Openembedded Core Discussions
 help / color / mirror / Atom feed
From: Mike Crowe <mac@mcrowe.com>
To: Scott Murray <scott.murray@konsulko.com>
Cc: Steve Sakoman <steve@sakoman.com>,
	mac@mcrowe.com, openembedded-core@lists.openembedded.org
Subject: Re: [OE-core] [dunfell][PATCH] glibc: Fix CVE-2023-4911 "Looney Tunables"
Date: Thu, 5 Oct 2023 19:49:35 +0100	[thread overview]
Message-ID: <ZR8FP8EoxdiM8RHQ@mcrowe.com> (raw)
In-Reply-To: <b98ca516-ff3d-48fa-bb5b-15fe93db14b0@konsulko.com>

On Thursday 05 October 2023 at 11:16:29 -0400, Scott Murray wrote:
> Debian's page at https://security-tracker.debian.org/tracker/CVE-2023-4911
> indicates at the bottom that they're only vulnerable on their 2.31 based
> versions because they backported the change that introduced the
> vulnerability, which I don't believe has been done in oe-core...

It has.

The openembedded-core dunfell branch is using glibc
2d4f26e5cfda682f9ce61444b81533b83f6381af. This commit is a successor of
8e88c0d8885f68d22f47b22969c273004c6e719f, which is the backport of
2ed18c5b534d9e92fc006202a5af0df6b72e7aca (as mentioned in the Qualsys
advisory) that introduced the vulnerability.

Mike.


  reply	other threads:[~2023-10-05 18:49 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-10-05  8:54 [dunfell][PATCH] glibc: Fix CVE-2023-4911 "Looney Tunables" mac
2023-10-05 14:17 ` [OE-core] " Steve Sakoman
2023-10-05 15:16   ` Scott Murray
2023-10-05 18:49     ` Mike Crowe [this message]
2023-10-05 19:23       ` Scott Murray
2023-10-05 18:44   ` Mike Crowe
2023-10-05 19:25     ` Steve Sakoman
2023-10-05 20:37       ` Mike Crowe
2023-10-05 20:39         ` Steve Sakoman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ZR8FP8EoxdiM8RHQ@mcrowe.com \
    --to=mac@mcrowe.com \
    --cc=openembedded-core@lists.openembedded.org \
    --cc=scott.murray@konsulko.com \
    --cc=steve@sakoman.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox