-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 30 Apr 2024 23:57:11 +0200 Source: glibc Binary: libc-bin libc-bin-dbgsym libc-dev-bin libc-dev-bin-dbgsym libc-devtools libc-devtools-dbgsym libc6 libc6-dbg libc6-dev libc6-udeb locales-all nscd nscd-dbgsym Architecture: ppc64el Version: 2.31-13+deb11u10 Distribution: bullseye-security Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-conova-01) Changed-By: Aurelien Jarno Description: libc-bin - GNU C Library: Binaries libc-dev-bin - GNU C Library: Development binaries libc-devtools - GNU C Library: Development tools libc6 - GNU C Library: Shared libraries libc6-dbg - GNU C Library: detached debugging symbols libc6-dev - GNU C Library: Development Libraries and Header Files libc6-udeb - GNU C Library: Shared libraries - udeb (udeb) locales-all - GNU C Library: Precompiled locale data nscd - GNU C Library: Name Service Cache Daemon Changes: glibc (2.31-13+deb11u10) bullseye-security; urgency=medium . * debian/patches/local-CVE-2024-33599-nscd.patch: Fix a stack-based buffer overflow in nscd netgroup cache (CVE-2024-33599). * debian/patches/local-CVE-2024-33600-nscd.patch: Fix a null pointer dereferences in nscd after failed netgroup cache insertion (CVE-2024-33600). * debian/patches/any/local-CVE-2024-33601-33602-nscd.patch: Fix a DoS in nscd in case of memory allocation failure (CVE-2024-33601) and a memory corruption in nscd when the underlying NSS callback function does not use the buffer space to store all strings (CVE-2024-33602). Checksums-Sha1: 7364ec1a612a68e66d1dd0fee3a08f4f7c500669 12172 glibc_2.31-13+deb11u10_ppc64el-buildd.buildinfo 82732dda36264a15734e87794f2cc34c4f849bfe 1936116 libc-bin-dbgsym_2.31-13+deb11u10_ppc64el.deb 1be5465c21bbf75a6f2157555697c07d28a68b4a 841336 libc-bin_2.31-13+deb11u10_ppc64el.deb acb36c850c0331053d409f5d98c6016fb6007038 116788 libc-dev-bin-dbgsym_2.31-13+deb11u10_ppc64el.deb d9cf17a478611834f390a91d83dbe84c0e779a3d 279388 libc-dev-bin_2.31-13+deb11u10_ppc64el.deb f10f6b8b25105764581becf0b3c325070d6273d0 42160 libc-devtools-dbgsym_2.31-13+deb11u10_ppc64el.deb e171465c8d943d749d56002941c95be72f42a8d2 247112 libc-devtools_2.31-13+deb11u10_ppc64el.deb c85aa4d94db5affd05b6b618e901e3b3d8947637 7488912 libc6-dbg_2.31-13+deb11u10_ppc64el.deb 462a443ab52ea0ca1f6e9ec922107617ccc483cf 2388920 libc6-dev_2.31-13+deb11u10_ppc64el.deb 0100530677a4eda241b87f53d67a47d2bd690daa 1225332 libc6-udeb_2.31-13+deb11u10_ppc64el.udeb e3b734f440d987b285270b3deaf0542853c11fec 2833964 libc6_2.31-13+deb11u10_ppc64el.deb 0eeaf44d75e8f390e1e87a294889accfaecee203 10753656 locales-all_2.31-13+deb11u10_ppc64el.deb 52bfed42caa3b3676b74bd1f1e1e3fdadccdb37e 237840 nscd-dbgsym_2.31-13+deb11u10_ppc64el.deb 257191225ad639cb9daf6a15680212a16f570321 294888 nscd_2.31-13+deb11u10_ppc64el.deb Checksums-Sha256: fd24164d8a198708a8bf33d7821801aa1c27adafd5fecb1907e6cc684ed699e7 12172 glibc_2.31-13+deb11u10_ppc64el-buildd.buildinfo fdd04db9feb4a58a703abfea3800b5917131b4d3831cefbcb38e670cad80983e 1936116 libc-bin-dbgsym_2.31-13+deb11u10_ppc64el.deb 01d979a5f271c80a67d712f0dc01926e358b891151f931e8a3aab5498bfd3aef 841336 libc-bin_2.31-13+deb11u10_ppc64el.deb 0fe9fbcd5cc52485796e5e7edecb5d5abf52bf98da8e662a224cc64929fc7251 116788 libc-dev-bin-dbgsym_2.31-13+deb11u10_ppc64el.deb f81db222e3cdda22eff3e0891c0205ab1abd017460ca93463b941326400f0e2c 279388 libc-dev-bin_2.31-13+deb11u10_ppc64el.deb 10a6ea722e1d54cfb907994b4a31dcfd4893336c5a64ac5688025099d1718c28 42160 libc-devtools-dbgsym_2.31-13+deb11u10_ppc64el.deb 273540f3e157076d72ab66ac2803ce9ec62654f73156834208d962842a67719c 247112 libc-devtools_2.31-13+deb11u10_ppc64el.deb 40a81289daa6236c4514b2bb38e6106e7bd89b7359b7bc52bf8b31a4b43d4550 7488912 libc6-dbg_2.31-13+deb11u10_ppc64el.deb 41558256bbdc37d173e1367d0c90f0e18907f3cd24b8c3ffa93474c728f68d0c 2388920 libc6-dev_2.31-13+deb11u10_ppc64el.deb 5dc57b81c47b33ffa7a4ed0d2f5aaa9b6f64a8338f758de5ea24858859b9c2cf 1225332 libc6-udeb_2.31-13+deb11u10_ppc64el.udeb ab32c934cd229afdff910e403b831f16c2e49f3effcd0bddc552ee7708c1bbef 2833964 libc6_2.31-13+deb11u10_ppc64el.deb 9e31ba1a4eb2cadbc4b5c446a0be0bcd7fb1db360bd664703d1e3b922b889402 10753656 locales-all_2.31-13+deb11u10_ppc64el.deb 2bf03ff5eae1e2b8b06f84ab29d3a1d5885e9c9912b62b2361956a5fef907673 237840 nscd-dbgsym_2.31-13+deb11u10_ppc64el.deb d2dc1cd7904d55251295b684fb9bc947a980f2b77e4cfd5dc6bd6ccfdfb293ff 294888 nscd_2.31-13+deb11u10_ppc64el.deb Files: 9d7bafbf3d02e172310178800c54c75b 12172 libs required glibc_2.31-13+deb11u10_ppc64el-buildd.buildinfo 1dd6f20d8b7b4caa4aee316192a68800 1936116 debug optional libc-bin-dbgsym_2.31-13+deb11u10_ppc64el.deb a6fc28d73a34d3af17f4a82c62db6285 841336 libs required libc-bin_2.31-13+deb11u10_ppc64el.deb ec6ca472101454425deef3968ac96345 116788 debug optional libc-dev-bin-dbgsym_2.31-13+deb11u10_ppc64el.deb 3aca9fdebfea1bb09fa05510c3579109 279388 libdevel optional libc-dev-bin_2.31-13+deb11u10_ppc64el.deb ac9b7311fee0c1bce2dc21d13e3586a1 42160 debug optional libc-devtools-dbgsym_2.31-13+deb11u10_ppc64el.deb 29d547789e834a5e7c2c893e32451af9 247112 devel optional libc-devtools_2.31-13+deb11u10_ppc64el.deb 692c28fb7fdc86705b8a997527ab3187 7488912 debug optional libc6-dbg_2.31-13+deb11u10_ppc64el.deb b85a6502fee03d43317345149ee8fa85 2388920 libdevel optional libc6-dev_2.31-13+deb11u10_ppc64el.deb fdd691e67989b5b6686af30fc9305d89 1225332 debian-installer optional libc6-udeb_2.31-13+deb11u10_ppc64el.udeb 1a5f4c5b2e79df13dca78af587c657be 2833964 libs optional libc6_2.31-13+deb11u10_ppc64el.deb e4ab4502f9039326a0d1ce3948e1c6ea 10753656 localization optional locales-all_2.31-13+deb11u10_ppc64el.deb 0eec95710e89c4f1cb9709fbae557642 237840 debug optional nscd-dbgsym_2.31-13+deb11u10_ppc64el.deb d71246310e56235ba0245e438b7d23ed 294888 admin optional nscd_2.31-13+deb11u10_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE8YyVP0bbbFwKPsGN0jKBgzfto4IFAmYxdU8ACgkQ0jKBgzft o4ILCRAApHeUCm3hA9p7NUBgwZqy10eYHLU087JoNYUMGPqwJ1FGNkJleiHgEo5R tkLAluyXqGXSw2LarliLqSnO6kjkOgv91CVStPk05L5QGcxER+Pz7QpNV9mcLWqI jbESiyq/00Do/dryN1FR/+UMpWHGZhbpvQSoCVYGuB9fj/BwiIwbTnlJnKA595yb XZ1yB/AvcztGNvyaF2kuRWHdKI8Rhaz9dfDvqPXTa3QLDB5OKpfsQhnrJbwrC0lV wcz8ghtI5TwdoRjYAlxRCr0yYOHOIigiMu02grJTGvxVhcrLC6Tl5/HcdKD7SGZ+ m/67KhJSCwBrk1RsnXwhPDlF2yWZQ0h2esqxo243C3lAqegknej7uU/BTFeXfeGk ZLrRMGvlqkvs/0tiZJh565WBjma1/XYU0rMliJyUnKeCAU/AADeIIZU6okNNVneA 1mHenwqH51Q2vMJWd8P28QwT2Qj5VNZEGsGn8rpTP5/K4nCCnd6bXCIOgRdUzNuG vKDhAD75Sj5sRmQiaD8oTwQsKf5ThdJOtHlXbV24J36KsvJ6c6Y7OK0f/z1bdUD6 KYgw7ivNoeBdZWlC51Y3KgjOpiRWeznAwCDqNiVdbdl8dTCAtbVar8alo0Y478pM BZ8XfmmVhvaCZy/TQy23RGgC0PrbUfhBrwTV8oNK+FAdFgZX3ko= =RKfI -----END PGP SIGNATURE-----