Bug#1134544: marked as done (glibc: CVE-2026-5928)
"Debian Bug Tracking System" <[email protected]> Sat, 11 Jul 2026 16:19:03 +0000
| Newsgroups | gmane.linux.debian.devel.glibc |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format... ------------=_1783786743-54770-0 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Your message dated Sat, 11 Jul 2026 16:17:06 +0000 with message-id <[email protected]> and subject line Bug#1134544: fixed in glibc 2.41-12+deb13u4 has caused the Debian Bug report #1134544, regarding glibc: CVE-2026-5928 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) --=20 1134544: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1134544 Debian Bug Tracking System Contact [email protected] with problems ------------=_1783786743-54770-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at submit) by bugs.debian.org; 21 Apr 2026 15:51:39 +0000 X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02 (2024-03-25) on buxtehude.debian.org X-Spam-Level: X-Spam-Status: No, score=-9.9 required=4.0 tests=BAYES_00,FOURLA,FROMDEVELOPER, NO_RELAYS,XMAILER_REPORTBUG autolearn=ham autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02 X-Spam-Bayes: score:0.0000 Tokens: new, 27; hammy, 150; neutral, 79; spammy, 0. spammytokens: hammytokens:0.000-+--H*F:U*carnil, 0.000-+--XDebbugsCc, 0.000-+--X-Debbugs-Cc, 0.000-+--HTo:N*Debian, 0.000-+--H*Ad:N*Bug Return-path: <[email protected]> Received: via submission by buxtehude.debian.org with esmtp (Exim 4.96) (envelope-from <[email protected]>) id 1wFDNy-007cyy-16 for [email protected]; Tue, 21 Apr 2026 15:51:39 +0000 Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit From: Salvatore Bonaccorso <[email protected]> To: Debian Bug Tracking System <[email protected]> Subject: glibc: CVE-2026-5928 Message-ID: <[email protected]> X-Mailer: reportbug 13.2.0 Date: Tue, 21 Apr 2026 17:51:37 +0200 Delivered-To: [email protected] Source: glibc Version: 2.42-15 Severity: important Tags: security upstream Forwarded: https://sourceware.org/bugzilla/show_bug.cgi?id=33998 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> Hi, The following vulnerability was published for glibc. CVE-2026-5928[0]: | Calling the ungetwc function on a FILE stream with wide characters | encoded in a character set that has overlaps between its single byte | and multi-byte character encodings, in the GNU C Library version | 2.43 or earlier, may result in an attempt to read bytes before an | allocated buffer, potentially resulting in unintentional disclosure | of neighboring data in the heap, or a program crash. A bug in the | wide character pushback implementation (_IO_wdefault_pbackfail in | libio/wgenops.c) causes ungetwc() to operate on the regular | character buffer (fp->_IO_read_ptr) instead of the actual wide- | stream read pointer (fp->_wide_data->_IO_read_ptr). The program | crash may happen in cases where fp->_IO_read_ptr is not initialized | and hence points to NULL. The buffer under-read requires a special | situation where the input character encoding is such that there are | overlaps between single byte representations and multibyte | representations in that encoding, resulting in spurious matches. The | spurious match case is not possible in the standard Unicode | character sets. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-5928 https://www.cve.org/CVERecord?id=CVE-2026-5928 [1] https://sourceware.org/bugzilla/show_bug.cgi?id=33998 [2] https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0010 Please adjust the affected versions in the BTS as needed. Regards, Salvatore ------------=_1783786743-54770-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at 1134544-close) by bugs.debian.org; 11 Jul 2026 16:17:09 +0000 X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02 (2024-03-25) on buxtehude.debian.org X-Spam-Level: X-Spam-Status: No, score=-113.1 required=4.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FVGT_m_MULTI_ODD,HAS_BUG_NUMBER, MD5_SHA1_SUM,PGPSIGNATURE,RCVD_IN_DNSWL_MED,SPF_HELO_PASS,SPF_PASS, USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02 X-Spam-Bayes: score:0.0000 Tokens: new, 71; hammy, 150; neutral, 165; spammy, 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK, 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--UD:debian.tar.xz, 0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo Return-path: <[email protected]> Received: from mitropoulos.debian.org ([2001:648:2ffc:deb:216:61ff:fe9d:958d]:40674) by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from <[email protected]>) id 1wiaO5-000DsL-2S for [email protected]; Sat, 11 Jul 2026 16:17:09 +0000 Received: via submission from C=NA,ST=NA,L=Ankh Morpork,O=Debian SMTP,OU=Debian SMTP CA,CN=fasolo.debian.org,[email protected] (verified) by mitropoulos.