-buildflags-CPPFLAGS.diff | no | |||||
| debian-hardened-buildflags-no-LO-fstack-protector-strong.diff | don't hardcode -fstack-protector-strong in configure.ac/gbuild. We get the hardening flags from dpkg-buildflags anyway. diff --git a/solenv/gbuild/platform/com_GCC_defs.mk b/solenv/gbuild/platform/com_GCC_defs.mk index 712a61df544f..0d50f538ba7b 100644 |
no | ||||
| default-to-Euro-for-Bulgaria.diff | default to EUR for Bulgaria Bulgaria will switch to EUR 2026-01-01. |
Rene Engelhard <rene@rene-engelhard.de> | no | 2025-11-09 | ||
| Conform-AlignEngine-parsing-to-spec.diff | Conform AlignEngine parsing to what section 2.3.4.10 of the spec has | Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-03-16 | ||
| jdk-minimal-and-zero-paths.diff | sunjre: check all four possible OpenJDK variants for libjvm.so Since OpenJDK 21, the "minimal" and "zero" variants of JVM no longer reside in the "server" directory in $JAVA_HOME/lib, making the loader unable to find libjvm.so. This regresses LO builds on platforms with only those variants of JVM (i.e. without a HotSpot port). Example error message is like this: > exception occurred: Could not create Java implementation loader at > ./stoc/source/javaloader/javaloader.cxx:551 Fix it by probing all four possible variant directories for libjvm.so. This is tested on Debian unstable (loong64 port) to fix the packaging. |
WANG Xuerui <xen0n@gentoo.org> | no | 2024-08-22 | ||
| lo-xlate-lang-add-tl.diff | diff --git a/bin/lo-xlate-lang b/bin/lo-xlate-lang index 9b939012e99a..967a188c14e5 100755 |
no | ||||
| fix-32bits-test-build.diff | diff --git a/sd/qa/unit/tiledrendering/tiledrendering.cxx b/sd/qa/unit/tiledrendering/tiledrendering.cxx index 18b213e99abf..3a26f9493a7f 100644 |
no | ||||
| disable-uitest-xmlsecurity-gpg.diff | diff --git a/xmlsecurity/Module_xmlsecurity.mk b/xmlsecurity/Module_xmlsecurity.mk index afb1e251586a..12241f6b6520 100644 |
no | ||||
| system-colamd.diff | implement --with-system-colamd (for internal lpsolve) using suitesparse. Tested with both suitesparse 5.12.0 (Debian stable, without pc) and 7.9.0 (Debian unstable, with .pc) |
Rene Engelhard <rene@rene-engelhard.de> | no | 2025-03-03 | ||
| add-EUR-for-Bulgaria-Lew.diff | fix typo: BLN -> BGN After commit 37d1cc071ba0cc7f9922c4409d0a014a722ebbce add EUR for Bulgaria/Lew |
Rene Engelhard <rene@rene-engelhard.de> | no | 2025-08-09 | ||
| avmedia-qt-use-gstreamer-frame-grabber-by-default.diff | tdf#166055 avmedia qt: Use GStreamer frame grabber by default As described in tdf#166055, QtFrameGrabber currently still causes issues (freezes or crashes). The QtMultimedia API does not provide a simple way to synchronously retrieve a video frame, so the current approach is to connect to the QVideoSink::videoFrameChanged signal and start playing the video until the first frame arrives. There are various QtMultimedia plugins/backends (at least GStreamer and ffmpeg for Linux). Some use multiple threads internally. Some logic needs to be run in the main thread however, so it's not possible to move things to a separate thread/event loop to decouple it from the main thread. As a consequence, there is a need to trigger event processing while waiting for the frame, as QVideoSink::videoFrameChanged would otherwise never be called. Triggering event processing can have bad side-effects however, as seen in tdf#166055, e.g. leading to endless recursion or crashes when processing LO events. See also commit 697405b533a8ae5b6a8f5bd184b9344a96f71c69 Author: Michael Weghorn <m.weghorn@posteo.de> Date: Wed Apr 9 09:42:45 2025 +0200 tdf#166055 qt avmedia: Provide media/player size right away for more background and some thoughts. For now, avoid the problem by using the GStreamer based frame grabber even with QtPlayer by default. This means that the QtMultimedia framework is still used for video playback with the qt6 VCL plugin, where LO's GStreamer implementation doesn't work properly, see commit 441d8ed9be0e7f831b455a69b8688dcb79a8bc00 Author: Michael Weghorn <m.weghorn@posteo.de> Date: Mon May 20 16:25:09 2024 +0200 tdf#145735 avmedia qt: Use QtMultimedia for Qt 6 media playback . However, in order to preview images (that are e.g. shown in Impress when not in presentation mode) the LO GStreamer backend is used now. (That works fine, no UI interaction is needed for that.) Adjust QtPlayer::createFrameGrabber accordingly to return the LO default platform player/frame grabber implementation (which is the GStreamer one on Linux), see also MediaWindowImpl::createPlayer. Use the service to avoid having to link GStreamer libraries. However, allow to force the use of QtFrameGrabber by setting environment variable SAL_VCL_QT_USE_QT_FRAME_GRABBER. (cherry picked from commit 08533ca4e2526644b803c40c0c3d3c96f43762af) |
