Opened 3 weeks ago

Closed 10 days ago

#5930 closed enhancement (fixed)

fix CVE-2026-4046, CVE-2026-5450, and CVE-2026-5928 in glibc

Reported by: Xi Ruoyao Owned by: SecurityAdvisory
Priority: high Milestone: 13.1
Component: Book Version: git
Severity: normal Keywords:
Cc:

Description

I'm really not a fan of "AI assisted" security vulnerability mining but ... it already happens.

I've uploaded a consolidated patch containing the fixes for them, the fixes for two prior vulnerabilities (currently as a sed command in book), and two fixes for Linux 7.0 so we can use it in mid-May update.

There are also CVE-2026-5435 and CVE-2026-6238 but they are not committed upstream yet and they only affect some interfaces deprecated for years, so I didn't include them here. If the fixes get committed before mid-May update we can append them into the patch.

Change History (7)

comment:2 by Bruce Dubbs, 3 weeks ago

I need clarification.

In chapter 5 we use glibc-fhs-1.patch. Is that still needed? I think yes, but I'm not sure. Is the glibc-2.43-consolidated-1.patch needed in chapter 5? I think no, but again I'm not sure. It probably wouldn't hurt though.

In Chapter 8, we now have a sed and the fhs patch. Are they still needed in addition to the glibc-2.43-consolidated-1.patch? My understanding is that the sed is incorporated into the consolidated patch and the fhs patch is not. Correct?

comment:3 by Douglas R. Reno, 3 weeks ago

The consolidated patch will be needed in Chapter 5, otherwise we can't build glibc against the Linux 7 API headers

comment:4 by Xi Ruoyao, 3 weeks ago

Yes, the sed is in the patch but the FHS patch is not.

(I didn't consolidate the FHS patch because it seems we are supposed to keep the FHS patch for a lot of future glibc versions).

Last edited 3 weeks ago by Xi Ruoyao (previous) (diff)

comment:5 by Bruce Dubbs, 3 weeks ago

Owner: changed from lfs-book to SecurityAdvisory

Fixed at commit 6d990d4871. Leaving open for security advisory.

comment:7 by Douglas R. Reno, 10 days ago

Resolution: fixed
Status: newclosed

SA-13.0-067 issued

Note: See TracTickets for help on using tickets.