-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 30 Apr 2024 23:57:11 +0200 Source: glibc Binary: libc-bin libc-bin-dbgsym libc-dev-bin libc-dev-bin-dbgsym libc-devtools libc-devtools-dbgsym libc6 libc6-dbg libc6-dev libc6-udeb locales-all nscd nscd-dbgsym Architecture: armhf Version: 2.31-13+deb11u10 Distribution: bullseye-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Aurelien Jarno Description: libc-bin - GNU C Library: Binaries libc-dev-bin - GNU C Library: Development binaries libc-devtools - GNU C Library: Development tools libc6 - GNU C Library: Shared libraries libc6-dbg - GNU C Library: detached debugging symbols libc6-dev - GNU C Library: Development Libraries and Header Files libc6-udeb - GNU C Library: Shared libraries - udeb (udeb) locales-all - GNU C Library: Precompiled locale data nscd - GNU C Library: Name Service Cache Daemon Changes: glibc (2.31-13+deb11u10) bullseye-security; urgency=medium . * debian/patches/local-CVE-2024-33599-nscd.patch: Fix a stack-based buffer overflow in nscd netgroup cache (CVE-2024-33599). * debian/patches/local-CVE-2024-33600-nscd.patch: Fix a null pointer dereferences in nscd after failed netgroup cache insertion (CVE-2024-33600). * debian/patches/any/local-CVE-2024-33601-33602-nscd.patch: Fix a DoS in nscd in case of memory allocation failure (CVE-2024-33601) and a memory corruption in nscd when the underlying NSS callback function does not use the buffer space to store all strings (CVE-2024-33602). Checksums-Sha1: 0e0c44284210dd55e2813143552ebcb6a6953146 11986 glibc_2.31-13+deb11u10_armhf-buildd.buildinfo cb467760657fb22e0966e1a0df045e095db75ba0 1785080 libc-bin-dbgsym_2.31-13+deb11u10_armhf.deb 26499189d328d75c770020b41a75eed5f174f757 719320 libc-bin_2.31-13+deb11u10_armhf.deb d92fad06f7549c99c7346d5b2afc9d64f07e52e6 109140 libc-dev-bin-dbgsym_2.31-13+deb11u10_armhf.deb 0b7002c1cf05ff43a5ae96edbd4d05232d7c6d08 271628 libc-dev-bin_2.31-13+deb11u10_armhf.deb 14eb306d2da34a6a898f1273a0885e3871fb1d45 42780 libc-devtools-dbgsym_2.31-13+deb11u10_armhf.deb b9b57419219856f0cb4ff961445ff0c235b09f67 247308 libc-devtools_2.31-13+deb11u10_armhf.deb 8bc0f0184d7452584d49ec0eba1ae25e88488bdc 6522472 libc6-dbg_2.31-13+deb11u10_armhf.deb 9ec0983e8b095a44d55cab7ab208452d8ccf3b1f 1875812 libc6-dev_2.31-13+deb11u10_armhf.deb 94a4e70119e90a7e2fdf27559e7e29e58615c668 796968 libc6-udeb_2.31-13+deb11u10_armhf.udeb 84952376014119df16c0cca64d5f96a77bbea667 2333632 libc6_2.31-13+deb11u10_armhf.deb 6b4b91a82b629e756562f3833b0cadf2635e0453 10753616 locales-all_2.31-13+deb11u10_armhf.deb fcea6ac4e3d85636e5fa4da19481161ce98bf045 231624 nscd-dbgsym_2.31-13+deb11u10_armhf.deb b71df6e8c583812784bb2415828854ba383ef4d5 284716 nscd_2.31-13+deb11u10_armhf.deb Checksums-Sha256: a389d116cbf0833781201516d37916e54866cda1ad33526e332929a788a54213 11986 glibc_2.31-13+deb11u10_armhf-buildd.buildinfo b2fe57d26e9db5cb41b2ae2f8e97fe9e39bb5d31ed71685de397a45e100777c5 1785080 libc-bin-dbgsym_2.31-13+deb11u10_armhf.deb 9db12511163541ee09ec7a574b81242e1fc1902c1608bc2fcb68aa7a0590f6ae 719320 libc-bin_2.31-13+deb11u10_armhf.deb 28fcbd396bdb095ad838a9a56590c5cf44ab8e4d3ca7291f2fbb285cbbc1a9aa 109140 libc-dev-bin-dbgsym_2.31-13+deb11u10_armhf.deb 79c0531ce12d4d3d20198811a90229e70406deb72657aafdd66908cffdad637c 