-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 30 Apr 2024 23:07:28 +0200 Source: glibc Binary: libc-bin libc-bin-dbgsym libc-dev-bin libc-dev-bin-dbgsym libc-devtools libc-devtools-dbgsym libc6 libc6-dbg libc6-dev libc6-dev-dbgsym libc6-dev-i386 libc6-dev-x32 libc6-i386 libc6-i386-dbgsym libc6-udeb libc6-x32 libc6-x32-dbgsym locales-all nscd nscd-dbgsym Architecture: amd64 Version: 2.36-9+deb12u7 Distribution: bookworm-security Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Aurelien Jarno Description: libc-bin - GNU C Library: Binaries libc-dev-bin - GNU C Library: Development binaries libc-devtools - GNU C Library: Development tools libc6 - GNU C Library: Shared libraries libc6-dbg - GNU C Library: detached debugging symbols libc6-dev - GNU C Library: Development Libraries and Header Files libc6-dev-i386 - GNU C Library: 32-bit development libraries for AMD64 libc6-dev-x32 - GNU C Library: X32 ABI Development Libraries for AMD64 libc6-i386 - GNU C Library: 32-bit shared libraries for AMD64 libc6-udeb - GNU C Library: Shared libraries - udeb (udeb) libc6-x32 - GNU C Library: X32 ABI Shared libraries for AMD64 locales-all - GNU C Library: Precompiled locale data nscd - GNU C Library: Name Service Cache Daemon Changes: glibc (2.36-9+deb12u7) bookworm-security; urgency=medium . * debian/patches/local-CVE-2024-33599-nscd.diff: Fix a stack-based buffer overflow in nscd netgroup cache (CVE-2024-33599). * debian/patches/local-CVE-2024-33600-nscd.diff: Fix a null pointer dereferences in nscd after failed netgroup cache insertion (CVE-2024-33600). * debian/patches/any/local-CVE-2024-33601-33602-nscd.diff: Fix a DoS in nscd in case of memory allocation failure (CVE-2024-33601) and a memory corruption in nscd when the underlying NSS callback function does not use the buffer space to store all strings (CVE-2024-33602). Checksums-Sha1: 2e4d92f01e171abb214c38cd34e5752ba19af86c 15319 glibc_2.36-9+deb12u7_amd64-buildd.buildinfo 4121089497626d59dc1026ea2bdfba185c6ff46f 2352028 libc-bin-dbgsym_2.36-9+deb12u7_amd64.deb a1f42983a592f2eadb232fb1e055636a05644848 606996 libc-bin_2.36-9+deb12u7_amd64.deb a26d4f1aa917393be79bc80bcfd81ccbe7aac893 29572 libc-dev-bin-dbgsym_2.36-9+deb12u7_amd64.deb d5d0630e3dd234fb99d4ea7ec86bd005fa66bc2c 45784 libc-dev-bin_2.36-9+deb12u7_amd64.deb 0487c80a64cbbaad41bc0d8052ab59fa20e1c574 44736 libc-devtools-dbgsym_2.36-9+deb12u7_amd64.deb 3cb13d0c7e551c50f36775eb99706e4d11156a59 53448 libc-devtools_2.36-9+deb12u7_amd64.deb 0f1a49b7afa1122cdacf8c829c14cbcb216ae48c 7461868 libc6-dbg_2.36-9+deb12u7_amd64.deb 71a986072da07f4a26e61ccb4286b9b0dbd79a06 15788 libc6-dev-dbgsym_2.36-9+deb12u7_amd64.deb 871d00e93952a4e9b38098412d3e33c448fdecff 1351000 libc6-dev-i386_2.36-9+deb12u7_amd64.deb 67ef372d193f1105bfd72d3732fc1ff569cce846 1515452 libc6-dev-x32_2.36-9+deb12u7_amd64.deb