#1145880 glibc: CVE-2026-77117

Package:
src:glibc
Source:
src:glibc
Submitter:
Salvatore Bonaccorso
Date:
2026-08-29 14:27:02 UTC
Severity:
normal
Tags:
#1145880#5
Date:
2026-08-27 13:41:04 UTC
From:
To:
Hi Aurelien,

The following vulnerability was published for glibc.

It appeared on Red Hat but only have so far the Red Hat bugzilla
entry.

CVE-2026-77117[0]:
| Non-progress DoS in SHIFT_JISX0213 ->

Is this something reported upstream?

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-77117
https://www.cve.org/CVERecord?id=CVE-2026-77117
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2523274

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1145880#10
Date:
2026-08-27 20:34:09 UTC
From:
To:
Hi Salvatore,
https://sourceware.org/bugzilla/show_bug.cgi?id=34556

It is linked to CVE-2026-80489 which is reported here:
https://sourceware.org/bugzilla/show_bug.cgi?id=34568

There are also patches being reviewed:
https://sourceware.org/pipermail/libc-alpha/2026-August/180042.html

I'll include them in one of the next upload to unstable, once they are
committed upstream. I'll then try to get them (with a few other ones) in
the 13.8 point release.

Regards
Aurelien

#1145880#13
Date:
2026-08-29 13:40:17 UTC
From:
To:
Hello,

Bug #1145880 in glibc reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/glibc-team/glibc/-/commit/5319205e44bdc0a6a26160468d7ec0782191d498
------------------------------------------------------------------------
debian/patches/git-updates.diff: update from upstream stable branch:

* debian/patches/git-updates.diff: update from upstream stable branch:
  - Fix unresolvable R_68K_32 relocation against symbol `fmod@@GLIBC_2.43'
    on m68k.  Closes: #1145406.
  - Fix a buffer overflow in strfmon right-justification padding
    (CVE-2026-19499).  Closes: #1145891.
  - Fix a hang when decoding SHIFT_JISX0213 to UTF-32 (CVE-2026-77117).
    Closes: #1145880.
  - Fix a hand when decoding EUC_JISX0213 to UTF-32 (CVE-2026-80489).
    Closes: #1145987.
  - Fix setrlimit compat symbol for negative rlim values besides -1 on
    alpha.
  - Fix stack alignment in makecontext on alpha.
  - Fix FE_NOMASK_ENV on alpha.
  - Mark test-float32x-float64-div as failing on alpha.
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1145880

#1145880#18
Date:
2026-08-29 14:25:46 UTC
From:
To:
Hello,

Bug #1145880 in glibc reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/glibc-team/glibc/-/commit/f1b430fe9bbd1fa047f80001da4e4428f25ab137
------------------------------------------------------------------------
debian/patches/git-updates.diff: update from upstream stable branch:

* debian/patches/git-updates.diff: update from upstream stable branch:
  - Fix out-of-bounds stack array write in tdelete (CVE-2026-19542).
  - Fix a buffer overflow in strfmon right-justification padding
    (CVE-2026-19499).  Closes: #1145891.
  - Fix a hang when decoding SHIFT_JISX0213 to UTF-32 (CVE-2026-77117).
    Closes: #1145880.
  - Fix a hand when decoding EUC_JISX0213 to UTF-32 (CVE-2026-80489).
    Closes: #1145987.
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1145880