-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 30 Apr 2024 23:07:28 +0200 Source: glibc Binary: libc-bin libc-bin-dbgsym libc-dev-bin libc-dev-bin-dbgsym libc-devtools libc-devtools-dbgsym libc6 libc6-dbg libc6-dev libc6-dev-dbgsym libc6-udeb locales-all nscd nscd-dbgsym Architecture: arm64 Version: 2.36-9+deb12u7 Distribution: bookworm-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-03) Changed-By: Aurelien Jarno Description: libc-bin - GNU C Library: Binaries libc-dev-bin - GNU C Library: Development binaries libc-devtools - GNU C Library: Development tools libc6 - GNU C Library: Shared libraries libc6-dbg - GNU C Library: detached debugging symbols libc6-dev - GNU C Library: Development Libraries and Header Files libc6-udeb - GNU C Library: Shared libraries - udeb (udeb) locales-all - GNU C Library: Precompiled locale data nscd - GNU C Library: Name Service Cache Daemon Changes: glibc (2.36-9+deb12u7) bookworm-security; urgency=medium . * debian/patches/local-CVE-2024-33599-nscd.diff: Fix a stack-based buffer overflow in nscd netgroup cache (CVE-2024-33599). * debian/patches/local-CVE-2024-33600-nscd.diff: Fix a null pointer dereferences in nscd after failed netgroup cache insertion (CVE-2024-33600). * debian/patches/any/local-CVE-2024-33601-33602-nscd.diff: Fix a DoS in nscd in case of memory allocation failure (CVE-2024-33601) and a memory corruption in nscd when the underlying NSS callback function does not use the buffer space to store all strings (CVE-2024-33602). Checksums-Sha1: 058aebac67351a13f01e4363cfa77ec335d9f527 12734 glibc_2.36-9+deb12u7_arm64-buildd.buildinfo ef0aed775ae79d71251356052d88208d4afd97f6 2242396 libc-bin-dbgsym_2.36-9+deb12u7_arm64.deb 99966005daf3f0d7a8d1f393d8e6395be7720ebd 530952 libc-bin_2.36-9+deb12u7_arm64.deb fd3c0a68f8b02d2e8e0c779fb50c4d37c9f53117 29536 libc-dev-bin-dbgsym_2.36-9+deb12u7_arm64.deb f1530ffc0f77dc68f2f38eae8da257036a0f3f2c 44924 libc-dev-bin_2.36-9+deb12u7_arm64.deb b7c9798ca5807053028440f086e98220ff990e0d 42700 libc-devtools-dbgsym_2.36-9+deb12u7_arm64.deb 64510237a597fb38b38519516643de043080b47a 52124 libc-devtools_2.36-9+deb12u7_arm64.deb 46a7c998875819cdeaaf014d9cec8a15a65edfb4 6541812 libc6-dbg_2.36-9+deb12u7_arm64.deb b50ac50aeda88d14d714966ebdf63ac9e3213ad5 15000 libc6-dev-dbgsym_2.36-9+deb12u7_arm64.deb 43deaef775499ae57959482a030e7d4279792d08 1429956 libc6-dev_2.36-9+deb12u7_arm64.deb a6c85e81820444207d1329668cfebc220d8b9cfd 897328 libc6-udeb_2.36-9+deb12u7_arm64.udeb e881d41ed19d7e931da649222434017349cf5cf6 2318568 libc6_2.36-9+deb12u7_arm64.deb e178c5b147abb0c1d0af146c24de55d0f4f87026 10699484 locales-all_2.36-9+deb12u7_arm64.deb 52f108dbd681674fb8a387a8abd36c2983cbc192 268076 nscd-dbgsym_2.36-9+deb12u7_arm64.deb 9b1160936dbd1441c4ba008cc96b3c54d05e9b3c 95888 nscd_2.36-9+deb12u7_arm64.deb Checksums-Sha256: c59d1188f2518dd53e10dac98b25a976439cb3a37516e850a1c00f4824dedafe 12734 glibc_2.36-9+deb12u7_arm64-buildd.buildinfo bf1eba5c027a7252d195fac64319bdc7d81b5442fe8d6ca719a121ebd6923141 2242396 libc-bin-dbgsym_2.36-9+deb12u7_arm64.deb 576e40fa477d01d2b35742594641d8e18a43cbb24752085146b286fe739f5a48 530952 libc-bin_2.36-9+deb12u7_arm64.deb 6b87ffa395971d11eab2f1bc6cc5a99161ccc84761ac7fd3de17cd8383be1b4e 29536 libc-dev-bin-dbgsym_2.36-9+deb12u7_arm64.deb 4fc3636abaf7abf067fb0402c0d8fd34c60ae9761ac34bdee8bc932d49f4849b 44924 