[PATCH] advisories: Update GLIBC-SA-2026-0005 and GLIBC-SA-2026-0006.
Carlos O'Donell
carlos@redhat.com
Fri Mar 27 12:49:14 GMT 2026
On 3/27/26 8:09 AM, Carlos O'Donell wrote:
> Update advisories with Fix-Commit information for 2.43.9000 and 2.44.
>
> Update NEWS with advisory entries.
This was fairly mechanical so I'm going to push this without further review.
We can adjust the data if it's wrong, but I don't think it's wrong (having just
reviewed the commits again).
> ---
> NEWS | 9 +++++++--
> advisories/GLIBC-SA-2026-0005 | 2 ++
> advisories/GLIBC-SA-2026-0006 | 2 ++
> 3 files changed, 11 insertions(+), 2 deletions(-)
>
> diff --git a/NEWS b/NEWS
> index bb942fcc94..c6e9a83923 100644
> --- a/NEWS
> +++ b/NEWS
> @@ -34,8 +34,13 @@ Security related changes:
> The following CVEs were fixed in this release, details of which can be
> found in the advisories directory of the release tarball:
>
> - [The release manager will add the list generated by
> - scripts/process-advisories.sh just before the release.]
> + GLIBC-SA-2026-0005:
> + gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS
> + response (CVE-2026-4437)
> +
> + GLIBC-SA-2026-0006:
> + gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames
> + (CVE-2026-4438)
>
> The following bugs were resolved with this release:
>
> diff --git a/advisories/GLIBC-SA-2026-0005 b/advisories/GLIBC-SA-2026-0005
> index a1a9991f84..7a50a43263 100644
> --- a/advisories/GLIBC-SA-2026-0005
> +++ b/advisories/GLIBC-SA-2026-0005
> @@ -31,5 +31,7 @@ Vulnerable-Commit: 32e5db37684ffcbc6ae34fcc6cdcf28670506baa (2.34-323)
> Vulnerable-Commit: def97e7f71a07517810f7263213d607e08ad21f1 (2.35-188)
> Vulnerable-Commit: 77f523c473878ec0051582ef15161c6982879095 (2.36-30)
> Vulnerable-Commit: e32547d661a43da63368e488b6cfa9c53b4dcf92 (2.37)
> +Fix-Commit: 5c6fca0c62ce5bd6e68e259f138097756cbafd4d (2.43-16)
> +Fix-Commit: 9f5f18aab40ec6b61fa49a007615e6077e9a979b (2.44)
> Reported-by: Antonio Maini (0rbitingZer0) - 0rbitingZer0@proton.me
> Reported-by: Kevin Farrell
> diff --git a/advisories/GLIBC-SA-2026-0006 b/advisories/GLIBC-SA-2026-0006
> index 106cf4fd84..1ac70de4d9 100644
> --- a/advisories/GLIBC-SA-2026-0006
> +++ b/advisories/GLIBC-SA-2026-0006
> @@ -22,4 +22,6 @@ Vulnerable-Commit: 32e5db37684ffcbc6ae34fcc6cdcf28670506baa (2.34-323)
> Vulnerable-Commit: def97e7f71a07517810f7263213d607e08ad21f1 (2.35-188)
> Vulnerable-Commit: 77f523c473878ec0051582ef15161c6982879095 (2.36-30)
> Vulnerable-Commit: e32547d661a43da63368e488b6cfa9c53b4dcf92 (2.37)
> +Fix-Commit: dd9945c0ba40d2dbc9eb7c99291ba6b69bd66718 (2.43-17)
> +Fix-Commit: e10977481f4db4b2a3ce34fa4c3a1e26651ae312 (2.44)
> Reported-by: Antonio Maini (0rbitingZer0) - 0rbitingZer0@proton.me
--
Cheers,
Carlos.
More information about the Libc-alpha
mailing list