[Bug network/30843] potential use-after-free in getcanonname (CVE-2023-4806)

romain.geissler at amadeus dot com sourceware-bugzilla@sourceware.org
Mon Sep 25 00:40:28 GMT 2023


https://sourceware.org/bugzilla/show_bug.cgi?id=30843

Romain Geissler <romain.geissler at amadeus dot com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |romain.geissler at amadeus dot com

--- Comment #12 from Romain Geissler <romain.geissler at amadeus dot com> ---
Hi,

Since it's a CVE fix, I guess some people will be tempted to backport the fix
in their own downstream forks (especially distros). Please note that the above
fix introduced a leak in getaddrinfo, for which a fix was just pushed in the
master branch as commit ec6b95c3303c700eb89eebeda2d7264cc184a796. Direct gitweb
link:
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=ec6b95c3303c700eb89eebeda2d7264cc184a796

I guess Siddhesh will backport this leak fix in release branches all the way
back to 2.34 after the commit will have spent some time in the master branch.

Cheers,
Romain

-- 
You are receiving this mail because:
You are on the CC list for the bug.


More information about the Glibc-bugs mailing list