CVE-2025-4802 backporting glitch for 2.34 and 2.35
Siddhesh Poyarekar
siddhesh@gotplt.org
Sat May 24 12:55:26 GMT 2025
On 2025-05-22 18:59, Sam James via Libc-stable wrote:
> Florian Weimer <fweimer@redhat.com> writes:
>
>> I accidentally dropped EXTRA_UNSECURE_ENVVARS handling from 2.34 and
>> 2.35 with my backport (it's gone in 2.36 and forward).
>>
>> What should we do? I can revert the current fix and re-apply the fixed
>> version, and then we make it official by listing that commit in
>> advisories/GLIBC-SA-2025-0002?
>
> I don't see an alternative to this, unless we're aware of
> EXTRA_UNSECURE_ENVVARS being otherwise broken there and/or no evidence
> of anybody using it (you're better placed to know that, though).
Likewise.
Thanks,
Sid
More information about the Libc-alpha
mailing list