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from <[email protected]>) id 1wiaO4-000Ai4-1y for [email protected]; Sat, 11 Jul 2026 16:17:08 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type: Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID :Content-Description:In-Reply-To:References; bh=Qk5OgryxD11CZOeHC8AxE+9IyVd44VKFi7cJGWroE7o=; b=JwxOGMFAGBNOdBpH30BGCXd0SQ kME8JoD9K7XSrwekZNigwhtHJ2oOWns0juZ5Ld6DR/Xt/BrVll19ad7hFPlQdO46eJwwYvpKTfHUl V5XWFQGRzevQHkUZr7A3K9wymTcvQ2Yv5Wu46/U5xpy9LwpDF3kbnXfhtrGwjO0K+MB2J1anwHvlm Dmo1y9HEEcTcj+zXqPMzU3HV6k8007055pmNVVzIxqqURrgg6Xt3ZwxJNQpny+6mXXuyIPK/H+xTO FIgJgrb/isfLoSh4mvznrx0GAWAy9FuUZB1sd+sOcO+0DE0iJb9HWMMVIeQ+vkGI4XxcEyfSYc4Gg 6RuFoBkQ==; Received: from dak by fasolo.debian.org with local (Exim 4.98.2) (envelope-from <[email protected]>) id 1wiaO2-000000073WQ-3qfj; Sat, 11 Jul 2026 16:17:06 +0000 From: Debian FTP Masters <[email protected]> Reply-To: Aurelien Jarno <[email protected]> To: [email protected] X-DAK: dak process-policy X-Debian: DAK X-Debian-Package: glibc Debian: DAK Debian-Changes: glibc_2.41-12+deb13u4_source.changes Debian-Source: glibc Debian-Version: 2.41-12+deb13u4 Debian-Architecture: source Debian-Suite: proposed-updates Debian-Archive-Action: accept MIME-Version: 1.0 Subject: Bug#1134544: fixed in glibc 2.41-12+deb13u4 Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="===============1275801628934276554==" Message-Id: <[email protected]> Date: Sat, 11 Jul 2026 16:17:06 +0000 --===============1275801628934276554== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Source: glibc Source-Version: 2.41-12+deb13u4 Done: Aurelien Jarno <[email protected]> We believe that the bug you reported is fixed in the latest version of glibc, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to [email protected], and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Aurelien Jarno <[email protected]> (supplier of updated glibc package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing [email protected]) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 29 Jun 2026 23:37:52 +0200 Source: glibc Architecture: source Version: 2.41-12+deb13u4 Distribution: trixie Urgency: medium Maintainer: GNU Libc Maintainers <[email protected]> Changed-By: Aurelien Jarno <[email protected]> Closes: 1134543 1134544 1135405 Changes: glibc (2.41-12+deb13u4) trixie; urgency=3Dmedium . * debian/patches/git-updates.diff: update from upstream stable branch: - Fix build against linux 7.0 headers. Closes: #1135405. - Fix ungetwc operating on byte stream (CVE-2026-5928). Closes: #113454= 4. - Fix buffer overflow in scanf %mc (CVE-2026-5450). Closes: #1134543. - Suppress iconv intermediate errors with //TRANSLIT. Checksums-Sha1: f291d4082eef7e094241a1a87585f275cf336149 7576 glibc_2.41-12+deb13u4.dsc 57751ec678751a3cf5bf3badb54f6ab6b9760eea 499524 glibc_2.41-12+deb13u4.debian= .tar.xz 62b4c5a63a1ea4ff036ac1a3a9ca6e49c7c3d7b9 9744 glibc_2.41-12+deb13u4_source.b= uildinfo Checksums-Sha256: 0915324aa646bb99abfaa9aa6ecb734b30babd28454a3e51f3152912370fbd3e 7576 glibc_= 2.41-12+deb13u4.dsc dda4153511bfd543502d18e5bc9323110996fe9c531f14ae3fad6eb17f027c7d 499524 glib= c_2.41-12+deb13u4.debian.tar.xz 43a8726930a9a9e5f1cdf431c3a239dab03ec5a555acc85d2f5d5c1388f11710 9744 glibc_= 2.41-12+deb13u4_source.buildinfo Files: fa18f1bcbca0299c1ea024bfc9623f7a 7576 libs required glibc_2.41-12+deb13u4.dsc 8e44b0a9913a886a781d99125209f7df 499524 libs required glibc_2.41-12+deb13u4.= debian.tar.xz f005e6cb9bc0bb82a20cf2cb96c14f54 9744 libs required glibc_2.41-12+deb13u4_so= urce.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEUryGlb40+QrX1Ay4E4jA+JnoM2sFAmpEnF8ACgkQE4jA+Jno M2uNMQ/9G6Ez7CakRZfrcoMwH8BBU61EBIYGYav1d74Blw6TWYd0KKmSOQN6dZfr nbDaWmByx7kKhdxbCjI44y+4GlHPu36CbweSJBhbQi3j/CRS4qP6sjJL7/kAz+gp Ft1uaHmBJJsaygriQxfojgMXp7NuQ0MAIALwRopKgvRyhkCRxOhqiFwYws3K8TuB VZ/ywaWRuc1EbiO8KPeUN6HEg9Tq7vHcgcwWfR+rSTMOhVFSzSca4GJI98Q/9kU8 nLx4lyboadzir/PkjI/2BTRCLASW7pFmIZBoYzF5tCrvCNXOGQe34BVnrDzR3f4H RV1sDHb2oGNRmwqmX8OmY2+/HJGapwmlvcqawlZ7AKo6UxwmfvQHqkwAtZcqgta1 8imlcEjYcZ5GtIxdIS59yScYos8hYtLuOmxXMtZryTaEQzpsb94jKwlQiWfLukaR 9fMkRmaUVrW+bYePjA8oYidIbDX6o0J7TKrQbSvxXqZ6Zfk3nlAqwgPbm0qPrQ+Y DBYGy6yL+AcWDWb/mNciGfcPu5mqsbHD6O+ciwGu2lQn5TwoGassF7qGecj49eY9 OXoK4FVyNJ6TseC94MwBB1rVzUhk5LUXmsODh0K1qZMyFxr7GAA/TG1YW3k8gTXG FsxFEFTOMazBGtjH8urnHZ4I0G4NyUAKVqkeTCEfmhUAOtIY/Gg=3D =3DIKe1 -----END PGP SIGNATURE----- --===============1275801628934276554== Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCalJsggAKCRCb9qggYcy5 IUxHAP4639nJh5aASS9MmQvTBreqvQ1UYX8i8AY4rwgJ/6Kz3QEAlWCGHR9KS6rs xdgKfXjyWsBK/N0ncgXDcdab9pMlGAo= =wKsZ -----END PGP SIGNATURE----- --===============1275801628934276554==-- ------------=_1783786743-54770-0--