-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 30 Apr 2024 23:07:28 +0200 Source: glibc Binary: libc-bin libc-bin-dbgsym libc-dev-bin libc-dev-bin-dbgsym libc-devtools libc-devtools-dbgsym libc6 libc6-dbg libc6-dev libc6-dev-dbgsym libc6-udeb locales-all nscd nscd-dbgsym Architecture: ppc64el Version: 2.36-9+deb12u7 Distribution: bookworm-security Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-osuosl-02) Changed-By: Aurelien Jarno Description: libc-bin - GNU C Library: Binaries libc-dev-bin - GNU C Library: Development binaries libc-devtools - GNU C Library: Development tools libc6 - GNU C Library: Shared libraries libc6-dbg - GNU C Library: detached debugging symbols libc6-dev - GNU C Library: Development Libraries and Header Files libc6-udeb - GNU C Library: Shared libraries - udeb (udeb) locales-all - GNU C Library: Precompiled locale data nscd - GNU C Library: Name Service Cache Daemon Changes: glibc (2.36-9+deb12u7) bookworm-security; urgency=medium . * debian/patches/local-CVE-2024-33599-nscd.diff: Fix a stack-based buffer overflow in nscd netgroup cache (CVE-2024-33599). * debian/patches/local-CVE-2024-33600-nscd.diff: Fix a null pointer dereferences in nscd after failed netgroup cache insertion (CVE-2024-33600). * debian/patches/any/local-CVE-2024-33601-33602-nscd.diff: Fix a DoS in nscd in case of memory allocation failure (CVE-2024-33601) and a memory corruption in nscd when the underlying NSS callback function does not use the buffer space to store all strings (CVE-2024-33602). Checksums-Sha1: 023752a8cff8854ca62d1bdfb72e322ad800764e 12809 glibc_2.36-9+deb12u7_ppc64el-buildd.buildinfo 56fe12cdc66c4b83acd09d83f2ebe68af3d12f56 2479404 libc-bin-dbgsym_2.36-9+deb12u7_ppc64el.deb cbe42875cc54e9dbc55b7e96421dd557f25a2338 646804 libc-bin_2.36-9+deb12u7_ppc64el.deb b8c129da3633783cee439b9185e57cb3214ae74e 29180 libc-dev-bin-dbgsym_2.36-9+deb12u7_ppc64el.deb ec840833fefd702c117d1bafd67a206873500590 46524 libc-dev-bin_2.36-9+deb12u7_ppc64el.deb 0770fb8e3993c66d1985848cc738d557722e0ec3 43360 libc-devtools-dbgsym_2.36-9+deb12u7_ppc64el.deb 01d5fb776171a67f333e05ce9900ee5d71d0915a 53924 libc-devtools_2.36-9+deb12u7_ppc64el.deb 796dc52f4358f399d8dbe59665e93c1867fde7d8 8185216 libc6-dbg_2.36-9+deb12u7_ppc64el.deb b3f2db0cc0034a20cda164ab0933b90c1be44c3a 15344 libc6-dev-dbgsym_2.36-9+deb12u7_ppc64el.deb 1d15dcd99dc32ed70501b03238c61e7b5fe4e895 1814652 libc6-dev_2.36-9+deb12u7_ppc64el.deb 72784f80f94509cc913f0652c5ad3eb467236015 1242112 libc6-udeb_2.36-9+deb12u7_ppc64el.udeb 4b251293a847b2f9010153c036e12b268328a1a7 2685588 libc6_2.36-9+deb12u7_ppc64el.deb ecee2cb55d8083b0f2d4a079e58d04229abd6295 10699560 locales-all_2.36-9+deb12u7_ppc64el.deb f4b766f16c8bd3471d7b2e8d00ed5f2db23f1143 272500 nscd-dbgsym_2.36-9+deb12u7_ppc64el.deb 1fb6916247349296fc0c053e9ecaa59ad20f4965 104604 nscd_2.36-9+deb12u7_ppc64el.deb Checksums-Sha256: 9b06226c2f5df48dd0e84ea0315d6c613cf18973d91dc371beba431afe5318c0 12809 glibc_2.36-9+deb12u7_ppc64el-buildd.buildinfo 35811fc7f27b4044aa64c061c741f797a3cacd735dbde613378be978b464ff10 2479404 libc-bin-dbgsym_2.36-9+deb12u7_ppc64el.deb a44081348db5c9a1b44ad3c6a7551fbfc642b7495153f180a62dde8589156927 646804 libc-bin_2.36-9+deb12u7_ppc64el.deb 38f491e9e2623e0afb9561eaafc7e841d0bc0efe718611a5f67def9975afbe51 29180 libc-dev-bin-dbgsym_2.36-9+deb12u7_ppc64el.deb d2c221bbea1bee946148687df8155b1d9a9d1cfdc8c02a10bec4a81e1758db0a 46524 