[PATCH] advisories: Update GLIBC-SA-2026-0005 and GLIBC-SA-2026-0006.

Carlos O'Donell carlos@redhat.com
Fri Mar 27 12:09:48 GMT 2026


Update advisories with Fix-Commit information for 2.43.9000 and 2.44.

Update NEWS with advisory entries.
---
 NEWS                          | 9 +++++++--
 advisories/GLIBC-SA-2026-0005 | 2 ++
 advisories/GLIBC-SA-2026-0006 | 2 ++
 3 files changed, 11 insertions(+), 2 deletions(-)

diff --git a/NEWS b/NEWS
index bb942fcc94..c6e9a83923 100644
--- a/NEWS
+++ b/NEWS
@@ -34,8 +34,13 @@ Security related changes:
 The following CVEs were fixed in this release, details of which can be
 found in the advisories directory of the release tarball:
 
-  [The release manager will add the list generated by
-  scripts/process-advisories.sh just before the release.]
+  GLIBC-SA-2026-0005:
+    gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS
+    response (CVE-2026-4437)
+
+  GLIBC-SA-2026-0006:
+    gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames
+    (CVE-2026-4438)
 
 The following bugs were resolved with this release:
 
diff --git a/advisories/GLIBC-SA-2026-0005 b/advisories/GLIBC-SA-2026-0005
index a1a9991f84..7a50a43263 100644
--- a/advisories/GLIBC-SA-2026-0005
+++ b/advisories/GLIBC-SA-2026-0005
@@ -31,5 +31,7 @@ Vulnerable-Commit: 32e5db37684ffcbc6ae34fcc6cdcf28670506baa (2.34-323)
 Vulnerable-Commit: def97e7f71a07517810f7263213d607e08ad21f1 (2.35-188)
 Vulnerable-Commit: 77f523c473878ec0051582ef15161c6982879095 (2.36-30)
 Vulnerable-Commit: e32547d661a43da63368e488b6cfa9c53b4dcf92 (2.37)
+Fix-Commit: 5c6fca0c62ce5bd6e68e259f138097756cbafd4d (2.43-16)
+Fix-Commit: 9f5f18aab40ec6b61fa49a007615e6077e9a979b (2.44)
 Reported-by: Antonio Maini (0rbitingZer0) - 0rbitingZer0@proton.me
 Reported-by: Kevin Farrell
diff --git a/advisories/GLIBC-SA-2026-0006 b/advisories/GLIBC-SA-2026-0006
index 106cf4fd84..1ac70de4d9 100644
--- a/advisories/GLIBC-SA-2026-0006
+++ b/advisories/GLIBC-SA-2026-0006
@@ -22,4 +22,6 @@ Vulnerable-Commit: 32e5db37684ffcbc6ae34fcc6cdcf28670506baa (2.34-323)
 Vulnerable-Commit: def97e7f71a07517810f7263213d607e08ad21f1 (2.35-188)
 Vulnerable-Commit: 77f523c473878ec0051582ef15161c6982879095 (2.36-30)
 Vulnerable-Commit: e32547d661a43da63368e488b6cfa9c53b4dcf92 (2.37)
+Fix-Commit: dd9945c0ba40d2dbc9eb7c99291ba6b69bd66718 (2.43-17)
+Fix-Commit: e10977481f4db4b2a3ce34fa4c3a1e26651ae312 (2.44)
 Reported-by: Antonio Maini (0rbitingZer0) - 0rbitingZer0@proton.me
-- 
2.53.0



More information about the Libc-alpha mailing list