Bug#1134543: marked as done (glibc: CVE-2026-5450)

"Debian Bug Tracking System" <[email protected]> Sat, 11 Jul 2026 16:19:02 +0000
Newsgroups gmane.linux.debian.devel.glibc
Message-ID <[email protected]>
This is a multi-part message in MIME format...

------------=_1783786742-54756-0
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="utf-8"

Your message dated Sat, 11 Jul 2026 16:17:06 +0000
with message-id <[email protected]>
and subject line Bug#1134543: fixed in glibc 2.41-12+deb13u4
has caused the Debian Bug report #1134543,
regarding glibc: CVE-2026-5450
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


--=20
1134543: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1134543
Debian Bug Tracking System
Contact [email protected] with problems

------------=_1783786742-54756-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at submit) by bugs.debian.org; 21 Apr 2026 15:49:48 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
	(2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-9.9 required=4.0 tests=BAYES_00,FOURLA,FROMDEVELOPER,
	NO_RELAYS,XMAILER_REPORTBUG autolearn=ham autolearn_force=no
	version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 16; hammy, 147; neutral, 34; spammy,
	1. spammytokens:0.942-+--H*r:bugs.debian.org
	hammytokens:0.000-+--H*F:U*carnil, 0.000-+--XDebbugsCc,
	0.000-+--X-Debbugs-Cc, 0.000-+--HTo:N*Debian, 0.000-+--H*Ad:N*Bug
Return-path: <[email protected]>
Received: via submission
	by buxtehude.debian.org with esmtp (Exim 4.96)
	(envelope-from <[email protected]>)
	id 1wFDMA-007clU-2D
	for [email protected];
	Tue, 21 Apr 2026 15:49:48 +0000
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Salvatore Bonaccorso <[email protected]>
To: Debian Bug Tracking System <[email protected]>
Subject: glibc: CVE-2026-5450
Message-ID: <[email protected]>
X-Mailer: reportbug 13.2.0
Date: Tue, 21 Apr 2026 17:49:45 +0200
Delivered-To: [email protected]

Source: glibc
Version: 2.42-15
Severity: important
Tags: security upstream
Forwarded: https://sourceware.org/bugzilla/show_bug.cgi?id=34008
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for glibc.

CVE-2026-5450[0]:
| Calling the scanf family of functions with a %mc (malloc'd character
| match) in the GNU C Library version 2.7 to version 2.43 with a
| format width specifier with an explicit width greater than 1024
| could result in a one byte heap buffer overflow.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-5450
    https://www.cve.org/CVERecord?id=CVE-2026-5450
[1] https://sourceware.org/bugzilla/show_bug.cgi?id=34008
[2] https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0009

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

------------=_1783786742-54756-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at 1134543-close) by bugs.debian.org; 11 Jul 2026 16:17:09 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
	(2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-114.2 required=4.0 tests=ALL_TRUSTED,BAYES_00,
	DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FVGT_m_MULTI_ODD,
	HAS_BUG_NUMBER,MD5_SHA1_SUM,PGPSIGNATURE,SPF_HELO_PASS,SPF_PASS,
	USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no
	version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 71; hammy, 150; neutral, 165; spammy,
	0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK,
	0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--UD:debian.tar.xz,
	0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo
Return-path: <[email protected]>
Received: from mailly.debian.org ([2001:41b8:202:deb:6564:a62:52c3:4b72]:58186)
	by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
	(Exim 4.96)
	(envelope-from <[email protected]>)
	id 1wiaO5-000DsI-0H
	for [email protected];
	Sat, 11 Jul 2026 16:17:09 +0000
Received: via submission
	from C=NA,ST=NA,L=Ankh Morpork,O=Debian SMTP,OU=Debian SMTP CA,CN=fasolo.debian.org,[email protected] (verified)
	by mailly.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
	(Exim 4.96)
	(envelope-from <[email protected]>)
	id 1wiaO3-0003pK-2a
	for [email protected];
	Sat, 11 Jul 2026 16:17:07 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
	d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
	Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
	:Content-Description:In-Reply-To:References;
	bh=xi0QF7YkFrEevZsZn2ZaBogUBWUQCXMVon5LAHOJi0E=; b=jDwN5bWfORXWFsO5+yWEH3jUpM
	fYZ3FeXZJSWIOOWG7b3e+mxixsAfqri40r6FniiXD8mmrYIg34dghOjNeByBUu5Vt3qCoJTtq5do0
	4Rl9rS68Jni5bu8RJqHuIAF3IOWytzNAk9ijWnW6QIEBWTwTDmSHgVxAH5tAbjsVBOVPWqMG0WjwY
	W70KWQskVcVbx+bLFg2DTwixyuy/fH0Iv7P0FTg2DLlLwmIO88DaSxUYomNEdVcTN+VLbQVHUn5ml
	PBIkl4I4VytxzuFDBDi2eH5YEsT9/2a4R/4fqkNvbgVBSpcx1AbCCsfST25Ct94YVsfGAR9mV1SdD
	WVl3cSpw==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
	(envelope-from <[email protected]>)
	id 1wiaO2-000000073WM-3h6c;
	Sat, 11 Jul 2026 16:17:06 +0000
From: Debian FTP Masters <[email protected]>
Reply-To: Aurelien Jarno <[email protected]>
To: [email protected]
X-DAK: dak process-policy
X-Debian: DAK
X-Debian-Package: glibc
Debian: DAK
Debian-Changes: glibc_2.41-12+deb13u4_source.changes
Debian-Source: glibc
Debian-Version: 2.41-12+deb13u4
Debian-Architecture: source
Debian-Suite: proposed-updates
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#1134543: fixed in glibc 2.41-12+deb13u4
Content-Type: multipart/signed; micalg="pgp-sha256";
 protocol="application/pgp-signature";
 boundary="===============2173300359623417828=="
Message-Id: <[email protected]>
Date: Sat, 11 Jul 2026 16:17:06 +0000

