-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 30 Apr 2024 23:57:11 +0200 Source: glibc Binary: libc-bin libc-bin-dbgsym libc-dev-bin libc-dev-bin-dbgsym libc-devtools libc-devtools-dbgsym libc6 libc6-dbg libc6-dev libc6-udeb locales-all nscd nscd-dbgsym Architecture: armel Version: 2.31-13+deb11u10 Distribution: bullseye-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-03) Changed-By: Aurelien Jarno Description: libc-bin - GNU C Library: Binaries libc-dev-bin - GNU C Library: Development binaries libc-devtools - GNU C Library: Development tools libc6 - GNU C Library: Shared libraries libc6-dbg - GNU C Library: detached debugging symbols libc6-dev - GNU C Library: Development Libraries and Header Files libc6-udeb - GNU C Library: Shared libraries - udeb (udeb) locales-all - GNU C Library: Precompiled locale data nscd - GNU C Library: Name Service Cache Daemon Changes: glibc (2.31-13+deb11u10) bullseye-security; urgency=medium . * debian/patches/local-CVE-2024-33599-nscd.patch: Fix a stack-based buffer overflow in nscd netgroup cache (CVE-2024-33599). * debian/patches/local-CVE-2024-33600-nscd.patch: Fix a null pointer dereferences in nscd after failed netgroup cache insertion (CVE-2024-33600). * debian/patches/any/local-CVE-2024-33601-33602-nscd.patch: Fix a DoS in nscd in case of memory allocation failure (CVE-2024-33601) and a memory corruption in nscd when the underlying NSS callback function does not use the buffer space to store all strings (CVE-2024-33602). Checksums-Sha1: aff594572430d97ffcd8bc51d92ee9990f894eb1 11984 glibc_2.31-13+deb11u10_armel-buildd.buildinfo 6a364f1eec81a6d002781d2d1ced8227871dcd83 1790256 libc-bin-dbgsym_2.31-13+deb11u10_armel.deb 9d07e46ab7dd96329e313f5c3c82a94b4b18a6d1 708264 libc-bin_2.31-13+deb11u10_armel.deb d9a7237a870ab94eab310b991c6884c789181b38 107896 libc-dev-bin-dbgsym_2.31-13+deb11u10_armel.deb 9fd8344e974dc3147bdca8bdcfba0d5fdf26cf55 270948 libc-dev-bin_2.31-13+deb11u10_armel.deb 3d4b99b73ca5df01a1c50b9c9583852574fea15f 42204 libc-devtools-dbgsym_2.31-13+deb11u10_armel.deb fc78ebc10be1b0aee9cdda10de02c70bf50542f3 247884 libc-devtools_2.31-13+deb11u10_armel.deb 87770f579f20bb7969bc9e8558d04359a160dc25 6645396 libc6-dbg_2.31-13+deb11u10_armel.deb 4f1af6773cbf6a2c1fb0e6cc9495bf8dcd15c067 1931928 libc6-dev_2.31-13+deb11u10_armel.deb 5ba9ed6ee900ba5c372f657fea70734f399814ac 822228 libc6-udeb_2.31-13+deb11u10_armel.udeb a71363f2c917b2c0e39b0375b55264f4c4cbbf0b 2340748 libc6_2.31-13+deb11u10_armel.deb e93b3d7d381c88d42e7d4dfd07743fbc1567f8d0 10753604 locales-all_2.31-13+deb11u10_armel.deb 673d2cab56748a2541ff691a456c979345722dea 228064 nscd-dbgsym_2.31-13+deb11u10_armel.deb 3019a8c94c8c4d5a61cbc4de87ace2bd51943cb1 283148 nscd_2.31-13+deb11u10_armel.deb Checksums-Sha256: ab6a59bab6657e4636e0999298199a98f4fbc9bfcdd3c82a89494d8e07f1d0bb 11984 glibc_2.31-13+deb11u10_armel-buildd.buildinfo 74e892ad999d1aeda0fd1440aaa25ee7597cd2a0d28677076324bb7428d6ee0a 1790256 libc-bin-dbgsym_2.31-13+deb11u10_armel.deb d4111534006d926ef129fb25fe683eb2315c0f15481959cc9bacc2de141cb002 708264 libc-bin_2.31-13+deb11u10_armel.deb d2a794c4b5fdfaa1a6e78af3ac11f69e2e0f2d6a584d5b61028d241b9bab8f81 107896 libc-dev-bin-dbgsym_2.31-13+deb11u10_armel.deb 0283163e66275add1090c73fe09dbadcb8ceb49485495659bb6fe45d157f1f57 