Description: "The mq_notify function in the GNU C Library (aka glibc) through 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact."
Fixed in 2.34, not got the commit to hand...
Any news on backport?
(In reply to Sam James from comment #2) > Any news on backport? Oh, I see it in the branch now.
Fixed in 2.33-r1 too.
arches please *test* and stabilize sys-libs/glibc-2.33-r1 please make tests only block if they are regressions compared to 2.33(-r0) currently I get the same three test failures for 2.33 and 2.33-r1: FAIL: stdlib/tst-system FAIL: string/tst-strerror FAIL: string/tst-strsignal
hppa stable
amd64 done
x86 stable
sparc stable
Added to existing request
This issue was resolved and addressed in GLSA 202107-07 at https://security.gentoo.org/glsa/202107-07 by GLSA coordinator John Helmert III (ajak).
Reopening for stabilization and cleanup
ppc64 stable
arm done
arm64 done
ppc: ping pretty please
(In reply to Andreas K. Hüttel from comment #16) > ppc: ping pretty please Yes please, I just got bit by the select(2) timeout bug in 2.33
ppc done all arches done
Please cleanup.
(In reply to Sam James from comment #18) > ppc done > > all arches done Thanks!
(In reply to Joakim Tjernlund from comment #20) > (In reply to Sam James from comment #18) > > ppc done > > > > all arches done > > Thanks! np, thanks for the reminder!
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=355dda138053b905004c5f9d70233b627cb9c857 commit 355dda138053b905004c5f9d70233b627cb9c857 Author: Andreas K. Hüttel <dilfridge@gentoo.org> AuthorDate: 2021-10-30 15:42:14 +0000 Commit: Andreas K. Hüttel <dilfridge@gentoo.org> CommitDate: 2021-10-30 15:42:31 +0000 sys-libs/glibc: Remove old Bug: https://bugs.gentoo.org/792261 Package-Manager: Portage-3.0.28, Repoman-3.0.3 Signed-off-by: Andreas K. Hüttel <dilfridge@gentoo.org> sys-libs/glibc/Manifest | 2 - sys-libs/glibc/glibc-2.33-r6.ebuild | 1551 ----------------------------------- sys-libs/glibc/glibc-2.33.ebuild | 1494 --------------------------------- 3 files changed, 3047 deletions(-)
All affected ebuilds are now masked. No further cleanup.
All done!