[PATCH v2] Record CVE-2026-18374 fix

Siddhesh Poyarekar siddhesh@gotplt.org
Fri Sep 4 15:37:56 GMT 2026


On 2026-09-04 11:35, Florian Weimer wrote:
> ---
> v2: Include test case commit as well.
>   advisories/GLIBC-SA-2026-0015 | 2 ++
>   1 file changed, 2 insertions(+)
> 
> diff --git a/advisories/GLIBC-SA-2026-0015 b/advisories/GLIBC-SA-2026-0015
> index 3ea6602399..a656f6d63d 100644
> --- a/advisories/GLIBC-SA-2026-0015
> +++ b/advisories/GLIBC-SA-2026-0015
> @@ -12,5 +12,7 @@ distributions and applications that process user-supplied values for
>   CVE-Id: CVE-2026-18374
>   Public-Date: 2026-08-27
>   Vulnerable-Commit: 129d706d77587e4d6627cc1ebef9be0f7cbc65f0
> +Fix-Commit: 9765a538ebf8661a6e5578e01e35a3dd30db7eb4 (2.45)
> +Fix-Commit: cca93e5d88d3d4ed073c03100467696f652269e7 (2.45)
>   Reported-by: AISLE in partnership with Red Hat
>   CVSS: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L - 4.9
> 
> base-commit: cca93e5d88d3d4ed073c03100467696f652269e7
> 

Reviewed-by: Siddhesh Poyarekar <siddhesh@gotplt.org>


More information about the Libc-alpha mailing list