Hi, The following vulnerability was published for glibc. CVE-2026-8674[0]: | Initializing the DNS stub resolver from an /etc/resolv.conf file, or | a LOCALDOMAIN environment variable, whose search list contains a | domain of roughly 200 characters or more in the GNU C Library | version 2.26 to 2.44 results in an assertion failure which aborts | the process. The resolver truncates the search list when copying it | into the fixed-size _res.defdname buffer, then asserts that the copy | is consistent with the full configuration. The consistency check | compared against the wrong size and did not handle a first entry | that does not fit, so a correctly truncated list failed the | assertion. Any process that resolves names through the library is | affected, including long-running processes that reload | /etc/resolv.conf on the next query after it changes. Search domains | are commonly written to /etc/resolv.conf from data received over | DHCP or from a VPN server, so an attacker on the local network may | be able to trigger this without privileges on the target system, | subject to validation by the network configuration software. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-8674 https://www.cve.org/CVERecord?id=CVE-2026-8674 [1] https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0021 [2] https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a Please adjust the affected versions in the BTS as needed. Rgards, Salvatore
Hello, Bug #1148168 in glibc reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/glibc-team/glibc/-/commit/c51215b41c67fc4dde4c1db00fbcd8eb101e94ca ------------------------------------------------------------------------ debian/patches/git-updates.diff: update from upstream stable branch: * debian/patches/git-updates.diff: update from upstream stable branch: - Fix swapped arguments in nss_files service parser. - Fix swapped arguments in hesiod service parser. - Skip pretty-printer tests without python3. - Keep needed last transition to new type in TZif files generated by zic. - Fix an assertion failure in the DNS stub resolver with a long search domain (CVE-2026-8674). Closes: #1148168. - debian/patches/any/local-nss-overflow.diff: rebased. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1148168
We believe that the bug you reported is fixed in the latest version of
glibc, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1148168@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Aurelien Jarno <aurel32@debian.org> (supplier of updated glibc package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 19 Sep 2026 11:29:42 +0200
Source: glibc
Architecture: source
Version: 2.43-6
Distribution: unstable
Urgency: medium
Maintainer: GNU Libc Maintainers <debian-glibc@lists.debian.org>
Changed-By: Aurelien Jarno <aurel32@debian.org>
Closes: 1148168
Changes:
glibc (2.43-6) unstable; urgency=medium
.
[ Aurelien Jarno ]
* debian/patches/git-updates.diff: update from upstream stable branch:
- Fix swapped arguments in nss_files service parser.
- Fix swapped arguments in hesiod service parser.
- Skip pretty-printer tests without python3.
- Keep needed last transition to new type in TZif files generated by zic.
- Fix an assertion failure in the DNS stub resolver with a long search
domain (CVE-2026-8674). Closes: #1148168.
- debian/patches/any/local-nss-overflow.diff: rebased.
.
[ Bjarni Ingi Gislason ]
* debian/local/manpages/getconf.1: editorial fixes.
* debian/local/manpages/validlocale.8: editorial fixes.
Checksums-Sha1:
ff3d2fa204130d19b9b2950d2c3751b06c64fee4 8571 glibc_2.43-6.dsc
0ceee5f8209ebf5c45299785d728b184a527dcde 490948 glibc_2.43-6.debian.tar.xz
56c30aa17cf9bb3950c082ae325b3e22ef788510 9473 glibc_2.43-6_source.buildinfo
Checksums-Sha256:
b096f4bcc7af857d147b2e2c76a734a0b32c56ae835eeabbf380332d803eec64 8571 glibc_2.43-6.dsc
7cae5fd8fbc8a83809f75fc5e9432bd789191fd8173721c3863df486a9c7d237 490948 glibc_2.43-6.debian.tar.xz
29382b11250fdaa963f9a7b6284dad9042e8c22f97d2f4ee7b943261c5e9157b 9473 glibc_2.43-6_source.buildinfo
Files:
0ad95afb14708311db536ec716a12da8 8571 libs required glibc_2.43-6.dsc
2bd73190df90521d78edf193626988eb 490948 libs required glibc_2.43-6.debian.tar.xz
055cf3a61f57675afea59b27cb263558 9473 libs required glibc_2.43-6_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUryGlb40+QrX1Ay4E4jA+JnoM2sFAmquV2QACgkQE4jA+Jno
M2sf5hAAoXlk48+oS8iyOyeD32JQgW1cZDGSoEg+s2EKiTYzjw/dJXIUSMUiVAxV
kdCXBIZM+5DilUIv7MBgPXXjdkpP/RBofvTE8xNbLg14wjX/phIGNLeZHIAlj4/C
uVdJNnTJIDuHlYAyDt2M7bcPRkrs4gpxZgJr9QW2k19qj5llmHos90bVXMn8GRSE
vgoW0iormYN5KxtMhuGXtZG7w38RFYrWcAkA03ae0bqTzmlGrhAnbi+CwrJ6mOwy
L1PwuMJELsXAidyCfu74a2euLdpdq7kTYFb3pb8txcNFOrZJhl9dv0Hkxjuu8eHQ
anONjiLNQDg1PghMT4aAbdWMsH1eKmIDwAHs3JrKuqDd8GI9IL4Gxh1IB/i1GIle
eYxAdJhPEwUAnNTpf6Mz0EDyhkM06+vyzifVar0smKsQMt4RMHiqmvRZ9UfwtLGa
/wmn6Ya9eh3Jnh5MDaTQRb5TPhT7i3O3b+rXLKRtFyyVQo8tt+KFn7nXrPwjKiN/
Cvdah1erpnt9lFFpPjmhuXIOBGH/FeaZjz4SJk62C9lBLSVfC0vNyMPRFRs12CIF
LP1Etq7YAEDRp/3OYfxECBHzq5XAeCYCrN0oS0/l7sizJeaD/vv13qoucL0o1aBX
eO2E3OkXbTNl+3P4Jfy26P1jvNIIB+9m1ScFu6/VVqMtjGMcCoY=
=VFER
-----END PGP SIGNATURE-----