Cybersecurity Risk Assessment Request from Emerson for libnsl
Mark Wielaard
mark@klomp.org
Mon Aug 11 21:57:27 GMT 2025
Hi Saurabh,
On Mon, Aug 11, 2025 at 11:37:44AM +0000, KATARE, SAURABH [EMR/MSOL/PUNE] wrote:
> As part of our ongoing efforts to comply with the EU Cyber
> Resilience Act (CRA), we are currently conducting a cybersecurity
> risk assessment of third-party software vendors whose products or
> components are integrated into our systems.
>
> To support this initiative, we kindly request your input on the
> following questions related to your software product "libnsl" with
> version 2.39
Note the following from the glibc Version 2.32 NEWS:
libnsl is only built as shared library for backward compatibility
and the NSS modules "nis" and "nisplus" are not built at all and
libnsl's headers aren't installed. This compatibility is kept only
for architectures and ABIs that have been added in or before version
2.28. Replacement implementations based on TI-RPC, which
additionally support IPv6, are available from
<https://github.com/thkukuk/>.
So please check why exactly you have integrated libnsl into your
systems, how it is used and whether an alternative implementation
might be useful.
glibc isn't a product and the glibc community isn't a "third party
vendor".
If you are a commercial manufacturer or importer that wants to put
products with digital elements on the EU market, then you are
responsible for cybersecurity throughout your product's life cycle.
Please see https://sourceware.org/cyber-security-faq.html#eu-cra for
some recommendations around the EU CRA.
Cheers,
Mark
More information about the Libc-alpha
mailing list