From ${URL} : A weakness in the dynamic loader has been found, making glibc of versions prior 2.22.90 affected. LD_POINTER_GUARD in the environment is not sanitizaed allowing attacker to easily bypass the pointer guarding protection on set-user-ID and set-group-ID programs. Reproducing steps available at: CVE request: @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Commit fix:;a=commit;h=a014cecd82b71b70a6a843e250e06b541ad524f7
This issue was resolved and addressed in GLSA 201702-11 at by GLSA coordinator Thomas Deutschmann (whissi).