guix-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH 01/68] gnu: Add flex-2.6.1.


From: Leo Famulari
Subject: Re: [PATCH 01/68] gnu: Add flex-2.6.1.
Date: Sat, 29 Oct 2016 16:40:55 -0400
User-agent: Mutt/1.7.1 (2016-10-04)

On Sat, Oct 29, 2016 at 07:46:53PM +0100, Marius Bakke wrote:
> David Craven <address@hidden> writes:
> 
> > * gnu/packages/flex.scm (flex-2.6.1): New variable.
> 
> This is newer than what we currently have (2.6.0). I know it's late in
> the core-updates cycle, but maybe we can squeeze in a flex upgrade?

Unfortunately, changing flex will cause ~1500 rebuilds per architecture,
so I think we won't do it unless there is some very serious problem.

Also see commit eba7fab890f43 on core-updates, which fixes a bug
(CVE-2016-6354) that allow DOS and potentially arbitrary code execution
in code generated by flex.

Updating flex to the latest version should happen in the next
core-updates, or possibly in an earlier staging / security-updates
cycle.

Attachment: signature.asc
Description: PGP signature


reply via email to

[Prev in Thread] Current Thread [Next in Thread]