--===============2173300359623417828==
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

Source: glibc
Source-Version: 2.41-12+deb13u4
Done: Aurelien Jarno <[email protected]>

We believe that the bug you reported is fixed in the latest version of
glibc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Aurelien Jarno <[email protected]> (supplier of updated glibc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 29 Jun 2026 23:37:52 +0200
Source: glibc
Architecture: source
Version: 2.41-12+deb13u4
Distribution: trixie
Urgency: medium
Maintainer: GNU Libc Maintainers <[email protected]>
Changed-By: Aurelien Jarno <[email protected]>
Closes: 1134543 1134544 1135405
Changes:
 glibc (2.41-12+deb13u4) trixie; urgency=3Dmedium
 .
   * debian/patches/git-updates.diff: update from upstream stable branch:
     - Fix build against linux 7.0 headers.  Closes: #1135405.
     - Fix ungetwc operating on byte stream (CVE-2026-5928).  Closes: #113454=
4.
     - Fix buffer overflow in scanf %mc (CVE-2026-5450).  Closes: #1134543.
     - Suppress iconv intermediate errors with //TRANSLIT.
Checksums-Sha1:
 f291d4082eef7e094241a1a87585f275cf336149 7576 glibc_2.41-12+deb13u4.dsc
 57751ec678751a3cf5bf3badb54f6ab6b9760eea 499524 glibc_2.41-12+deb13u4.debian=
.tar.xz
 62b4c5a63a1ea4ff036ac1a3a9ca6e49c7c3d7b9 9744 glibc_2.41-12+deb13u4_source.b=
uildinfo
Checksums-Sha256:
 0915324aa646bb99abfaa9aa6ecb734b30babd28454a3e51f3152912370fbd3e 7576 glibc_=
2.41-12+deb13u4.dsc
 dda4153511bfd543502d18e5bc9323110996fe9c531f14ae3fad6eb17f027c7d 499524 glib=
c_2.41-12+deb13u4.debian.tar.xz
 43a8726930a9a9e5f1cdf431c3a239dab03ec5a555acc85d2f5d5c1388f11710 9744 glibc_=
2.41-12+deb13u4_source.buildinfo
Files:
 fa18f1bcbca0299c1ea024bfc9623f7a 7576 libs required glibc_2.41-12+deb13u4.dsc
 8e44b0a9913a886a781d99125209f7df 499524 libs required glibc_2.41-12+deb13u4.=
debian.tar.xz
 f005e6cb9bc0bb82a20cf2cb96c14f54 9744 libs required glibc_2.41-12+deb13u4_so=
urce.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUryGlb40+QrX1Ay4E4jA+JnoM2sFAmpEnF8ACgkQE4jA+Jno
M2uNMQ/9G6Ez7CakRZfrcoMwH8BBU61EBIYGYav1d74Blw6TWYd0KKmSOQN6dZfr
nbDaWmByx7kKhdxbCjI44y+4GlHPu36CbweSJBhbQi3j/CRS4qP6sjJL7/kAz+gp
Ft1uaHmBJJsaygriQxfojgMXp7NuQ0MAIALwRopKgvRyhkCRxOhqiFwYws3K8TuB
VZ/ywaWRuc1EbiO8KPeUN6HEg9Tq7vHcgcwWfR+rSTMOhVFSzSca4GJI98Q/9kU8
nLx4lyboadzir/PkjI/2BTRCLASW7pFmIZBoYzF5tCrvCNXOGQe34BVnrDzR3f4H
RV1sDHb2oGNRmwqmX8OmY2+/HJGapwmlvcqawlZ7AKo6UxwmfvQHqkwAtZcqgta1
8imlcEjYcZ5GtIxdIS59yScYos8hYtLuOmxXMtZryTaEQzpsb94jKwlQiWfLukaR
9fMkRmaUVrW+bYePjA8oYidIbDX6o0J7TKrQbSvxXqZ6Zfk3nlAqwgPbm0qPrQ+Y
DBYGy6yL+AcWDWb/mNciGfcPu5mqsbHD6O+ciwGu2lQn5TwoGassF7qGecj49eY9
OXoK4FVyNJ6TseC94MwBB1rVzUhk5LUXmsODh0K1qZMyFxr7GAA/TG1YW3k8gTXG
FsxFEFTOMazBGtjH8urnHZ4I0G4NyUAKVqkeTCEfmhUAOtIY/Gg=3D
=3DIKe1
-----END PGP SIGNATURE-----


--===============2173300359623417828==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCalJsggAKCRCb9qggYcy5
IZkSAQDeNpL7tydlAmU7yqDK/bxNk5lQFBHZ99lsjD4eoEcZlgEA7t6xKJpvPmE2
lOrtdJl39L/zgpUU+rk3nVXJiu3oRgs=
=5xse
-----END PGP SIGNATURE-----

--===============2173300359623417828==--
------------=_1783786742-54756-0--