Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 914281 (CVE-2023-4527, CVE-2023-4806) - <sys-libs/glibc-{2.37-r5, 2.38-r2}: Multiple vulnerabilities
Summary: <sys-libs/glibc-{2.37-r5, 2.38-r2}: Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2023-4527, CVE-2023-4806
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A3 [glsa+]
Keywords:
Depends on: 915142
Blocks:
  Show dependency tree
 
Reported: 2023-09-16 09:53 UTC by Sam James
Modified: 2023-11-24 18:02 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-09-16 09:53:57 UTC
1) Stack read overflow in getaddrinfo in no-aaaa mode (CVE-2023-4527)

See https://sourceware.org/bugzilla/show_bug.cgi?id=30842.

2) Potential use-after-free in getcanonname (CVE-2023-4806)

See https://sourceware.org/bugzilla/show_bug.cgi?id=30843.
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-09-16 09:54:58 UTC
commit 5e4787264d2ac33ff1718753e683122950fcf317
Author: Andreas K. Hüttel <dilfridge@gentoo.org>
Date:   Sat Sep 16 11:39:52 2023 +0200

    sys-libs/glibc: 2.37 and 2.38 patchset bumps, untested

    Signed-off-by: Andreas K. Hüttel <dilfridge@gentoo.org>
Comment 2 Andreas K. Hüttel archtester gentoo-dev 2023-09-17 21:30:47 UTC
Both re-keyworded as of now
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-10-03 21:50:40 UTC
GLSA request filed.
Comment 4 Larry the Git Cow gentoo-dev 2023-10-04 08:02:46 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=029e12731f29676d3f6ebed09f7747ee6e15c5e8

commit 029e12731f29676d3f6ebed09f7747ee6e15c5e8
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2023-10-04 08:02:08 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-10-04 08:02:41 +0000

    [ GLSA 202310-03 ] glibc: Multiple vulnerabilities
    
    Bug: https://bugs.gentoo.org/867952
    Bug: https://bugs.gentoo.org/914281
    Bug: https://bugs.gentoo.org/915127
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Sam James <sam@gentoo.org>

 glsa-202310-03.xml | 47 +++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 47 insertions(+)