summary |
shortlog | log |
commit |
commitdiff |
tree
first ⋅ prev ⋅ next
Arnaud Rebillout [Wed, 27 May 2026 04:49:44 +0000 (11:49 +0700)]
glibc (2.31-13+deb11u14) bullseye-security; urgency=medium
* Non-maintainer upload by the LTS Team.
* debian/patches/git-updates.diff: update from upstream stable branch
(4 commits total, including 2 CVE fixes):
- aarch64: MTE compatible strncmp
- nptl: Optimize trylock for high cache contention workloads
- memalign: reinstate alignment overflow check (CVE-2026-0861)
- posix: Reset wordexp_t fields with WRDE_REUSE (CVE-2025-15281)
* Backport patches to fix 3 CVEs:
- CVE-2025-8058: posix: Fix double-free after allocation failure in
regcomp
- CVE-2026-0915: resolv: Fix NSS DNS backend for getnetbyaddr
- CVE-2026-4046: iconvdata: Use pending character state in IBM1390,
IBM1399 character sets
[dgit import unpatched glibc 2.31-13+deb11u14]
Arnaud Rebillout [Wed, 27 May 2026 04:49:44 +0000 (11:49 +0700)]
Import glibc_2.31-13+deb11u14.debian.tar.xz
[dgit import tarball glibc 2.31-13+deb11u14 glibc_2.31-13+deb11u14.debian.tar.xz]
Aurelien Jarno [Thu, 12 Mar 2020 06:10:01 +0000 (07:10 +0100)]
Import glibc_2.31.orig.tar.xz
[dgit import orig glibc_2.31.orig.tar.xz]