271628 libc-dev-bin_2.31-13+deb11u10_armhf.deb d1ce69b9c2954a83f9ca7fd25742cc791984021f8f952d57c22a6b846c961a98 42780 libc-devtools-dbgsym_2.31-13+deb11u10_armhf.deb d802d909ce7ed6a469d08126ad813e36fade9a80ddf4e16231cfcc2a35116305 247308 libc-devtools_2.31-13+deb11u10_armhf.deb c6856b8d035633d9f9626b5f1fc7db606d32812ba205e1ebaa3bbc7f71b642a1 6522472 libc6-dbg_2.31-13+deb11u10_armhf.deb 86c9915ed0bdd94076d08e1cd0397b2b9d3bcc17590c6b28d8c12fd28e11c72a 1875812 libc6-dev_2.31-13+deb11u10_armhf.deb 0551819ef65004f353513641a20e28e72728a0ad657bd27f06ba76709f041356 796968 libc6-udeb_2.31-13+deb11u10_armhf.udeb dc83cff8caa906fde83d8d654047f828296cc8a1642595635c7b097a06d20cf9 2333632 libc6_2.31-13+deb11u10_armhf.deb c54ee66a597e93be42319414ba853b42dfba9bfefbc4351f49313820e095e910 10753616 locales-all_2.31-13+deb11u10_armhf.deb 696d97273c21d7ede6a0972e8b2353e414fc51918b19e9f81601ac498a6cc4a7 231624 nscd-dbgsym_2.31-13+deb11u10_armhf.deb 9a41ae0d29ab3e58c6bbb5b944a2fc79bf992c2d2f2d26ec6ae373a903c2822d 284716 nscd_2.31-13+deb11u10_armhf.deb Files: 72cac3fd07fb42170bd45800efe918ac 11986 libs required glibc_2.31-13+deb11u10_armhf-buildd.buildinfo 311fd21e46a8746b19d2369f99941789 1785080 debug optional libc-bin-dbgsym_2.31-13+deb11u10_armhf.deb 787b8ea0a7c74f6370ca2307e746319c 719320 libs required libc-bin_2.31-13+deb11u10_armhf.deb a4c878c1377f21fffe3e2a128e869c7d 109140 debug optional libc-dev-bin-dbgsym_2.31-13+deb11u10_armhf.deb b196c9ffb437a96fe67a1b998c61e333 271628 libdevel optional libc-dev-bin_2.31-13+deb11u10_armhf.deb 6853953ad66837bd63acf00066077e7f 42780 debug optional libc-devtools-dbgsym_2.31-13+deb11u10_armhf.deb 0bda4ce2542d0429c4249d970cd40622 247308 devel optional libc-devtools_2.31-13+deb11u10_armhf.deb 5e9510f1cd9d7ddea28ef5892399e647 6522472 debug optional libc6-dbg_2.31-13+deb11u10_armhf.deb 453d2f85cdfca0141e8fb2f9d6e15a08 1875812 libdevel optional libc6-dev_2.31-13+deb11u10_armhf.deb a9ddcc0156ef03ec92e994ffaf9a5167 796968 debian-installer optional libc6-udeb_2.31-13+deb11u10_armhf.udeb a401c27c00a0d11ea832cc2f7e0b6be5 2333632 libs optional libc6_2.31-13+deb11u10_armhf.deb f49ab857e07fe8d307ea599e3ae34073 10753616 localization optional locales-all_2.31-13+deb11u10_armhf.deb 761fab7edf553dee8a1bea7e54fbe013 231624 debug optional nscd-dbgsym_2.31-13+deb11u10_armhf.deb 4526492b6caca99a8a5ed53b8c3c5770 284716 admin optional nscd_2.31-13+deb11u10_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEw2TRpv7HYIvK+TsIbEMdCP/rlD8FAmYxdQMACgkQbEMdCP/r lD8eOQ//dagvagQx/sUI31TxyM5Ek7oW8S1ZaEMaNgy4Cp+ev5ZRR1A1zn8BGlIH g++oMi568PPmr+5oF7E6+u62GK11tz27wD33wGxJ3EqUgXFHLYzgHaitNPsTsssK jOsN4aouxYTbJg3mm/yCB+SjF5z0qnkc658oHP914TPtQTgnWoh64/QIyTjGEnv5 B1KF7Nk9L17AnJHY+Kw9CJszFRuWjO04LmXVr0QcJb3glZyM+exRm1CILTU8wwXO ncvuGepIRAnDgpf/o0R66xcCyFEYU8lCxLdZR2Au1oxftE3x8afPft29k2rwjL52 u3VMRUjInP7k1w2UXZ9RG2CK6r+wP05wQ7jkdEFtBRZpnkf/wMUF4inj5dfju5hW lNFNw2mXw63V73Z7GiWaGbcXsOM8ICcFFnveEoAtABOtj/vvCo2zfbfDNh0VkQcl /kFbIlp1Cp9PHYbZtYy/r9zTvZW1TJSJt1aOcvSnS7usecVt1lfA0fHl85oWi8Vm DtjnE3xMCGtI1dkxs0wGAw0PK8Ef+K0q/OO+eyf0rttS42no0rlNMFiK8BlorNXm nOX3wMWTZ8apRYHbSrfuHw1QX6P4lmphL1dyH/OqhluQEtuPsYNxCSTFWBX5OwfM cspKMvEdCJjang53gBjfhTIcczaKLiZmnxRl1HwJfOWo+8ZNWRc= =wHmZ -----END PGP SIGNATURE-----