libc-dev-bin_2.36-9+deb12u7_ppc64el.deb e92b640a976612ea78f5c1a2d057ff60a9771e5cf4df3a0eb3ab405efd637e59 43360 libc-devtools-dbgsym_2.36-9+deb12u7_ppc64el.deb 6d8a07e94697e4da7c61b3c1bf9d49553a40ddf5cbb3723fa75356bad8dcecfb 53924 libc-devtools_2.36-9+deb12u7_ppc64el.deb 430d4cdf2b897ca3c32c78a0de58484bfee5924ec11644fc72a7cfdf307497cb 8185216 libc6-dbg_2.36-9+deb12u7_ppc64el.deb dd1ce4e87affeb1bd56cb789310c2f7e195c213242d2c60771ca966548abfa2d 15344 libc6-dev-dbgsym_2.36-9+deb12u7_ppc64el.deb 87b6e943f796c94c5f208d441c37d96948e6ec9f06eed2750510a0d528813329 1814652 libc6-dev_2.36-9+deb12u7_ppc64el.deb 690b9c37d948374b061271828d92fa5151339cd54f1033f040504396c92c30f5 1242112 libc6-udeb_2.36-9+deb12u7_ppc64el.udeb b25dd4f5ad282be5f414570fcf3612c39b48fd809db421f79637578ceea84c90 2685588 libc6_2.36-9+deb12u7_ppc64el.deb 69a90eacd0993153a05a02026bc58f5587b90245e7fa9f6b9c83f41c33d41dc4 10699560 locales-all_2.36-9+deb12u7_ppc64el.deb e2c3d0422569dfb6cbb9dd01b7640ac544f1d3e5aac121f34ed8edd99df5f919 272500 nscd-dbgsym_2.36-9+deb12u7_ppc64el.deb b33ea826ece4fd1946a6ab3c552844fde5db9dab0b3986de43f312d11c80ea82 104604 nscd_2.36-9+deb12u7_ppc64el.deb Files: 8b2b9e833af04f88cb84ae61863d3e24 12809 libs required glibc_2.36-9+deb12u7_ppc64el-buildd.buildinfo 2006b91d33737af8192fee6398894d36 2479404 debug optional libc-bin-dbgsym_2.36-9+deb12u7_ppc64el.deb 45d6ef9e41795c8be12f2c6486839107 646804 libs required libc-bin_2.36-9+deb12u7_ppc64el.deb 8df688ca354c899e23f902ca56773082 29180 debug optional libc-dev-bin-dbgsym_2.36-9+deb12u7_ppc64el.deb b390c24bbcbf3b3d97b325840ddd9adb 46524 libdevel optional libc-dev-bin_2.36-9+deb12u7_ppc64el.deb b61a1b9495dfd822a097acde4b81ae4d 43360 debug optional libc-devtools-dbgsym_2.36-9+deb12u7_ppc64el.deb 99f5d8f351f448b2887b544446828910 53924 devel optional libc-devtools_2.36-9+deb12u7_ppc64el.deb eab5199b8da8996b510bdc51acd24547 8185216 debug optional libc6-dbg_2.36-9+deb12u7_ppc64el.deb 12b03c980faf1b7b0cad153399060050 15344 debug optional libc6-dev-dbgsym_2.36-9+deb12u7_ppc64el.deb a40d38814c610985c033fb27d29f10dc 1814652 libdevel optional libc6-dev_2.36-9+deb12u7_ppc64el.deb b55d2ea726a726b2151f0240e25fbc9e 1242112 debian-installer optional libc6-udeb_2.36-9+deb12u7_ppc64el.udeb 65fa3027b4d2b73370528b43cae96931 2685588 libs optional libc6_2.36-9+deb12u7_ppc64el.deb 7f509815195239877db3df6dc348e2a9 10699560 localization optional locales-all_2.36-9+deb12u7_ppc64el.deb a141e97b88925539c94d63068c4d10e4 272500 debug optional nscd-dbgsym_2.36-9+deb12u7_ppc64el.deb a8e78b763eb50bea6a04b46ab9080872 104604 admin optional nscd_2.36-9+deb12u7_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEHDNCkvGgp2XShfnByW8ECaj2byoFAmYxatcACgkQyW8ECaj2 byqSfw//U8sYXmO6N/YcHo+ZV41A/0MXysmOF7vn4fOLdptWMq/4G+1MQyaUaBir u88Ipcl/u1HFK8CDunnd5+sSdkv2KBHoR/tXKQirWCKzpo7qIGBy1ikrRrLiz758 sO6Wl1AzovoELrpEzO2GYIaXvojLYaLrd8ueWjAsgQHDsC6iEPzJilQ/7EHULe2V E4g9IgFvFuJ2S7il5cqTNuFNCggcO4ZxmWqxK5MZtRmrziiOVVArkVsCt4EldThe EPIHUx3ShBUyt21Rxi2grFyucUO2InvWkI2IRc5uG3jq9wRNKdVbiuHndewUzCdk 31irJTUh+wCJav80PpAvJT+OjE8P90mfS8j+85jOYI45MqueRg6CNKTL1GixhE0U eEjmNmYFsKz0yvlChD+QPmnJV/+QBZ3Xb52dunilWLA9MhlNxeX+3vw+2RBOaDGx 73U+QLYahAKRWn81msD6WMoBFa3Kq9Y2euKv0eqU1DWevC8NdoVr/8PovRXh0xVh UJjZ9M+DQ0PsIjkKFMkjlztZWKgCBMnST9JKbrAVhA84FP2ihl3cjGMHTdnd/znf GMsU0EoLEC5HSsSZVrjWC1xXrf/8QPPC0dcxLrlF96ZLWAqIKsKeVrsl/1qoG17E 7NQtyYfpd161QiDvezEc2seBNXSWRRX4PrfO0boFZhbV9fiLvEI= =tAft -----END PGP SIGNATURE-----