libc-dev-bin_2.36-9+deb12u7_arm64.deb 12a2b6bd5d992b910b067e0f60a6e90f73391fce6718e07b89ced473cc28c056 42700 libc-devtools-dbgsym_2.36-9+deb12u7_arm64.deb fa7df1269ff32cbf2c627bdf61f50548f5a9f8f88d6f2be9d40df8896491a0d8 52124 libc-devtools_2.36-9+deb12u7_arm64.deb 75938cbf4cade93139aa87c902e47678e945f6733368799fc5d1f7ad62ea4b80 6541812 libc6-dbg_2.36-9+deb12u7_arm64.deb 7b681ee57e4693849c18e121ae320f28360251ce3ae712d3fb2f20d3d383607c 15000 libc6-dev-dbgsym_2.36-9+deb12u7_arm64.deb 20285d9082f7c0587f72cc79a98f75b60782d7edaa1550e8cfe5a337883fd78e 1429956 libc6-dev_2.36-9+deb12u7_arm64.deb aa6746ec1d925f500b7b33f0d4c6cbc46ba4b8dc1296d6df231ec72541ff2d04 897328 libc6-udeb_2.36-9+deb12u7_arm64.udeb 84f9a8f8fa182c17e998c6094293ff0f4d504bfdb9b856802cf28b5d272ed303 2318568 libc6_2.36-9+deb12u7_arm64.deb 1818b0a9d2943a7f6ae8e0bec5e650329e60ea23137c679bff9a0b05df1de9ec 10699484 locales-all_2.36-9+deb12u7_arm64.deb 0e84d60029675490340fbe0cca75e5b3043bf86e121e92f959c09a0a39a89dfc 268076 nscd-dbgsym_2.36-9+deb12u7_arm64.deb aab7108661e99d0aed8a477901d96195efc557d6669f74f75e633e6f80fd4564 95888 nscd_2.36-9+deb12u7_arm64.deb Files: 6d2099cda63f43199f732d6b22158fe7 12734 libs required glibc_2.36-9+deb12u7_arm64-buildd.buildinfo 364749b8b587005db69a58e7ce5417ba 2242396 debug optional libc-bin-dbgsym_2.36-9+deb12u7_arm64.deb ffea7702402876cb256b1810bfbc22a5 530952 libs required libc-bin_2.36-9+deb12u7_arm64.deb acd1d5a035a2d590a5db904a08fef14c 29536 debug optional libc-dev-bin-dbgsym_2.36-9+deb12u7_arm64.deb 20ee2ec36bac171591d12c6bfcfd934e 44924 libdevel optional libc-dev-bin_2.36-9+deb12u7_arm64.deb 26d8d9a5bfbb21e072b43a93337375d9 42700 debug optional libc-devtools-dbgsym_2.36-9+deb12u7_arm64.deb 01fd8a33ef40962c9061901d903def0a 52124 devel optional libc-devtools_2.36-9+deb12u7_arm64.deb edcd9f3ec7afee85ea979b8de296498f 6541812 debug optional libc6-dbg_2.36-9+deb12u7_arm64.deb 031ab62091d63f220898b9a2291f3838 15000 debug optional libc6-dev-dbgsym_2.36-9+deb12u7_arm64.deb b6deb2083a57a11d4c1171f9178ca2e3 1429956 libdevel optional libc6-dev_2.36-9+deb12u7_arm64.deb 99e136a31f5ba4d6426318ac55aa9b4b 897328 debian-installer optional libc6-udeb_2.36-9+deb12u7_arm64.udeb 5219d369c707e361309c8b0dc056e012 2318568 libs optional libc6_2.36-9+deb12u7_arm64.deb 6a8561855ef12c22d5e8abcb63de70e3 10699484 localization optional locales-all_2.36-9+deb12u7_arm64.deb 523d8b855d036c73dcee454fc9a0be4d 268076 debug optional nscd-dbgsym_2.36-9+deb12u7_arm64.deb 15e6544b6951c3828bbf0791be73ff77 95888 admin optional nscd_2.36-9+deb12u7_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEU81tY/BC8e+eAeWhLffeOnPnbLUFAmYxaikACgkQLffeOnPn bLUYLRAAlZSE0m7LzUW6EvFddnm5qg3nGKOS7zn3EYwGW31U15r0e9MWKTuXJ4v1 3ggziyMFturcUfR96YXkcg0Cp+tSR59UChZSY9vYOetYwzcQzCJH/cfjp9HBtQbB uWk0BQXcNkBaLzSrizNkp5wFw7eZMS4s//t4CoefJaxGkfzO00BaFsfvyJZHEN3G LL9osn/fg5fJ4gX4BiNDAn598kZyugz3Bm1esbT3O8RFciMZb+LDazdlj4EFPB3n oJikjR6HU+YJzgi4x0qLj9HxUVUWrFGN9iZHNLA8qkIE0uSQT3jr9WHVAuXSzDYn 1MMwsxR+Jzwgb8xjPM3R8LsDIP+SmhvyEZ6gASepQOPdDj8oEAntjpJtZ7WZubw8 +MBmzIpwxI5p2NHun7x7tFmsQfC1dDXFpV1dazK6Qy2HJ7loSttrSwTukX/tjl1F msfUlaAihGVANLJtoMJHX5fSLkn+MOyPDrASrc1mmhl6pITXIxGOvki4ko7c76X2 KfwT1uVW+469Q0Yc2D+RZng1+oHVcIegxdrl+62+swnY/WKfMmn6Yw7KWAPIyKYl TlPIuEQeWT/Sqd+UejS+MlhZoHIJoWLVZE/UToodPpofjFo0ZaPQUxYMoRaEBo2O xzu92wzpv1BgOijN6SrXg4GJU1O4cEDbSDCjCXxuYgutfRG0H7U= =Ffzk -----END PGP SIGNATURE-----