Package "glibc"
Name: |
glibc
|
Description: |
This package is just an umbrella for a group of other packages,
it has no description. Description samples from packages in group:
- GNU C Library: sources
- GNU C Library: Precompiled locale data
- GNU C Library: Name Service Cache Daemon
|
Latest version: |
2.35-0ubuntu3.5 |
Release: |
jammy (22.04) |
Level: |
updates |
Repository: |
universe |
Links
Other versions of "glibc" in Jammy
Packages in group
Deleted packages are displayed in grey.
Changelog
glibc (2.35-0ubuntu3.5) jammy-security; urgency=medium
* SECURITY UPDATE: use-after-free through getcanonname_r plugin call
- debian/patches/any/CVE-2023-4806-pre1.patch: sort tests and
tests-container and put one test per line (nss).
- debian/patches/any/CVE-2023-4806-pre2.patch: simplify canon name
resolution (gaih_inet).
- debian/patches/any/CVE-2023-4806-pre3.patch: fix leak with AI_ALL
(gaih_inet).
- debian/patches/any/CVE-2023-4806-pre4.patch: simplify service resolution
(gaih_inet).
- debian/patches/any/CVE-2023-4806-pre5.patch: make numeric lookup a
separate routine (gaih_inet).
- debian/patches/any/CVE-2023-4806-pre6.patch: split simple gethostbyname
into its own function (gaih_inet).
- debian/patches/any/CVE-2023-4806-pre7.patch: split nscd lookup code into
its own function (gaih_inet).
- debian/patches/any/CVE-2023-4806-pre8.patch: separate nss lookup loop
into its own function (gaih_inet).
- debian/patches/any/CVE-2023-4806-pre9.patch: make gethosts into a
function (gaih_inet).
- debian/patches/any/CVE-2023-4806-pre10.patch: split loopback lookup into
its own function (gaih_inet).
- debian/patches/any/CVE-2023-4806-pre11.patch: split result generation
into its own function (gaih_inet).
- debian/patches/any/CVE-2023-4806-pre12.patch: return EAI_MEMORY on
allocation failure (gethosts).
- debian/patches/any/CVE-2023-4806.patch: copy h_name over and free it at
the end (getaddrinfo).
- CVE-2023-4806
* SECURITY UPDATE: use-after-free in gaih_inet function
- debian/patches/any/CVE-2023-4813.patch: simplify allocations and fix
merge and continue actions.
- CVE-2023-4813
* SECURITY UPDATE: memory leak in getaddrinfo
- debian/patches/any/CVE-2023-5156.patch: fix leak in getaddrinfo
introduced by the fix for CVE-2023-4806.
- CVE-2023-5156
-- Camila Camargo de Matos <email address hidden> Wed, 22 Nov 2023 10:18:45 -0300
|
Source diff to previous version |
CVE-2023-4806 |
A flaw was found in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an applicatio |
CVE-2023-4813 |
A flaw was found in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. Th |
CVE-2023-5156 |
A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application |
|
glibc (2.35-0ubuntu3.4) jammy-security; urgency=medium
* SECURITY UPDATE: privilege escalation in ld.so
- debian/patches/any/CVE-2023-4911.patch: terminate immediately if end
of input is reached in elf/dl-tunables.c.
- CVE-2023-4911
-- Marc Deslauriers <email address hidden> Mon, 25 Sep 2023 10:45:50 -0400
|
Source diff to previous version |
CVE-2023-4911 |
A buffer overflow was discovered in the GNU C Library's dynamic loader ... |
|
glibc (2.35-0ubuntu3.3) jammy; urgency=medium
* Drop SVE patches due to kernal-related performance regression
* Fix the armhf stripping exception for ld.so (LP: #1927192)
|
Source diff to previous version |
glibc (2.35-0ubuntu3.1) jammy; urgency=medium
* debian/maint: add a script to manage backports of patches from upstream
maintenance branch.
* Cherry-pick patches from upstream maintenance branch:
- 0001-S390-Add-new-s390-platform-z16.patch (LP: #1971612)
- 0002-powerpc-Fix-VSX-register-number-on-__strncpy_power9-.patch (LP: #1978130)
-- Michael Hudson-Doyle <email address hidden> Thu, 07 Jul 2022 11:23:23 +1200
|
1971612 |
[UBUNTU 22.04] GLIBC: Adding new s390 platform IBM z16 |
1978130 |
Ubuntu22.04: glibc: __strncpy_power9() uses uninitialised register vs18 value for filling after \\0 |
|
About
-
Send Feedback to @ubuntu_updates