Hi Aurelien, The following vulnerability was published for glibc. It appeared on Red Hat but only have so far the Red Hat bugzilla entry. CVE-2026-77117[0]: | Non-progress DoS in SHIFT_JISX0213 -> Is this something reported upstream? If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-77117 https://www.cve.org/CVERecord?id=CVE-2026-77117 [1] https://bugzilla.redhat.com/show_bug.cgi?id=2523274 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hi Salvatore, https://sourceware.org/bugzilla/show_bug.cgi?id=34556 It is linked to CVE-2026-80489 which is reported here: https://sourceware.org/bugzilla/show_bug.cgi?id=34568 There are also patches being reviewed: https://sourceware.org/pipermail/libc-alpha/2026-August/180042.html I'll include them in one of the next upload to unstable, once they are committed upstream. I'll then try to get them (with a few other ones) in the 13.8 point release. Regards Aurelien
Hello, Bug #1145880 in glibc reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/glibc-team/glibc/-/commit/5319205e44bdc0a6a26160468d7ec0782191d498 ------------------------------------------------------------------------ debian/patches/git-updates.diff: update from upstream stable branch: * debian/patches/git-updates.diff: update from upstream stable branch: - Fix unresolvable R_68K_32 relocation against symbol `fmod@@GLIBC_2.43' on m68k. Closes: #1145406. - Fix a buffer overflow in strfmon right-justification padding (CVE-2026-19499). Closes: #1145891. - Fix a hang when decoding SHIFT_JISX0213 to UTF-32 (CVE-2026-77117). Closes: #1145880. - Fix a hand when decoding EUC_JISX0213 to UTF-32 (CVE-2026-80489). Closes: #1145987. - Fix setrlimit compat symbol for negative rlim values besides -1 on alpha. - Fix stack alignment in makecontext on alpha. - Fix FE_NOMASK_ENV on alpha. - Mark test-float32x-float64-div as failing on alpha. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1145880
Hello, Bug #1145880 in glibc reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/glibc-team/glibc/-/commit/f1b430fe9bbd1fa047f80001da4e4428f25ab137 ------------------------------------------------------------------------ debian/patches/git-updates.diff: update from upstream stable branch: * debian/patches/git-updates.diff: update from upstream stable branch: - Fix out-of-bounds stack array write in tdelete (CVE-2026-19542). - Fix a buffer overflow in strfmon right-justification padding (CVE-2026-19499). Closes: #1145891. - Fix a hang when decoding SHIFT_JISX0213 to UTF-32 (CVE-2026-77117). Closes: #1145880. - Fix a hand when decoding EUC_JISX0213 to UTF-32 (CVE-2026-80489). Closes: #1145987. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1145880