-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 30 Apr 2024 23:07:28 +0200 Source: glibc Binary: libc-bin libc-bin-dbgsym libc-dev-bin libc-dev-bin-dbgsym libc-devtools libc-devtools-dbgsym libc6 libc6-dbg libc6-dev libc6-dev-dbgsym libc6-udeb locales-all nscd nscd-dbgsym Architecture: armel Version: 2.36-9+deb12u7 Distribution: bookworm-security Urgency: medium Maintainer: arm Build Daemon (arm-ubc-05) Changed-By: Aurelien Jarno Description: libc-bin - GNU C Library: Binaries libc-dev-bin - GNU C Library: Development binaries libc-devtools - GNU C Library: Development tools libc6 - GNU C Library: Shared libraries libc6-dbg - GNU C Library: detached debugging symbols libc6-dev - GNU C Library: Development Libraries and Header Files libc6-udeb - GNU C Library: Shared libraries - udeb (udeb) locales-all - GNU C Library: Precompiled locale data nscd - GNU C Library: Name Service Cache Daemon Changes: glibc (2.36-9+deb12u7) bookworm-security; urgency=medium . * debian/patches/local-CVE-2024-33599-nscd.diff: Fix a stack-based buffer overflow in nscd netgroup cache (CVE-2024-33599). * debian/patches/local-CVE-2024-33600-nscd.diff: Fix a null pointer dereferences in nscd after failed netgroup cache insertion (CVE-2024-33600). * debian/patches/any/local-CVE-2024-33601-33602-nscd.diff: Fix a DoS in nscd in case of memory allocation failure (CVE-2024-33601) and a memory corruption in nscd when the underlying NSS callback function does not use the buffer space to store all strings (CVE-2024-33602). Checksums-Sha1: 6b673c9806bf60c961022fb061fa6df97a7045b3 12584 glibc_2.36-9+deb12u7_armel-buildd.buildinfo 43ff6a8eefd22ae7e2867a33761a832ba2643566 2285980 libc-bin-dbgsym_2.36-9+deb12u7_armel.deb 04a7fcab4cc6324a1f7a64f5b2ff9549278efd39 494156 libc-bin_2.36-9+deb12u7_armel.deb ae5ce7cb2d243777a677ee270071c94d2e29cb7c 29460 libc-dev-bin-dbgsym_2.36-9+deb12u7_armel.deb 99682078fa3d72457352bec6d91259e45a737838 44476 libc-dev-bin_2.36-9+deb12u7_armel.deb 2fffedb72d35e6c805f9ee5bf1d6e88961f85845 43440 libc-devtools-dbgsym_2.36-9+deb12u7_armel.deb 1247f325650d1220fe642ce113598371341a2f54 55056 libc-devtools_2.36-9+deb12u7_armel.deb b90d76edbaa2947380efba246d4862ccf54d5eb0 6929068 libc6-dbg_2.36-9+deb12u7_armel.deb 4ca7445803537469c8ffbf48d89d4d5d814d43fb 14504 libc6-dev-dbgsym_2.36-9+deb12u7_armel.deb 81449fca7104e884d8de9dd81f386e980eb5694b 1292516 libc6-dev_2.36-9+deb12u7_armel.deb efc10799ece29da588ba9485dccbd2d74bafc873 786364 libc6-udeb_2.36-9+deb12u7_armel.udeb e61e789967bcc637e2b4a80e5bf7a928e52f540d 2141864 libc6_2.36-9+deb12u7_armel.deb cdb1874b6d9e67f7532467f53c334a1dc82c09ca 10699524 locales-all_2.36-9+deb12u7_armel.deb aebe6fa405cebfed77550f0cdc68581aba4f7745 267656 nscd-dbgsym_2.36-9+deb12u7_armel.deb 42d658c8e45005f5509d6dbb240bf28a7405a555 94884 nscd_2.36-9+deb12u7_armel.deb Checksums-Sha256: 5add02d2e692832d5b8bd23221157e89ceb7a4e8a940a52edc7a358080f11828 12584 glibc_2.36-9+deb12u7_armel-buildd.buildinfo a918f153ea9e82592c8bec32efeb836a297937df66bd724cf3180547db68c4d7 2285980 libc-bin-dbgsym_2.36-9+deb12u7_armel.deb e6e8fc692687fb667d95d0918bdcb9952a5c9b802b3709b92efa80b855695755 494156 libc-bin_2.36-9+deb12u7_armel.deb 6d258a1ceacfdcc2f3cf53eaf5eb44ad165c5e6eab51f035b696df88260d9725 29460 libc-dev-bin-dbgsym_2.36-9+deb12u7_armel.deb 80b6f696da4e52bf5a1c7cc292a74a4be3f3e7bf7efd45f2d9a96852f8301139 44476 