Re: [LFS Trac] #5850: glibc-2.43

"LFS Trac" ([email protected] via lfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.book
Message-ID <[email protected]>
#5850: glibc-2.43
-------------------------+-----------------------
 Reporter:  Xi Ruoyao    |       Owner:  lfs-book
     Type:  enhancement  |      Status:  closed
 Priority:  high         |   Milestone:  13.0
Component:  Book         |     Version:  git
 Severity:  normal       |  Resolution:  fixed
 Keywords:               |
-------------------------+-----------------------
Comment (by Douglas R. Reno):

 Replying to [comment:12 zeckma]:
 > This update fixes four CVEs:
 >
 > - CVE-2025-0395: assert: Buffer overflow when printing assertion failure
 message
 > - CVE-2025-5702: power10: strcmp fails to save and restore nonvolatile
 vector
 > - CVE-2025-5745: power10: strncmp fails to save and restore nonvolatile
 vector
 > - CVE-2025-8058: posix: Fix double-free after allocation failure in
 regcomp
 >
 > I don't know the ratings of these, yet.

 These vulnerabilities are actually for 2.42. 2.43's CVEs fixed are:

   GLIBC-SA-2026-0001:
     Integer overflow in memalign leads to heap corruption
     (CVE-2026-0861)

   GLIBC-SA-2026-0002:
     getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler
     (CVE-2026-0915)

   GLIBC-SA-2026-0003:
     wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized
     memory (CVE-2025-15281)
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5850#comment:19>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.

-- 
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.