[Buildroot] [PATCH] glibc: security bump to the latest commit on 2.26 branch

Peter Korsgaard peter at korsgaard.com
Sun Feb 18 20:56:01 UTC 2018


>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:

 > Fixes the following security issues according to NEWS:
 > CVE-2018-6485: An integer overflow in the implementation of the
 > posix_memalign in memalign functions in the GNU C Library (aka

 > CVE-2018-6551: The malloc implementation in the GNU C Library (aka glibc or
 > libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on
 > i386, did not properly handle malloc calls with arguments close to SIZE_MAX
 > and could return a pointer to a heap region that is smaller than requested,
 > eventually leading to heap corruption.

 > Signed-off-by: Peter Korsgaard <peter at korsgaard.com>

Committed, thanks.

-- 
Bye, Peter Korsgaard


More information about the buildroot mailing list