Opened 10 months ago

Closed 10 months ago

Last modified 8 months ago

#22500 closed enhancement (fixed)

glib-2.86.3

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (5)

comment:1 by Douglas R. Reno, 10 months ago

Overview of changes in GLib 2.86.3, 2025-12-08
==============================================

* Fix several security vulnerabilities of varying severity (see below for
  details)

* Bugs fixed:
  - #3827 (CVE-2025-13601) (#YWH-PGM9867-134) Incorrect calculation of buffer
    size in g_escape_uri_string() (Philip Withnall)
  - #3834 (#YWH-PGM9867-145) Buffer underflow on Glib through glib/gvariant via
    bytestring_parse() or string_parse() leads to OOB Write (Philip Withnall)
  - #3845 GIO: Integer overflow in file attribute escaping (Philip Withnall)
  - !4912 Backport !4901 “Issue #3819: G_FILE_MONITOR_WATCH_HARD_LINK does not
    monitor files on Windows.” to glib-2-86
  - !4915 Backport !4914 “gconvert: Error out if g_escape_uri_string() would
    overflow” to glib-2-86
  - !4934 Backport !4933 “gvariant-parser: Fix potential integer overflow
    parsing (byte)strings” to glib-2-86
  - !4936 Backport !4935 “gfileattribute: Fix integer overflow calculating
    escaping for byte strings” to glib-2-86

comment:2 by Douglas R. Reno, 10 months ago

Priority: normal → high

comment:3 by Douglas R. Reno, 10 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:4 by Douglas R. Reno, 10 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at 3332f43bfd0f26a5ddb0770029c46b5326638451

SA-12.4-056 issued

comment:5 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.