libc-dev-bin_2.36-9+deb12u7_armel.deb 2a2abec8fcff3dc06cfc14cab55dbf36e8a2fb2bf01924bd75244272e7b095f2 43440 libc-devtools-dbgsym_2.36-9+deb12u7_armel.deb 98201156fdf81681f1f48896c92e297e398ad9705ca36667f37d3f05d946cd0e 55056 libc-devtools_2.36-9+deb12u7_armel.deb 3977324dad632d7e44399788963292d126c9974657bb44d5a2ce75f8d133a87b 6929068 libc6-dbg_2.36-9+deb12u7_armel.deb ec0fe0fbea966d5e2d59a583764c457b05f166ded7e02b0ab7c268229a490c1a 14504 libc6-dev-dbgsym_2.36-9+deb12u7_armel.deb 657944454829384ddd403af9975529aa79a5c0691a98da6ae7f433f3be0670e2 1292516 libc6-dev_2.36-9+deb12u7_armel.deb 688c6dc6e2d53aa567f08f06338825e734a4e3317d86e49459a7633744cc67c3 786364 libc6-udeb_2.36-9+deb12u7_armel.udeb 3cc583984b28bda1b7ffe75801666664bd42fd8a0254f57b8ca774d6f650cdf4 2141864 libc6_2.36-9+deb12u7_armel.deb d66ba3e11beca6c5ddb32c44f8efe17302c292b722baa3e1523f986446e1bace 10699524 locales-all_2.36-9+deb12u7_armel.deb 2722641850393c6bb8632ea2a10efd520d574b1f6533fde74186b5b3225ed13b 267656 nscd-dbgsym_2.36-9+deb12u7_armel.deb 77a4cea38b40267996cf20b4b57a20f932475f8369161be3fc1d559483938526 94884 nscd_2.36-9+deb12u7_armel.deb Files: 0d54bba89efb4f80fc9533b9d6c87c41 12584 libs required glibc_2.36-9+deb12u7_armel-buildd.buildinfo b3029c356aa354cae9911621ebbfbb46 2285980 debug optional libc-bin-dbgsym_2.36-9+deb12u7_armel.deb 2e12ae4bf438c14ca41ac83e8d1897d9 494156 libs required libc-bin_2.36-9+deb12u7_armel.deb 13103d12ce24176142aa2024bef2221b 29460 debug optional libc-dev-bin-dbgsym_2.36-9+deb12u7_armel.deb 05ee9564fde026ca871a2bd375ddb650 44476 libdevel optional libc-dev-bin_2.36-9+deb12u7_armel.deb 5ed8a3d4a7120bb59ba2f4532fd0ea18 43440 debug optional libc-devtools-dbgsym_2.36-9+deb12u7_armel.deb aa7ecb477cd8592350fd92be6d31d73b 55056 devel optional libc-devtools_2.36-9+deb12u7_armel.deb d253bc9e6c7fda0e1b554e3d08c37e81 6929068 debug optional libc6-dbg_2.36-9+deb12u7_armel.deb 8de69b02438dc12ba9a36f0ab3ed7445 14504 debug optional libc6-dev-dbgsym_2.36-9+deb12u7_armel.deb e0fe925245daa2137e3a4ddd316d5eb4 1292516 libdevel optional libc6-dev_2.36-9+deb12u7_armel.deb c9f5ae00cf468956fca77fa2c7149c9d 786364 debian-installer optional libc6-udeb_2.36-9+deb12u7_armel.udeb e7fd07dc42bd0496bb8be3702b989f3e 2141864 libs optional libc6_2.36-9+deb12u7_armel.deb 39f7c06469410387a2d4f666a93ab9eb 10699524 localization optional locales-all_2.36-9+deb12u7_armel.deb 78b85b4a6872df25bc5db2fefcba38f7 267656 debug optional nscd-dbgsym_2.36-9+deb12u7_armel.deb 73f15524d259a5cd67fd5f0699b75d4f 94884 admin optional nscd_2.36-9+deb12u7_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEiIhsyZ7bTtoONs0yzW4+LN9obe4FAmYyL4cACgkQzW4+LN9o be7HbA/+OgxC9DJD38NDw+mImw6f+X2TD2kO9V51iuAeRezyRiMUmOwhzZiNz68w bs+iezWzyVegFdrPkTsV0xvhJcW0XlW5QoK0GN55qVkDfA24/0dBrYF5wHR27Mzb CT7tdKn4EwEEpfdFUBojeO8KD+ID4a8ARPxEGekL/oYzmSxCHUKOGesc77APGbEI E9Lv/LXIr5mocbFCigzsaZi6kITtGxB39U6VznWCxkVMHMbc6+rlTiVlfteJvNZl CqHqD1TESru9iaAfnYB7U5QTRbMslFngG5lW2teNN6UELwRPAKv9TnmCM1cl8CZ2 20xpC4Mg381wIoNfKW8iaP0M5CRWiD+H2O4eBpAiTx3nD4P7K13CuFNOXKcGqZeX jPE21IGfWVc5nhFIyaf6iHNlnJHBpfdT/h3eaBRLlrDFc70KTAMoe/sbv0OAW3Lc 0C7P5MLpzGBF2ZxWYmwCmHOja40dWMGzq+cQ/2f9e7TGI5Vm2oSyGP4THHn5CNWL lvxyqJjID9QBWuuSt10aPSdEbvGMPvzNrzouMJLAdUZeoE2LEDoi6oV1ER+K7bZ1 n8/eft9Bgb3NEYYlVSOp0xa/lOOtgxyBNoxtQmLHeHohKjb1xz7loLAzrSHHzIM1 eAtQ78/nZB6+fr0ds8ZmPbq4ANoF7v5mDbrEqrkfwgde8jNwvZA= =nX0x -----END PGP SIGNATURE-----