Re: [LFS Trac] #5850: glibc-2.43
| Newsgroups | gmane.linux.lfs.book |
|---|---|
| Message-ID | <[email protected]> |
#5850: glibc-2.43
-------------------------+-----------------------
Reporter: Xi Ruoyao | Owner: lfs-book
Type: enhancement | Status: closed
Priority: high | Milestone: 13.0
Component: Book | Version: git
Severity: normal | Resolution: fixed
Keywords: |
-------------------------+-----------------------
Comment (by Douglas R. Reno):
Replying to [comment:12 zeckma]:
> This update fixes four CVEs:
>
> - CVE-2025-0395: assert: Buffer overflow when printing assertion failure
message
> - CVE-2025-5702: power10: strcmp fails to save and restore nonvolatile
vector
> - CVE-2025-5745: power10: strncmp fails to save and restore nonvolatile
vector
> - CVE-2025-8058: posix: Fix double-free after allocation failure in
regcomp
>
> I don't know the ratings of these, yet.
These vulnerabilities are actually for 2.42. 2.43's CVEs fixed are:
GLIBC-SA-2026-0001:
Integer overflow in memalign leads to heap corruption
(CVE-2026-0861)
GLIBC-SA-2026-0002:
getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler
(CVE-2026-0915)
GLIBC-SA-2026-0003:
wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized
memory (CVE-2025-15281)
--
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5850#comment:19>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.
--
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page