* [Buildroot] [PATCH 1/1] package/{glibc, localedef}: security bump version to 2.44-36-g2d5421ffc
@ 2026-08-29 19:07 Bernd Kuhls
2026-08-30 16:50 ` Julien Olivain via buildroot
0 siblings, 1 reply; 2+ messages in thread
From: Bernd Kuhls @ 2026-08-29 19:07 UTC (permalink / raw)
To: buildroot; +Cc: Romain Naour, Thomas Petazzoni
Fixes the following CVEs:
CVE-2026-19499:
https://gitlab.com/gnutools/glibc/-/commit/63b53df549451a5d69fcba6d7612ea99f517e8e3
CVE-2026-77117:
https://gitlab.com/gnutools/glibc/-/commit/6f9b2bfa500bf5d1cff5d990adfff4b71298dadd
CVE-2026-80489:
https://gitlab.com/gnutools/glibc/-/commit/cb61572ea3f773e1e1978f6c412cc36a30acdb0c
Added GLIBC_IGNORE_CVES for CVE-2026-19542 which was forgotten in
buildroot commit 58f31377389dd2f5090e4dd69deb4d5f994f88c0.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
package/glibc/glibc.hash | 2 +-
package/glibc/glibc.mk | 14 +++++++++++++-
package/localedef/localedef.mk | 2 +-
3 files changed, 15 insertions(+), 3 deletions(-)
diff --git a/package/glibc/glibc.hash b/package/glibc/glibc.hash
index bfeb5ab6bd..8d69de7b2a 100644
--- a/package/glibc/glibc.hash
+++ b/package/glibc/glibc.hash
@@ -1,5 +1,5 @@
# Locally calculated (fetched from git)
-sha256 028aa13d6c0737aecf0ec6ac0fa842e3a18c82bcdaeeb800d42a65a76dcbfe91 glibc-2.44-27-gae9225d55963c4420c49ccfa3f2fafc416f92032-git4.tar.gz
+sha256 39f6808e31a02da42f774912c6754ea22d5f076c4e935b1e233f3602d4d772c0 glibc-2.44-36-g2d5421ffca8893534d5e02ad38c28acd8e778fa3-git4.tar.gz
# Hashes for license files
sha256 edaef632cbb643e4e7a221717a6c441a4c1a7c918e6e4d56debc3d8739b233f6 COPYINGv2
diff --git a/package/glibc/glibc.mk b/package/glibc/glibc.mk
index e0332dadc4..f39e959c29 100644
--- a/package/glibc/glibc.mk
+++ b/package/glibc/glibc.mk
@@ -7,7 +7,7 @@
# Generate version string using:
# git describe --match 'glibc-*' --abbrev=40 origin/release/MAJOR.MINOR/master | cut -d '-' -f 2-
# When updating the version, please also update localedef
-GLIBC_VERSION = 2.44-27-gae9225d55963c4420c49ccfa3f2fafc416f92032
+GLIBC_VERSION = 2.44-36-g2d5421ffca8893534d5e02ad38c28acd8e778fa3
GLIBC_SITE = https://gitlab.com/gnutools/glibc.git
GLIBC_SITE_METHOD = git
@@ -25,6 +25,18 @@ GLIBC_CPE_ID_VENDOR = gnu
# allow proper matching with the CPE database.
GLIBC_CPE_ID_VERSION = $(word 1, $(subst -,$(space),$(GLIBC_VERSION)))
+# Fixed by 2.44-26-gd6ff274313d79feb864cc10eb775b91c817a67e9
+GLIBC_IGNORE_CVES += CVE-2026-19542
+
+# Fixed by 2.44-29-g63b53df549451a5d69fcba6d7612ea99f517e8e3
+GLIBC_IGNORE_CVES += CVE-2026-19499
+
+# Fixed by 2.44-30-g6f9b2bfa500bf5d1cff5d990adfff4b71298dadd
+GLIBC_IGNORE_CVES += CVE-2026-77117
+
+# Fixed by 2.44-31-gcb61572ea3f773e1e1978f6c412cc36a30acdb0c
+GLIBC_IGNORE_CVES += CVE-2026-80489
+
# This CVE is considered as not being security issues by
# upstream glibc:
# https://security-tracker.debian.org/tracker/CVE-2010-4756
diff --git a/package/localedef/localedef.mk b/package/localedef/localedef.mk
index c88f3f1fa6..048891724d 100644
--- a/package/localedef/localedef.mk
+++ b/package/localedef/localedef.mk
@@ -7,7 +7,7 @@
# Use the same VERSION, SITE, and LICENSE as target glibc
# As in glibc.mk, generate version string using:
# git describe --match 'glibc-*' --abbrev=40 origin/release/MAJOR.MINOR/master | cut -d '-' -f 2-
-LOCALEDEF_VERSION = 2.44-27-gae9225d55963c4420c49ccfa3f2fafc416f92032
+LOCALEDEF_VERSION = 2.44-36-g2d5421ffca8893534d5e02ad38c28acd8e778fa3
LOCALEDEF_SOURCE = glibc-$(LOCALEDEF_VERSION)$(BR_FMT_VERSION_git).tar.gz
LOCALEDEF_SITE = https://gitlab.com/gnutools/glibc.git
LOCALEDEF_SITE_METHOD = git
--
2.47.3
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [Buildroot] [PATCH 1/1] package/{glibc, localedef}: security bump version to 2.44-36-g2d5421ffc
2026-08-29 19:07 [Buildroot] [PATCH 1/1] package/{glibc, localedef}: security bump version to 2.44-36-g2d5421ffc Bernd Kuhls
@ 2026-08-30 16:50 ` Julien Olivain via buildroot
0 siblings, 0 replies; 2+ messages in thread
From: Julien Olivain via buildroot @ 2026-08-30 16:50 UTC (permalink / raw)
To: Bernd Kuhls; +Cc: buildroot, Romain Naour, Thomas Petazzoni
On 29/08/2026 21:07, Bernd Kuhls wrote:
> Fixes the following CVEs:
>
> CVE-2026-19499:
> https://gitlab.com/gnutools/glibc/-/commit/63b53df549451a5d69fcba6d7612ea99f517e8e3
>
> CVE-2026-77117:
> https://gitlab.com/gnutools/glibc/-/commit/6f9b2bfa500bf5d1cff5d990adfff4b71298dadd
>
> CVE-2026-80489:
> https://gitlab.com/gnutools/glibc/-/commit/cb61572ea3f773e1e1978f6c412cc36a30acdb0c
>
> Added GLIBC_IGNORE_CVES for CVE-2026-19542 which was forgotten in
> buildroot commit 58f31377389dd2f5090e4dd69deb4d5f994f88c0.
>
> Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Applied to master, thanks.
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-08-30 16:50 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-29 19:07 [Buildroot] [PATCH 1/1] package/{glibc, localedef}: security bump version to 2.44-36-g2d5421ffc Bernd Kuhls
2026-08-30 16:50 ` Julien Olivain via buildroot
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.