From: Andreas K. Hüttel Date: Sat, 26 Jul 2025 13:23:49 +0000 (+0200) Subject: NEWS: insert list of CVEs X-Git-Tag: glibc-2.42~10 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=a92914de93979dbaa85ae9e410157bf5b67bcf98;p=thirdparty%2Fglibc.git NEWS: insert list of CVEs Signed-off-by: Andreas K. Hüttel --- diff --git a/NEWS b/NEWS index a3ab26c046..14a58be747 100644 --- a/NEWS +++ b/NEWS @@ -83,8 +83,21 @@ Security related changes: The following CVEs were fixed in this release, details of which can be found in the advisories directory of the release tarball: - [The release manager will add the list generated by - scripts/process-advisories.sh just before the release.] + GLIBC-SA-2025-0001: + assert: Buffer overflow when printing assertion failure message + (CVE-2025-0395) + + GLIBC-SA-2025-0003: + power10: strcmp fails to save and restore nonvolatile vector + registers (CVE-2025-5702) + + GLIBC-SA-2025-0004: + power10: strncmp fails to save and restore nonvolatile vector + registers (CVE-2025-5745) + + GLIBC-SA-2025-0005: + posix: Fix double-free after allocation failure in regcomp + (CVE-2025-8058) The following bugs were resolved with this release: