]> git.ipfire.org Git - thirdparty/glibc.git/commitdiff
Add references to CVE-2018-11236, CVE-2017-18269
authorFlorian Weimer <fweimer@redhat.com>
Thu, 24 May 2018 12:41:57 +0000 (14:41 +0200)
committerFlorian Weimer <fweimer@redhat.com>
Thu, 24 May 2018 13:49:32 +0000 (15:49 +0200)
ChangeLog
NEWS

index 41b4dae2318a8749b866fef43aeed3672ec1ddb1..e45fa8e6d0066e7347933cadf38cce55e3528363 100644 (file)
--- a/ChangeLog
+++ b/ChangeLog
@@ -16,6 +16,7 @@
 2018-05-09  Paul Pluzhnikov  <ppluzhnikov@google.com>
 
        [BZ #22786]
+       CVE-2018-11236
        * stdlib/canonicalize.c (__realpath): Fix overflow in path length
        computation.
        * stdlib/Makefile (test-bz22786): New test.
@@ -59,6 +60,7 @@
            Max Horn  <max@quendi.de>
 
        [BZ #22644]
+       CVE-2017-18269
        * sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S: Fixed
        branch conditions.
        * string/test-memmove.c (do_test2): New testcase.
diff --git a/NEWS b/NEWS
index c3c6aff8fc6275f1dd73522e2117aeafb549eff3..27548fdb4b21ef1fbf634fb5f2429b107f1958c8 100644 (file)
--- a/NEWS
+++ b/NEWS
@@ -59,6 +59,9 @@ Security related changes:
   for AT_SECURE or SUID binaries could be used to load libraries from the
   current directory.
 
+  CVE-2017-18269: An SSE2-based memmove implementation for the i386
+  architecture could corrupt memory.  Reported by Max Horn.
+
   CVE-2018-1000001: Buffer underflow in realpath function when getcwd function
   succeeds without returning an absolute path due to unexpected behaviour
   of the Linux kernel getcwd syscall.  Reported by halfdog.