[Bug network/30843] potential use-after-free in getcanonname (CVE-2023-4806)
romain.geissler at amadeus dot com
sourceware-bugzilla@sourceware.org
Mon Sep 25 00:40:28 GMT 2023
https://sourceware.org/bugzilla/show_bug.cgi?id=30843
Romain Geissler <romain.geissler at amadeus dot com> changed:
What |Removed |Added
----------------------------------------------------------------------------
CC| |romain.geissler at amadeus dot com
--- Comment #12 from Romain Geissler <romain.geissler at amadeus dot com> ---
Hi,
Since it's a CVE fix, I guess some people will be tempted to backport the fix
in their own downstream forks (especially distros). Please note that the above
fix introduced a leak in getaddrinfo, for which a fix was just pushed in the
master branch as commit ec6b95c3303c700eb89eebeda2d7264cc184a796. Direct gitweb
link:
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=ec6b95c3303c700eb89eebeda2d7264cc184a796
I guess Siddhesh will backport this leak fix in release branches all the way
back to 2.34 after the commit will have spent some time in the master branch.
Cheers,
Romain
--
You are receiving this mail because:
You are on the CC list for the bug.
More information about the Glibc-bugs
mailing list