From: Peter Korsgaard <peter@korsgaard.com>
To: buildroot@busybox.net
Subject: [Buildroot] [PATCH] glibc: bump version for post-2.28 security fixes
Date: Fri, 30 Nov 2018 11:20:50 +0100 [thread overview]
Message-ID: <87h8fy6f3x.fsf@dell.be.48ers.dk> (raw)
In-Reply-To: <20181130090557.14640-1-peter@korsgaard.com> (Peter Korsgaard's message of "Fri, 30 Nov 2018 10:05:57 +0100")
>>>>> "Peter" == Peter Korsgaard <peter@korsgaard.com> writes:
> Fixes the following security vulnerability:
> CVE-2018-19591: A file descriptor leak in if_nametoindex can lead to a
> denial of service due to resource exhaustion when processing getaddrinfo
> calls with crafted host names. Reported by Guido Vranken.
> Adhemerval Zanella (2):
> Fix misreported errno on preadv2/pwritev2 (BZ#23579)
> x86: Fix Haswell CPU string flags (BZ#23709)
> Alexandra H?jkov? (1):
> Add an additional test to resolv/tst-resolv-network.c
> Andreas Schwab (2):
> Fix stack overflow in tst-setcontext9 (bug 23717)
> libanl: properly cleanup if first helper thread creation failed (bug 22927)
> DJ Delorie (2):
> malloc: tcache double free check
> malloc: tcache double free check
> Florian Weimer (9):
> conform: XFAIL siginfo_t si_band test on sparc64
> stdlib/test-bz22786: Avoid spurious test failures using alias mappings
> stdlib/test-bz22786: Avoid memory leaks in the test itself
> support_blob_repeat: Call mkstemp directory for the backing file
> stdlib/tst-strtod-overflow: Switch to support_blob_repeat
> nscd: Fix use-after-free in addgetnetgrentX [BZ #23520]
> support: Print timestamps in timeout handler
> Revert "malloc: tcache double free check" [BZ #23907]
> CVE-2018-19591: if_nametoindex: Fix descriptor for overlong name [BZ #23927]
> H.J. Lu (2):
> i386: Use _dl_runtime_[resolve|profile]_shstk for SHSTK [BZ #23716]
> Check multiple NT_GNU_PROPERTY_TYPE_0 notes [BZ #23509]
> Ilya Yu. Malakhov (1):
> signal: Use correct type for si_band in siginfo_t [BZ #23562]
> Istvan Kurucsai (1):
> malloc: Additional checks for unsorted bin integrity I.
> Joseph Myers (2):
> Update syscall-names.list for Linux 4.18.
> Update kernel version in syscall-names.list to 4.19.
> Moritz Eckert (1):
> malloc: Mitigate null-byte overflow attacks
> Paul Eggert (1):
> Fix tzfile low-memory assertion failure
> Paul Pluzhnikov (2):
> Fix BZ#23400 (creating temporary files in source tree), and undefined behavior in test.
> [BZ #20271] Add newlines in __libc_fatal calls.
> Pochang Chen (1):
> malloc: Verify size of top chunk.
> Rafal Luzynski (1):
> kl_GL: Fix spelling of Sunday, should be "sapaat" (bug 20209).
> Stefan Liebler (2):
> Fix race in pthread_mutex_lock while promoting to PTHREAD_MUTEX_ELISION_NP [BZ #23275]
> Test stdlib/test-bz22786 exits now with unsupported if malloc fails.
> Szabolcs Nagy (2):
> i64: fix missing exp2f, log2f and powf symbols in libm.a [BZ #23822]
> Increase timeout of libio/tst-readline
> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Committed, thanks.
--
Bye, Peter Korsgaard
prev parent reply other threads:[~2018-11-30 10:20 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-11-30 9:05 [Buildroot] [PATCH] glibc: bump version for post-2.28 security fixes Peter Korsgaard
2018-11-30 10:20 ` Peter Korsgaard [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87h8fy6f3x.fsf@dell.be.48ers.dk \
--to=peter@korsgaard.com \
--cc=buildroot@busybox.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox