-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 30 Apr 2024 23:07:28 +0200 Source: glibc Binary: libc-bin libc-bin-dbgsym libc-dev-bin libc-dev-bin-dbgsym libc-devtools libc-devtools-dbgsym libc6 libc6-dbg libc6-dev libc6-dev-dbgsym libc6-udeb locales-all nscd nscd-dbgsym Architecture: armhf Version: 2.36-9+deb12u7 Distribution: bookworm-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Aurelien Jarno Description: libc-bin - GNU C Library: Binaries libc-dev-bin - GNU C Library: Development binaries libc-devtools - GNU C Library: Development tools libc6 - GNU C Library: Shared libraries libc6-dbg - GNU C Library: detached debugging symbols libc6-dev - GNU C Library: Development Libraries and Header Files libc6-udeb - GNU C Library: Shared libraries - udeb (udeb) locales-all - GNU C Library: Precompiled locale data nscd - GNU C Library: Name Service Cache Daemon Changes: glibc (2.36-9+deb12u7) bookworm-security; urgency=medium . * debian/patches/local-CVE-2024-33599-nscd.diff: Fix a stack-based buffer overflow in nscd netgroup cache (CVE-2024-33599). * debian/patches/local-CVE-2024-33600-nscd.diff: Fix a null pointer dereferences in nscd after failed netgroup cache insertion (CVE-2024-33600). * debian/patches/any/local-CVE-2024-33601-33602-nscd.diff: Fix a DoS in nscd in case of memory allocation failure (CVE-2024-33601) and a memory corruption in nscd when the underlying NSS callback function does not use the buffer space to store all strings (CVE-2024-33602). Checksums-Sha1: 3b1304b155167e4bf7cf1c000e70eafb27cd9a5d 12586 glibc_2.36-9+deb12u7_armhf-buildd.buildinfo 0c9034d1a71936075c9cfb41b9b071a64e30037f 2270936 libc-bin-dbgsym_2.36-9+deb12u7_armhf.deb 9a05a1154e8e8ded5a8da0acfa670b3dc0eb8aea 503784 libc-bin_2.36-9+deb12u7_armhf.deb 730075372fbf20e277f8016f2b67c2bbd8137af3 29828 libc-dev-bin-dbgsym_2.36-9+deb12u7_armhf.deb f9a9b44ddd4b0e2b3f9fcfcebeb43fbb5185f431 44452 libc-dev-bin_2.36-9+deb12u7_armhf.deb 46d6be9526842df690efd2a6180b9d73ecb05838 43560 libc-devtools-dbgsym_2.36-9+deb12u7_armhf.deb dfc2dd6a7bd577dfb60b6ef8e8b9d2412556ac27 54432 libc-devtools_2.36-9+deb12u7_armhf.deb 11e3d1b984d59faed070db9beb1d438db95ec9f1 6755416 libc6-dbg_2.36-9+deb12u7_armhf.deb 3c7e2ba1772ba83d0e271efbc1ea13657074435b 14668 libc6-dev-dbgsym_2.36-9+deb12u7_armhf.deb a30692d16511139f0fe4608d69409582191ad44f 1266768 libc6-dev_2.36-9+deb12u7_armhf.deb 1e72bc8890c944aca5c78f5c8d03fd81c66060d8 768176 libc6-udeb_2.36-9+deb12u7_armhf.udeb d5f76fcff89fd8fca07b2f1dabc5b386faa07936 2142976 libc6_2.36-9+deb12u7_armhf.deb fec26e0d5c372a27a8896bba0f58c514d25cb3bc 10699528 locales-all_2.36-9+deb12u7_armhf.deb 59eec0373fa9caa33f834a201b96acbc449fcd09 269304 nscd-dbgsym_2.36-9+deb12u7_armhf.deb 07996dab8be55aa14688e251f4c14c6b3f8488f8 95772 nscd_2.36-9+deb12u7_armhf.deb Checksums-Sha256: ebc4e6c790572902f9792d0052df720d9f9cc9ac9d9f557062f41bd637e47e50 12586 glibc_2.36-9+deb12u7_armhf-buildd.buildinfo 1dfdde5df8bfb4368cbf47b9f329029699fdc4dc9161944afd1cbb47a82ba4a6 2270936 libc-bin-dbgsym_2.36-9+deb12u7_armhf.deb 5c23240e963128e14c5522894aab4ec64082a9c7bed9b4f0f796137ac7a0a73f 503784 libc-bin_2.36-9+deb12u7_armhf.deb b64e6d97d741d11a0f4e7d8603750d1bb4496ec867a7bb4393eec341dfb3c312 29828 libc-dev-bin-dbgsym_2.36-9+deb12u7_armhf.deb c42e3e393710c86df07b9fa6adeb11423a8537ad90a10fdaf208d6c796cc1522 44452 libc-dev-bin_2.36-9+deb12u7_armhf.deb 