UbuntuUpdates.org

Package "libc-bin"

Name: libc-bin

Description:

GNU C Library: Binaries

Latest version: 2.43-2ubuntu2.4
Release: resolute (26.04)
Level: security
Repository: main
Head package: glibc
Homepage: https://www.gnu.org/software/libc/libc.html

Links


Download "libc-bin"


Other versions of "libc-bin" in Resolute

Repository Area Version
base main 2.43-2ubuntu2
updates main 2.43-2ubuntu2.4

Changelog

Version: 2.43-2ubuntu2.4 2026-09-08 17:07:38 UTC

glibc (2.43-2ubuntu2.4) resolute-security; urgency=medium

  * SECURITY UPDATE: Buffer overflow in strfmon right-justification padding
    - debian/patches/CVE-2026-19499.patch: stdlib: Fix right-justification in
      strfmon (bug 34510, CVE-2026-19499) in stdlib/Makefile,
      stdlib/strfmon_l.c, stdlib/tst-strfmon-bug34510.c.
    - CVE-2026-19499
  * SECURITY UPDATE: Out-of-bounds stack array access in tdelete
    - debian/patches/CVE-2026-19542.patch: misc: Fix out-of-bounds array write
      in tdelete (bug 34506) in misc/tsearch.c.
    - CVE-2026-19542
  * SECURITY UPDATE: invalid memory when calling wordexp with WRDE_APPEND
    - debian/patches/CVE-2026-6368.patch: posix: Fix wordexp WRDE_APPEND to
      preserve state on non-NOSPACE errors (BZ 34090, CVE-2026-6368) in
      posix/Makefile, posix/tst-wordexp-append.c, posix/wordexp.c.
    - CVE-2026-6368
  * SECURITY UPDATE: stack clash issue when expanding long tilde paths
    - debian/patches/CVE-2026-6791.patch: posix: Fix stack overflow in wordexp
      tilde expansion (BZ 34091, CVE-2026-6791) in posix/Makefile, posix/tst-
      wordexp-tilde.c, posix/tst-wordexp-tilde.root/etc/group, posix/tst-
      wordexp-tilde.root/etc/nsswitch.conf, posix/tst-wordexp-
      tilde.root/etc/passwd, posix/wordexp.c.
    - CVE-2026-6791
  * SECURITY UPDATE: SHIFT_JISX0213 converter hang
    - debian/patches/CVE-2026-77117-1.patch: iconvdata: SHIFT_JISX0213 decoding
      lacks pending character reset (CVE-2026-77117) in
      iconvdata/shift_jisx0213.c.
    - debian/patches/CVE-2026-77117-2.patch: iconvdata: Test case for bug 34556,
      bug 34568 in iconvdata/Makefile, iconvdata/tst-jisx0213-progress.c.
    - CVE-2026-77117
  * SECURITY UPDATE: EUC_JISX0213 converter hang
    - debian/patches/CVE-2026-80489.patch: iconvdata: EUC_JISX0213 decoding
      lacks pending character reset (CVE-2026-80489) in iconvdata/euc-
      jisx0213.c.
    - CVE-2026-80489

 -- Marc Deslauriers Thu, 03 Sep 2026 10:09:39 -0400

Source diff to previous version
CVE-2026-19542 Out-of-bounds stack array access in tdelete
CVE-2026-6368 Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv me
CVE-2026-6791 When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the use

Version: 2.43-2ubuntu2.3 2026-07-27 14:10:16 UTC
No changelog available yet.



About   -   Send Feedback to @ubuntu_updates