Merge version 2.36-9+rpi1+deb12u4 and 2.36-9+deb12u7 to produce 2.36-9+rpi1+deb12u7 archive/raspbian/2.36-9+rpi1+deb12u7 raspbian/2.36-9+rpi1+deb12u7
authorRaspbian automatic forward porter <root@raspbian.org>
Sun, 26 May 2024 04:58:35 +0000 (05:58 +0100)
committerRaspbian automatic forward porter <root@raspbian.org>
Sun, 26 May 2024 04:58:35 +0000 (05:58 +0100)
1  2 
debian/changelog
debian/patches/series

index fa7e3d9f1e0e0002751d6b086e41ca9574f397b7,508118be47971ac0d3f7497c15e3eb9e2ddd416f..3f8431828db995181644b619a767bd6ad50bef52
@@@ -1,12 -1,40 +1,50 @@@
- glibc (2.36-9+rpi1+deb12u4) bookworm-staging; urgency=medium
++glibc (2.36-9+rpi1+deb12u7) bookworm-staging; urgency=medium
 +
 +  [changes brought forward from 2.25-2+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Wed, 29 Nov 2017 03:00:21 +0000]
 +  * Disable testsuite.
 +
 +  [changes brought forward from 2.35-1+rpi2 by Peter Michael Green <plugwash@raspbian.org> at Sun, 02 Oct 2022 17:46:25 +0000]
 +  * Remove valgrind breaks.
 +
-  -- Raspbian forward porter <root@raspbian.org>  Tue, 06 Feb 2024 22:41:45 +0000
++ -- Raspbian forward porter <root@raspbian.org>  Sun, 26 May 2024 04:58:34 +0000
++
+ glibc (2.36-9+deb12u7) bookworm-security; urgency=medium
+   * debian/patches/local-CVE-2024-33599-nscd.diff: Fix a stack-based buffer
+     overflow in nscd netgroup cache (CVE-2024-33599).
+   * debian/patches/local-CVE-2024-33600-nscd.diff: Fix a null pointer
+     dereferences in nscd after failed netgroup cache insertion
+     (CVE-2024-33600).
+   * debian/patches/any/local-CVE-2024-33601-33602-nscd.diff: Fix a DoS in nscd
+     in case of memory allocation failure (CVE-2024-33601) and a memory
+     corruption in nscd when the underlying NSS callback function does not use
+     the buffer space to store all strings (CVE-2024-33602).
+  -- Aurelien Jarno <aurel32@debian.org>  Tue, 30 Apr 2024 23:07:28 +0200
+ glibc (2.36-9+deb12u6) bookworm-security; urgency=medium
+   * debian/patches/any/local-CVE-2024-2961-iso-2022-cn-ext.diff: Fix
+     out-of-bound writes when writing escape sequence in iconv ISO-2022-CN-EXT
+     module (CVE-2024-2961).  Closes: #1069191.
+  -- Aurelien Jarno <aurel32@debian.org>  Fri, 19 Apr 2024 18:34:04 +0200
+ glibc (2.36-9+deb12u5) bookworm; urgency=medium
+   * debian/patches/git-updates.diff: update from upstream stable branch:
+     - any/local-CVE-2023-4911.patch: upstreamed.
+     - any/local-CVE-2023-6246.patch: upstreamed.
+     - any/local-CVE-2023-6779.patch: upstreamed.
+     - any/local-CVE-2023-6780.patch: upstreamed.
+     - Revert fix to always call destructors in reverse constructor order due
+       to unforeseen application compatibility issues.
+     - Fix a DTV corruption due to a reuse of a TLS module ID following dlclose
+       with unused TLS.
+     - Fix the DTV field load on x32.
+     - Fix the TCB field load on x32.
+  -- Aurelien Jarno <aurel32@debian.org>  Sun, 24 Mar 2024 13:07:31 +0100
  
  glibc (2.36-9+deb12u4) bookworm-security; urgency=medium
  
index 3982018e2bf7d694e7171b59666d0237208f7ced,3701a83f6e2b3c8e320b3b543cd440704bc4bf79..985db41cf8e7d00a885a9452beaaf022999d0f79
@@@ -105,9 -119,8 +105,9 @@@ any/local-test-install.dif
  any/local-cross.patch
  any/git-floatn-gcc-13-support.diff
  any/local-disable-tst-bz29951.diff
- any/local-CVE-2023-4911.patch
- any/local-CVE-2023-6246.patch
- any/local-CVE-2023-6779.patch
- any/local-CVE-2023-6780.patch
  any/local-qsort-memory-corruption.patch
+ any/local-CVE-2024-2961-iso-2022-cn-ext.diff
+ any/local-CVE-2024-33599-nscd.diff
+ any/local-CVE-2024-33600-nscd.diff
+ any/local-CVE-2024-33601-33602-nscd.diff
 +auto-2.34-7+rpi1-de346af12a6cb5181ed2ab174fb35c88f3b64f4b-1663212931