[PATCH] Record CVE-2026-18374 fix

Florian Weimer fweimer@redhat.com
Fri Sep 4 15:18:10 GMT 2026


* Siddhesh Poyarekar:

> On 2026-09-04 10:57, Florian Weimer wrote:
>> ---
>>   advisories/GLIBC-SA-2026-0015 | 1 +
>>   1 file changed, 1 insertion(+)
>> diff --git a/advisories/GLIBC-SA-2026-0015
>> b/advisories/GLIBC-SA-2026-0015
>> index 3ea6602399..1863dfe75d 100644
>> --- a/advisories/GLIBC-SA-2026-0015
>> +++ b/advisories/GLIBC-SA-2026-0015
>> @@ -12,5 +12,6 @@ distributions and applications that process user-supplied values for
>>   CVE-Id: CVE-2026-18374
>>   Public-Date: 2026-08-27
>>   Vulnerable-Commit: 129d706d77587e4d6627cc1ebef9be0f7cbc65f0
>> +Fix-Commit: 9765a538ebf8661a6e5578e01e35a3dd30db7eb4 (2.45)
>>   Reported-by: AISLE in partnership with Red Hat
>>   CVSS: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L - 4.9
>> base-commit: cca93e5d88d3d4ed073c03100467696f652269e7
>> 
>
> Maybe also cca93e5d88d3d4ed073c03100467696f652269e7, the test case?

Have we done that in other cases?  I think it adds more noise?

Thanks,
Florian



More information about the Libc-alpha mailing list