270948 libc-dev-bin_2.31-13+deb11u10_armel.deb 2efdafcdc82d585c6256663ee3a11e6e28bfe425913ed8e288c9533d774b82f8 42204 libc-devtools-dbgsym_2.31-13+deb11u10_armel.deb e0825ef3bb42622b7164029a4a8980f1a7a27f2ba144e854b796e0d38f20e664 247884 libc-devtools_2.31-13+deb11u10_armel.deb 17b1a4ce892d89e1de414ee3f64bb4cab83d9cc9daa07753615d75b9a2bbb722 6645396 libc6-dbg_2.31-13+deb11u10_armel.deb e9ae4d8acea44b6e62c8dcaf98f2e5f4acee1392da2f16ab389d77c2989e809c 1931928 libc6-dev_2.31-13+deb11u10_armel.deb 6329af7629586e7ea8a0acb53af544ce56367a5990e43b2d4373bbbb4107222a 822228 libc6-udeb_2.31-13+deb11u10_armel.udeb 77c291eb8a324ea4d45f4461e9bbc37d2576ddc6e896ba7cf48783e6e21d3081 2340748 libc6_2.31-13+deb11u10_armel.deb cc65153b9f0c015e4c55dff8bf9ee235e6cf26d99c5f65ab4e5eabaf43cf35ed 10753604 locales-all_2.31-13+deb11u10_armel.deb 1e937e3fb1d3519e3e635ef5dd5ca6032340745a2d5678fb8f39b8bc647708fe 228064 nscd-dbgsym_2.31-13+deb11u10_armel.deb 3514ec5d99b9f66aa7851ea38817612864d324e6c2f184e8bc1c5c498be6ea6c 283148 nscd_2.31-13+deb11u10_armel.deb Files: b28c8f7405c6f4858d279d99d58b2b84 11984 libs required glibc_2.31-13+deb11u10_armel-buildd.buildinfo 9e10b6521f9551538ea70b121d9d9ae9 1790256 debug optional libc-bin-dbgsym_2.31-13+deb11u10_armel.deb ec1d046ac99608009390bc03108933cd 708264 libs required libc-bin_2.31-13+deb11u10_armel.deb 7daa2fde7a15e7784afecf50c8fccc39 107896 debug optional libc-dev-bin-dbgsym_2.31-13+deb11u10_armel.deb fda05b5e54e51b2f8c97f43973b035f8 270948 libdevel optional libc-dev-bin_2.31-13+deb11u10_armel.deb a4454860497fa4eb9149892b8db5133b 42204 debug optional libc-devtools-dbgsym_2.31-13+deb11u10_armel.deb 9f1ba1cb2e769c4b22ea01b42cc2119a 247884 devel optional libc-devtools_2.31-13+deb11u10_armel.deb af20bc0ffd035b0183af1e0a3e29993a 6645396 debug optional libc6-dbg_2.31-13+deb11u10_armel.deb 826d045effa132a6e18de300828d2855 1931928 libdevel optional libc6-dev_2.31-13+deb11u10_armel.deb 1215aab4d4c7877cf6479f2a511455d7 822228 debian-installer optional libc6-udeb_2.31-13+deb11u10_armel.udeb 998fa4ce8a8169d635db2e13020cf53b 2340748 libs optional libc6_2.31-13+deb11u10_armel.deb 757e0a928de550d784f5ae05aeeda594 10753604 localization optional locales-all_2.31-13+deb11u10_armel.deb dccc11e698be2309b78dcb63d9ab4229 228064 debug optional nscd-dbgsym_2.31-13+deb11u10_armel.deb 26232d23980edd57e1f2e96520019734 283148 admin optional nscd_2.31-13+deb11u10_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEU81tY/BC8e+eAeWhLffeOnPnbLUFAmYxeC8ACgkQLffeOnPn bLXiBxAAm3W6UVRwWcbBzygJ4sDQdN54gc9G4zNoju8HoPdEEeVpCGuLrQCCtJdh iX2QUbEad5vOV9NPbnPF4t+n2+6mKXnymuP9DOahHbh62NpZ1vngraUIaM7fQuBi t7wFL4mttgWF0OLP8qZ1A5Cem4LLbs/hkFaW6GzQSjL3Hecy7Xc4vCpSOKbdUwei HjXi8WVFq3tVTQZGyMmX2WN6z5emE8W/1pr4cKWt0kPMuGFET3lJUDlOXTUEKxq2 ITGEV1El2M5oQU1khJRkjJR0gmXr9kbEV5Ub7e+l6k5LeLE7AnIQr4JLx76m4c2n b2ZcAluA2eN04VXh1J70YyAEHKFJF3Ekdo7qYDAOAXnLQfomT+NowB7vrlKPdqqE rOJSQl+qOabXRA1Vx2wBMZ0IyzhiXNXCby3zROJ98s2o9DRaItw6M/iAG813S73+ QzAb83BQ75haV9/4fEtNzHmXrFMYIotz5HGXyTC755JVFinw581EAdqF6+KMwVrK y9ZO+X2aZaQwuYGhvHdLtRufiwSrpZyoXmTkZ/zCt2YBz0EfEzcZiO/B8gS5w0Z1 zPmHEElJqeSkICHLCnSdib4VItRb3guzAF3bhQ+wfWU6p0yU1rEukfExxQJiYHh0 OZyg3GQNhZOytNxP3O12XmA5hZPkGuur/wElGzCnABqe4gkM1rM= =yt9l -----END PGP SIGNATURE-----