Michael Weghorn <m.weghorn@posteo.de> | no | 2025-05-02 | ||
| qt-Consolidate-to-one-toOUString-helper.diff | qt: Consolidate to one toOUString helper Instead of having one for vcl in vcl/inc/qt5/QtTools.hxx and one in avmedia/source/qt6/QtFrameGrabber.cxx, move the existing implementation to include/vcl/qt/QtUtils.hxx and use it everywhere. (cherry picked from commit d023035acf83ee1b61dfc03333bfc6e612bb58f6) |
Michael Weghorn <m.weghorn@posteo.de> | no | 2025-04-11 | ||
| CVE-2026-6045.diff | check that the file can provide the claimed data and make sure we initialize these locals |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-04-09 | ||
| CVE-2026-8356.diff | SdrEscherImport::RecolorGraphic reads but doesn't use FillColors it never did, but at: commit 025bfa7e510bdab3ef93ad45a731fc25085ba3cc cppcheck: unreadVariable the wrong choice was made wrt the dead store, the dead loop should have been fixed rather than let the unused fill colors accumulate in the globalcolors buffer. This function doesn't need to consume the unused data, all callers don't expect the entire record to be read so just drop the loop. (cherry picked from commit 07faeadace3d8d93225f9dd72c4f911e331070e2) (cherry picked from commit 9ba100c0d2131862c9356a86906921abc80d8f98) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2015-04-23 | ||
| CVE-2026-8357.diff | A formula of length L, composed entirely of open tokens, needs L+1 slots (cherry picked from commit 0b7a9149d7c7b5e044bb4f02668297bdf41b64d6) (cherry picked from commit a28cead4b7796642d946173b479281a6272117f2) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-04-26 | ||
| CVE-2026-8358.diff | drop malformed duplicate-id calc change track actions (cherry picked from commit b5b56a2239369e45d7fac2ea965558a1f337b602) (cherry picked from commit a20ae7b5f80a45e49a47ce22f5e92749cd9816a0) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-04-26 | ||
| check-for-hb_shape_full-failure.diff | check for hb_shape_full failure (cherry picked from commit 22c19be8fae977a90f83a82d8acccd0b46c7cf20) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-05-06 | ||
| CVE-2026-63272.diff | ofz: ignore an advance array shorter than the string (cherry picked from commit 6ab602ca281f507f7e637183a49dd514ffb1376b) (cherry picked from commit 4406da79b0715411528c17f93ae7ebcb29b9a0d2) (cherry picked from commit acf64b67cceecf3d1acd26033668b6673208bcf2) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-04 | ||
| CVE-2026-63273.diff | ofz: pdf, check record againsts max allowed size (cherry picked from commit e230b10b7cd2d5d8623cdba0877ec68f67003690) (cherry picked from commit 21124741e0134f0f1222a42726c223bf6da41dca) (cherry picked from commit 3a92ea5af6d1bf3820ce0909fb9de003565ebf2b) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-04 | ||
| CVE-2026-63274.diff | ofz: pdf, clamp stream Length to the bytes actually read (cherry picked from commit 332e8831e0b0e580dae0d77a0ec27bd267af6b29) (cherry picked from commit 7906b5a8aac335a0155a90fc6f8310a92e558124) (cherry picked from commit b4b7fcc1f0551ccdba1ddc520c351eee9bfccd4c) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-04 | ||
| CVE-2026-63275.diff | ofz: wmf, check record against max allowed size (cherry picked from commit 9b412f7cda30a4e1b820e51249fa7b3c36a812d3) (cherry picked from commit 1db305f340787ab7e59d089e51ac9d6fc07c2715) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-04 | ||
| CVE-2026-63276.diff | ofz: cff, track the charstring output capacity (cherry picked from commit 0b090eff6ca18e3f2bacc7311b746d2a15ed1247) (cherry picked from commit 49360f34f5caff4eee29489e339def8cf13053cc) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-05 | ||
| CVE-2026-63278.diff | match the package content provider when checking a vnd.sun.star.pkg url IsExoticProtocol used GetHost() to recover the nested package url of a vnd.sun.star.pkg url, but the package content provider in ucb/source/ucp/package/pkguri.cxx uses the whole authority between "://" and the next '/', which GetHost() truncates at '@'. Check the same substring the provider does. The vnd.sun.star.zip branch below already did the equivalent extraction, so pull the shared parts into a helper that both branches call. (cherry picked from commit ce436efb34d2e0e90ee2cdb450da285530c562f7) (cherry picked from commit 4ba5567cc44be760066c0c45c99949f790cf181a) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-06-12 | ||
