Opened 4 weeks ago

Closed 3 weeks ago

#23926 closed enhancement (fixed)

glib-networking-2.90.0

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: elevated Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New minor version.

Change History (3)

comment:1 by Joe Locash, 3 weeks ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 3 weeks ago

Milestone: 13.2 → 98-Security
Owner: changed from Joe Locash to SecurityAdvisory
Priority: normal → elevated
Severity: normal → medium
Status: assigned → new
2.90.0 - September 10, 2026
===========================

* Bugs fixed:
  - !286 meson: Remove version checks that are always true (correctmost)

* Translation updates:
  - Bulgarian (Alexander Alexandrov Shopov)
  - Catalan (Xavi Ivars)
  - Chinese (China) (luming zh)
  - Czech (Daniel Rusek)
  - Danish (Ask Hjorth Larsen)
  - Dutch (Nathan Follens)
  - French (Guillaume Bernard)
  - Galician (Francisco Diéguez Souto)
  - Georgian (Ekaterine Papava)
  - Hebrew (Yaron Shahrabani)
  - Hungarian (Balázs Úr)
  - Kazakh (Baurzhan Muftakhidinov)
  - Korean (Changwoo Ryu)
  - Lithuanian (Aurimas Černius)
  - Occitan (post 1500) (Quentin PAGÈS)
  - Persian (Danial Behzadi)
  - Portuguese (Brazil) (burns)
  - Russian (Artur S0)
  - Serbian (Марко Костић)
  - Spanish (Daniel Mustieles)
  - Swedish (Anders Jonsson)
  - Thai (Aefgh Threenine)
  - Turkish (Emin Tufan Çetin)
  - Uighur (Abduqadir Abliz)
  - Ukrainian (Yuri Chornoivan)

2.90.alpha - June 25, 2026
==========================

* Bugs fixed:
  - #222 test fails with openssl 3.4.x (Michael Catanzaro)
  - #226 (CVE-2025-60018) (#YWH-PGM9867-106) Out of Bond Reads on glib-
    networking through tls/openssl/gtlscertificate-openssl.c via
    "g_tls_certificate_openssl_get_property()" due to Incorrect BIO_write Return
    Value Validation in Certificate PEM Export (Michael Catanzaro)
  - #228 (CVE-2026-2574) (#YWH-PGM9867-150) OOB Read on glib-networking through
    tls/openssl/gtlsclientconnection-openssl.c via
    g_tls_client_connection_openssl_get_property() (Michael Catanzaro)
  - #231 (CVE-2026-10028) (#YWH-PGM9867-278) Infinite loop in certification path
    building (Michael Catanzaro)
  - !261 meson: Introduce option for enable/disable tests (Leonid Zaburunov)
  - !263 openssl: check return value of g_tls_bio_alloc() and BIO_new() (Michael
    Catanzaro)
  - !265 openssl: delete support for OCSP stapling (Michael Catanzaro)
  - !268 Fix file database and PKCS11 test failures and update CI! (Michael
    Catanzaro)
  - !270 Fix miscellaneous safety issues reported by bug hunters (Michael
    Catanzaro)
  - !271 Delete gtlshttp (Michael Catanzaro)
  - !272 Fix connection test reusing a GError (Michael Catanzaro)
  - !273 openssl: fix error code confusion (Michael Catanzaro)
  - !274 ci: add catch for reporting stack traces (Michael Catanzaro)
  - !277 Require OpenSSL 1.1.1 or newer (Michael Catanzaro)
  - !280 Some fixes found with kiro (Ignacio Casal Quinteiro)
  - !281 Fix various memory leaks (Michael Catanzaro)
  - !283 openssl: refactor error handling code (Michael Catanzaro)
  - !284 openssl: use ERR_clear_error() all over the place (Michael Catanzaro)
  - !285 gnutls: always notify accepted-cas property after handshake (Michael
    Catanzaro)

* Translation updates:
  - Arabic (Ahmed Najmawi)
  - Basque (Asier Saratsua Garmendia)
  - Belarusian (Vasil Pupkin)
  - Cornish (Flynn Peck)
  - Esperanto (Kristjan SCHMIDT)
  - Greek, Modern (1453-) (Efstathios Iosifidis)
  - Japanese (Takayuki Kusano)
  - Lao (Saikeo Kavhanxay)
  - Romanian (Antonio Marin)
  - Slovak (Jose Riha)
  - Slovenian (Martin)
  - Thai (Aefgh Threenine)
  - Uighur (Abduqadir Abliz)
  - Uzbek (Baxrom Raxmatov)

Fixed at 00d245048c. Leaving open for SA.

comment:3 by Bruce Dubbs, 3 weeks ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.1-025 has been issued.

Note: See TracTickets for help on using tickets.