Summary: | <sys-libs/glibc-2.40-r8: Buffer overflow in the GNU C Library's assert() | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | toolchain |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://www.openwall.com/lists/oss-security/2025/01/22/4 | ||
See Also: | https://sourceware.org/bugzilla/show_bug.cgi?id=32582 | ||
Whiteboard: | A2 [glsa+] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 948633 | ||
Bug Blocks: |
Description
Sam James
![]() ![]() ![]() ![]() commit d1644f95aaf356acf6e77124b8da1904a23bdf45 Author: Andreas K. Hüttel <dilfridge@gentoo.org> Date: Thu Jan 23 00:28:38 2025 +0100 sys-libs/glibc: 2.40 patchlevel 8 bump Signed-off-by: Andreas K. Hüttel <dilfridge@gentoo.org> Not yet keyworded while we test. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=18ec4be7c8526a0adb89279c09e2eff6da2acece commit 18ec4be7c8526a0adb89279c09e2eff6da2acece Author: Andreas K. Hüttel <dilfridge@gentoo.org> AuthorDate: 2025-01-23 12:03:13 +0000 Commit: Andreas K. Hüttel <dilfridge@gentoo.org> CommitDate: 2025-01-23 13:59:48 +0000 sys-libs/glibc: keyword 2.40-r8 Patchset changelog 2.40-7..2.40-8 f37769b877 (HEAD -> gentoo/2.40, tag: gentoo/glibc-2.40-8, gentoo/gentoo/2.40) Fix underallocation of abort_msg_s struct (CVE-2025-0395) d6df843eca Fix missing randomness in __gen_tempname (bug 32214) e4ef305fc4 hppa: Simplify handling of sanity check errors in clone.S. aea26c8570 hppa: Fix strace detach-vfork test 098aaa8d6b x86: Avoid integer truncation with large cache sizes (bug 32470) 4c028395a1 linux: Fix tst-syscall-restart.c on old gcc (BZ 32283) 70258d6110 math: Exclude internal math symbols for tests [BZ #32414] 199b0f2247 malloc: add indirection for malloc(-like) functions in tests [BZ #32366] 2d6ede43d6 nptl: initialize cpu_id_start prior to rseq registration 38d45c44c5 nptl: initialize rseq area prior to registration Bug: https://bugs.gentoo.org/948592 Signed-off-by: Andreas K. Hüttel <dilfridge@gentoo.org> sys-libs/glibc/glibc-2.40-r8.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) I've filed and kicked off bug 948633. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=2904a06243343837870fc27f44047c5a4c5ca296 commit 2904a06243343837870fc27f44047c5a4c5ca296 Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2025-05-12 14:34:54 +0000 Commit: Hans de Graaff <graaff@gentoo.org> CommitDate: 2025-05-12 14:35:16 +0000 [ GLSA 202505-06 ] glibc: Buffer Overflow Bug: https://bugs.gentoo.org/948592 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Hans de Graaff <graaff@gentoo.org> glsa-202505-06.xml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) |