| CVE-2026-63279.diff | limit palette index use the same SanitizePaletteIndex guard ipsd and iras already have. (cherry picked from commit ada76821319b80671dba9908aeea8cabba5cedc0) (cherry picked from commit 6bc93227e7c603d3f314202b89b6c567680e6261) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-06-13 | ||
| CVE-2026-63277.diff | translate only file URLs (cherry picked from commit 478eb7de0d14a05e6501bd44851f73ec0df5c59a) (cherry picked from commit e663f8baed49976fd4d4d6d1c277ab036cd28736) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-06-12 | ||
| do-not-load-exotic-protocols-for-document-supplied-data.diff | don't bother loading exotic protocols for document-supplied data (cherry picked from commit 0274803ae273fa6bdbd1124cedf37395ce847148) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-11 | ||
| CVE-2026-63269-1.diff | limit the gstreamer backend to simple self-contained media The adaptive-streaming cases follow a more complicated indirect route of a manifest to further resources which is atypical for our use. (cherry picked from commit c7eada5bc2233369e196f2c93e7606b56e3acc62) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-13 | ||
| CVE-2026-63269-2.diff | put media files under link update control A media object whose content lives at an external URL, rather than inside the document, is registered with the link manager like a linked graphic. So it then shares the usual link update mechanism. Media copied into the document is extracted to a temp file and is not a link, so that's left alone. (cherry picked from commit 1ea4fc54036587c7eb4d4cea74e776de9e6baaf3) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-13 | ||
| CVE-2026-63269-3.diff | put slideshow media links under link control (cherry picked from commit f0768394c14f928d47547408fc1195368be81f86) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-14 | ||
| Show-infobar-for-calc-graphics-with-remote-content-too.diff | Show infobar for calc graphics with remote content too (cherry picked from commit 1f51bbee0e7661d5607efe2603c59d83f410dd3d) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-04-01 | ||
| CVE-2026-63267-1.diff | put calc external data mappings under link update control register each mapping as a LinkManager link, so its refresh goes through the same update control as sheet links and area links. Wait until after the infobar-controlled update mode is known to update. (cherry picked from commit b72d760465c857eb5dd10cdc45b107c49bb0caec) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-11 | ||
| CVE-2026-63267-2.diff | sc: check the host when fetching an external data range checked only the file path allowlist. reject hosts outside it too, like ScExternalRefManager and ScWebServiceLink. (cherry picked from commit 29b5cb45a18ca79b28ce3a02be22803d94a36368) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-11 | ||
| CVE-2026-63268-1.diff | sc: quote the table name in the sql data provider query (cherry picked from commit 1d24f1b1937995936011f61b6c1436d821f66faf) (cherry picked from commit d7712feea1d1992c62f72aeeec32c2053556898b) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-12 | ||
| CVE-2026-63268-2.diff | sc: only build the supported data providers when loading a document Build a data mapping only for the csv, html and xml providers. Any other provider name in the document is ignored. The sql provider is not included. It never worked and was dropped from the Data Provider dialog in tdf#169079. (cherry picked from commit 9b6d7ec607e68c79ce685f126139ef826776e783) (cherry picked from commit 104d2b4f5dae917661b20b18d5d2043fca4407e4) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-12 | ||
| CVE-2026-63266-2.diff | Reapply "firebird: keep each embedded database's files in one directory" This reverts commit 23a5d0dc305fc04bdd277b24db8d5c8e41aa9ccd. it also contains https://gerrit.collaboraoffice.com/c/core/+/7093 "firebird: upper-case the DatabaseAccess Restrict path on Windows" (cherry picked from commit e4dc6a3cb2bfbf9d4c1e30e777b0f46417cf4c92) |
Xisco Fauli <xiscofauli@libreoffice.org> | no | 2026-07-17 | ||