5288ee794954c0069d2422e3c0c6d338069607a07f4ca4a9d7271f75015ddcea 43560 libc-devtools-dbgsym_2.36-9+deb12u7_armhf.deb e44baeb80c765859a9f496bd5a40ff84f51b249c007ecd59773d4f4c7b73d58a 54432 libc-devtools_2.36-9+deb12u7_armhf.deb 31e7d9dfa1d8dfb93bb32d7e8f13df214b72d03a72031d272607b79f953b3406 6755416 libc6-dbg_2.36-9+deb12u7_armhf.deb cc896c7ea25a70503c60ae03865c9069b529276c954e39f68ad9fe4cab9392d7 14668 libc6-dev-dbgsym_2.36-9+deb12u7_armhf.deb 0c2878979fc898032035d81c3d8b29ac4572baa48a1023d29296cca6ceb55718 1266768 libc6-dev_2.36-9+deb12u7_armhf.deb 27b1b777c4ec795aa7d788cf636eef1dc6f3811011ab86ffb81d9cc9d27f814b 768176 libc6-udeb_2.36-9+deb12u7_armhf.udeb 2e837cab99a0dabcc1672b19829c15f8b16b61e52196d97513bb179bf41a6b03 2142976 libc6_2.36-9+deb12u7_armhf.deb 13668816de5fc0e109a0f8514898a00640d34ace3427aeb25ebfd88cd6dae188 10699528 locales-all_2.36-9+deb12u7_armhf.deb d175a784e826e15826c359349df2f7c3a7ea4b8a9c416f906228dea76fa61460 269304 nscd-dbgsym_2.36-9+deb12u7_armhf.deb 2d37b766f0e7841e13049cceb19bfbc901bd5a7b17a24e224915d951257f7558 95772 nscd_2.36-9+deb12u7_armhf.deb Files: 630f4cb4d7355bedf080e7611c192efc 12586 libs required glibc_2.36-9+deb12u7_armhf-buildd.buildinfo f0c9e208011ee2ad8dd29db167976927 2270936 debug optional libc-bin-dbgsym_2.36-9+deb12u7_armhf.deb 6e5dae2d5ff00fcb5c38125a8ee45aed 503784 libs required libc-bin_2.36-9+deb12u7_armhf.deb 94b6c70d6b58d4508083c44cb9b4c463 29828 debug optional libc-dev-bin-dbgsym_2.36-9+deb12u7_armhf.deb 1c17e6b559d1e4bbb2d105bc54bedc19 44452 libdevel optional libc-dev-bin_2.36-9+deb12u7_armhf.deb 6e220590d89f9f1561b47d0753b0d4b5 43560 debug optional libc-devtools-dbgsym_2.36-9+deb12u7_armhf.deb d61aabd0852eff031ed41cd11ab36092 54432 devel optional libc-devtools_2.36-9+deb12u7_armhf.deb 290405763eda0b1ac4b078a3d8a93b3a 6755416 debug optional libc6-dbg_2.36-9+deb12u7_armhf.deb 0f3cfbe627a738382e06c84878494d50 14668 debug optional libc6-dev-dbgsym_2.36-9+deb12u7_armhf.deb 8de0d9b0aeaa59810d7e694b2ff86084 1266768 libdevel optional libc6-dev_2.36-9+deb12u7_armhf.deb 18a3a44812ff97c1044b5077c85f78d3 768176 debian-installer optional libc6-udeb_2.36-9+deb12u7_armhf.udeb 50d7ac75ef16c7b5ef120d11704df34d 2142976 libs optional libc6_2.36-9+deb12u7_armhf.deb 97c41d25bb267fd3a280f88a8d2d5cb9 10699528 localization optional locales-all_2.36-9+deb12u7_armhf.deb 28b7efa63a34f3454cc8d58a5154c7f2 269304 debug optional nscd-dbgsym_2.36-9+deb12u7_armhf.deb 063c988d0fcd26c218dc3e6e0d51d1ba 95772 admin optional nscd_2.36-9+deb12u7_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEw2TRpv7HYIvK+TsIbEMdCP/rlD8FAmYxaxUACgkQbEMdCP/r lD8X7g//SC1ayTNo6/FXMCY22VInpUvkLo+uSxxTQdR/nh7g6trOss2MqQkH0QKw MHrbCUpmkH7JticityPPK0Do2JBZNUU/Hkbhwls4KblcLnvXecbOkLAnyiqhS1Zf x4Jv8EUBMe+n5ze2r7U7i+mbtXbnJdKmaCGwQmRyS5JxZ37fYMmFeIsbzsU1eQvJ ExTSVehAk/WldCNwPUBI3cfpXxqlO5kMuaBEHA5N86KqNPO5v/iAFVES8jQzBvYu Rpe5YPeYoNOW1tgmKM+SGuIBL97myAizwGhuXvIY1DxJc9JgSGeDJZ4kqeJwUJVy +OORGRe8LZImsqjjbGP/A7N+VB6/tvhRDoSkt05PEvuXa54UGG4KSX39+TxoUkVb 6nLYy8/U3Hmx9kRlC55hJkCK3t4r5I3A9rr8+nYdS7o4Wagons2acaj21RxDeFAo L+8k4zzJaARUarCsgYgNM0gcwHFhXgfalpnaVduex6TmcMWTQQzbwX/tBXmVPaWS BSz17u9lthaJHgR+YCBEGSHPth3nq8IozCkAFlKGmXnViyWXhvqE9CUEUg7HePoT zxdORpxfU3vnUr9qQBOvy3Az2ALv2aguL+qf02XYHazE13+9diLalKf0bML/qDGa WI0P6gTKNpZ+b2Hp3gaie+KA6Wz+HYsfcAiAezJvHU2OARfFBEM= =74ZJ -----END PGP SIGNATURE-----