[Buildroot] [PATCH] glibc: security bump to the latest commit on 2.26 branch
Peter Korsgaard
peter at korsgaard.com
Sun Feb 18 20:56:01 UTC 2018
>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:
> Fixes the following security issues according to NEWS:
> CVE-2018-6485: An integer overflow in the implementation of the
> posix_memalign in memalign functions in the GNU C Library (aka
> CVE-2018-6551: The malloc implementation in the GNU C Library (aka glibc or
> libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on
> i386, did not properly handle malloc calls with arguments close to SIZE_MAX
> and could return a pointer to a heap region that is smaller than requested,
> eventually leading to heap corruption.
> Signed-off-by: Peter Korsgaard <peter at korsgaard.com>
Committed, thanks.
--
Bye, Peter Korsgaard
More information about the buildroot
mailing list