| CVE-2026-63266-4.diff | firebird: only write back an embedded database that was opened When construct throws before the attach succeeds, the connection is disposed with the temporary .fdb extracted but never opened, but storeDatabase ran the backup service against it anyway. Note whether the database was opened and skip the write back when it was not. (cherry picked from commit a73db8b145af1c74cb181e094c0b7ccc4d92d8f0) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-12 | ||
| CVE-2026-63266-1.diff | firebird: don't run an attached database's own event triggers for the embedded and file cases suppress the database's ON CONNECT and similar event triggers when attaching, they should not fire just because the document was opened (cherry picked from commit 36335ff89ea2309e99da02b449c9b35517cd6f9d) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-12 | ||
| CVE-2026-63266-3.diff | firebird: don't attach a database that is not in the normal backup state A database we extract from a .odb is always in the normal backup state, so refuse one that is not, we're not interested in the difference file mode case. firebird upstream attempt as: https://github.com/FirebirdSQL/firebird/pull/9089 And do it manually for the system-firebird case. (cherry picked from commit e7ea381e87cadaf31bf1ad2213a23f17a6284d1c) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-12 | ||
| firebird-db-connection.diff | commit 16cf06caff90c0e4d9fe2fc24eac378ed533c48d Resolves: tdf#172935 Connection from Base to external firebird database refused there is one firebird engine per process and it reads its configuration once from the directory we set up, so a .fdb the user picked somewhere else could not be attached. firebird resolves a name in databases.conf before it treats it as a path, so give the file a name there and pass firebird that name, dropped again when the connection is disposed. since: commit 520d8173cef39a4da85b3ba21bdaaa3150384c25 Date: Sun Jul 12 12:10:41 2026 +0000 firebird: keep each embedded database's files in one directory Change-Id: I4872a4e2165c4701bfb20be5dcd8c119b1723125 Signed-off-by: Caolán McNamara <caolan.mcnamara@collabora.com> Reviewed-on: https://gerrit.collaboraoffice.com/c/core/+/7990 Tested-by: Jenkins CPCI <releng@collaboraoffice.com> Reviewed-by: Michael Stahl <michael.stahl@collabora.com> (cherry picked from commit 6ab71a109bd8a8335208c9faa37a3cfa94523148) Reviewed-on: https://gerrit.libreoffice.org/c/core/+/208773 Tested-by: Jenkins Reviewed-by: Xisco Fauli <xiscofauli@libreoffice.org> (cherry picked from commit 99bf5222896886d062b6a6a67377e7671de1446a) Reviewed-on: https://gerrit.libreoffice.org/c/core/+/208855 diff --git a/connectivity/source/drivers/firebird/Connection.cxx b/connectivity/source/drivers/firebird/Connection.cxx index 3b918e696d87..c4b9126cd0c9 100644 |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-28 | ||
| firebird-module-path.diff | firebird: name the modules of a system firebird by absolute path Debian patches firebird to resolve its plugins, intl and conf directories under the FIREBIRD variable (instead of where it was built) and we want point that variable at a private directory. But then the modules aren't loaded and no database opens. So write a replacement plugins.conf that lists the absolute path of each plugin module (and the intl conf files) with their macros expanded. each lib<Name>.so (otherwise found by default) with no entry names gets an entry of its own. (cherry picked from commit b8407b18adf3c6d552d54d7b6657539e2769afd6) (cherry picked from commit 09dbbe16b04add973ab04fe5937c12478e52451c) |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-28 | ||
| firebird-call-writeFile-outside-the-SAL_WARN_IF-cond.patch | firebird: call writeFile outside the SAL_WARN_IF condition a product build doesn't evaluate the condition, so none of the conf files were written there. since: commit b8407b18adf3c6d552d54d7b6657539e2769afd6 firebird: name the modules of a system firebird by absolute path and: commit 6ab71a109bd8a8335208c9faa37a3cfa94523148 Resolves: tdf#172935 Connection from Base to external firebird database refused |
Caolán McNamara <caolan.mcnamara@collabora.com> | no | 2026-07-28 |
All known versions for source package 'libreoffice'
- 4:26.8.1.1-3 (sid)
- 4:26.8.0.3-2 (forky)
- 4:26.8.0.3-2~bpo13+1 (trixie-backports)
- 4:25.2.3-2+deb13u8 (trixie-security)
- 4:25.2.3-2+deb13u7 (trixie-proposed-updates)
- 4:25.2.3-2+deb13u6 (trixie)
- 4:25.2.3-2+deb13u5~bpo12+1 (bookworm-backports)
- 4:7.4.7-1+deb12u14 (bookworm)
- 4:7.4.7-1+deb12u13 (bookworm-security)
