CVE-2025-4802 backporting glitch for 2.34 and 2.35
Sam James
sam@gentoo.org
Thu May 22 22:59:23 GMT 2025
Florian Weimer <fweimer@redhat.com> writes:
> I accidentally dropped EXTRA_UNSECURE_ENVVARS handling from 2.34 and
> 2.35 with my backport (it's gone in 2.36 and forward).
>
> What should we do? I can revert the current fix and re-apply the fixed
> version, and then we make it official by listing that commit in
> advisories/GLIBC-SA-2025-0002?
I don't see an alternative to this, unless we're aware of
EXTRA_UNSECURE_ENVVARS being otherwise broken there and/or no evidence
of anybody using it (you're better placed to know that, though).
(Or am I missing another option?)
More information about the Libc-alpha
mailing list