From: Peter Korsgaard <peter@korsgaard.com>
To: buildroot@busybox.net
Subject: [Buildroot] [PATCH] glibc: bump version for post-2.28 security fixes
Date: Fri, 30 Nov 2018 11:20:50 +0100 [thread overview]
Message-ID: <87h8fy6f3x.fsf@dell.be.48ers.dk> (raw)
In-Reply-To: <20181130090557.14640-1-peter@korsgaard.com> (Peter Korsgaard's message of "Fri, 30 Nov 2018 10:05:57 +0100")
>>>>> "Peter" == Peter Korsgaard <peter@korsgaard.com> writes:
> Fixes the following security vulnerability:
> CVE-2018-19591: A file descriptor leak in if_nametoindex can lead to a
> denial of service due to resource exhaustion when processing getaddrinfo
> calls with crafted host names. Reported by Guido Vranken.
> Adhemerval Zanella (2):
> Fix misreported errno on preadv2/pwritev2 (BZ#23579)
> x86: Fix Haswell CPU string flags (BZ#23709)
> Alexandra H?jkov? (1):
> Add an additional test to resolv/tst-resolv-network.c
> Andreas Schwab (2):
> Fix stack overflow in tst-setcontext9 (bug 23717)
> libanl: properly cleanup if first helper thread creation failed (bug 22927)
> DJ Delorie (2):
> malloc: tcache double free check
> malloc: tcache double free check
> Florian Weimer (9):
> conform: XFAIL siginfo_t si_band test on sparc64
> stdlib/test-bz22786: Avoid spurious test failures using alias mappings
> stdlib/test-bz22786: Avoid memory leaks in the test itself
> support_blob_repeat: Call mkstemp directory for the backing file
> stdlib/tst-strtod-overflow: Switch to support_blob_repeat
> nscd: Fix use-after-free in addgetnetgrentX [BZ #23520]
> support: Print timestamps in timeout handler
> Revert "malloc: tcache double free check" [BZ #23907]
> CVE-2018-19591: if_nametoindex: Fix descriptor for overlong name [BZ #23927]
> H.J. Lu (2):
> i386: Use _dl_runtime_[resolve|profile]_shstk for SHSTK [BZ #23716]
> Check multiple NT_GNU_PROPERTY_TYPE_0 notes [BZ #23509]
> Ilya Yu. Malakhov (1):
> signal: Use correct type for si_band in siginfo_t [BZ #23562]
> Istvan Kurucsai (1):
> malloc: Additional checks for unsorted bin integrity I.
> Joseph Myers (2):
> Update syscall-names.list for Linux 4.18.
> Update kernel version in syscall-names.list to 4.19.
> Moritz Eckert (1):
> malloc: Mitigate null-byte overflow attacks
> Paul Eggert (1):
> Fix tzfile low-memory assertion failure
> Paul Pluzhnikov (2):
> Fix BZ#23400 (creating temporary files in source tree), and undefined behavior in test.
> [BZ #20271] Add newlines in __libc_fatal calls.
> Pochang Chen (1):
> malloc: Verify size of top chunk.
> Rafal Luzynski (1):
> kl_GL: Fix spelling of Sunday, should be "sapaat" (bug 20209).
> Stefan Liebler (2):
> Fix race in pthread_mutex_lock while promoting to PTHREAD_MUTEX_ELISION_NP [BZ #23275]
> Test stdlib/test-bz22786 exits now with unsupported if malloc fails.
> Szabolcs Nagy (2):
> i64: fix missing exp2f, log2f and powf symbols in libm.a [BZ #23822]
> Increase timeout of libio/tst-readline
> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Committed, thanks.
--
Bye, Peter Korsgaard
prev parent reply other threads:[~2018-11-30 10:20 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-11-30 9:05 [Buildroot] [PATCH] glibc: bump version for post-2.28 security fixes Peter Korsgaard
2018-11-30 10:20 ` Peter Korsgaard [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87h8fy6f3x.fsf@dell.be.48ers.dk \
--to=peter@korsgaard.com \
--cc=buildroot@busybox.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.