f970df789944e2c38200412ed2519008ead26cbc 1898644 libc6-dev_2.36-9+deb12u7_amd64.deb 75071bea423802f57ac8719fffcd01693a5a512c 7045808 libc6-i386-dbgsym_2.36-9+deb12u7_amd64.deb 49b4265d2400cfefcdf0f47eba4304fa21638883 2460188 libc6-i386_2.36-9+deb12u7_amd64.deb 20d6f00e723ce4e5099aa58b9f1c4a35db34bed2 1364620 libc6-udeb_2.36-9+deb12u7_amd64.udeb 343ce9530b3c9313e0f13a2ca87f1601e7a28798 7262264 libc6-x32-dbgsym_2.36-9+deb12u7_amd64.deb 8382608dcfb293e440099205e5bb053f13c5c487 2584260 libc6-x32_2.36-9+deb12u7_amd64.deb 370433cabd51dddecd7f601f6f31ff32e9388df2 2757936 libc6_2.36-9+deb12u7_amd64.deb 6b44953c01d5f7d1d2799ed16c116533ae64954b 10699468 locales-all_2.36-9+deb12u7_amd64.deb bf5174bc08bd85534a73b93183f9b98cf7b7d62c 274684 nscd-dbgsym_2.36-9+deb12u7_amd64.deb 949066f015ece9b5d25972c46c07d52b2c40b774 102528 nscd_2.36-9+deb12u7_amd64.deb Checksums-Sha256: 09916571c1bc495c9228089daf6a5fa8e996fa119dcf4b841e2c9261bdbda554 15319 glibc_2.36-9+deb12u7_amd64-buildd.buildinfo bc72391ddffd43712d2f684be6ee629305ecec601b1cadccf4d7400b0573077c 2352028 libc-bin-dbgsym_2.36-9+deb12u7_amd64.deb 687687d1ace90565cc451b1be527914246123968b747c823e276cd7f8b57ba3d 606996 libc-bin_2.36-9+deb12u7_amd64.deb d9c890a1f009f27a0b4eba98180ca509f7592f85d9deae1ed1c8366a40134b78 29572 libc-dev-bin-dbgsym_2.36-9+deb12u7_amd64.deb 176dfc2e819d5b2b0c3626f6c08d79a30c39639001b3a464327a4683b95e3611 45784 libc-dev-bin_2.36-9+deb12u7_amd64.deb 88f0114b11f0bbb66a836a7c6b13d90c6c822b75118516952f859dabc8ccf806 44736 libc-devtools-dbgsym_2.36-9+deb12u7_amd64.deb 7481e9b34a2583c2c198264162169dbf48addf2378a0dcad85dc7b3a99a6d00a 53448 libc-devtools_2.36-9+deb12u7_amd64.deb ca4c010c705192750d935af10fec55213cd0b56646a5ab9caa425c70c0bf82ee 7461868 libc6-dbg_2.36-9+deb12u7_amd64.deb 3182dee6cb2554ac8627d2eed9ccee20ceb0290cd161c4fe068c205a17bd8c3e 15788 libc6-dev-dbgsym_2.36-9+deb12u7_amd64.deb 415268bc2974ba504d8d3866ac1b5d407761417c702e6f2e4a9a1d1d77ffddfc 1351000 libc6-dev-i386_2.36-9+deb12u7_amd64.deb e5f381f74996eab2ae439c88d1cf3d56a6250231bbd6f6413370e54c93d3ec82 1515452 libc6-dev-x32_2.36-9+deb12u7_amd64.deb 26d7b128d9cdba9c30028d382aa265514616a6cdc08643f7397a32eba3a3bd60 1898644 libc6-dev_2.36-9+deb12u7_amd64.deb 55cea9a3fa2baa263458c98ebbe0ed9541091a47691f366fae749ab4194c3872 7045808 libc6-i386-dbgsym_2.36-9+deb12u7_amd64.deb a97737f9de39789c59f7328a3150f4983d1003dc321f834d7cfff711d9e02978 2460188 libc6-i386_2.36-9+deb12u7_amd64.deb 917c815aacd590791efb489e47aa9d3bdf86d739d2e72b677508015ff833cc23 1364620 libc6-udeb_2.36-9+deb12u7_amd64.udeb 7ed6e17b627a0a4ae4a67e24adbc859b59900238368d87e69e5316e4bfa531aa 7262264 libc6-x32-dbgsym_2.36-9+deb12u7_amd64.deb cec420fb034ba5f5ba6d6b5434e2b22c8880b605b1361928eb51edfbb776c4f1 2584260 libc6-x32_2.36-9+deb12u7_amd64.deb eba944bd99c2f5142baf573e6294a70f00758083bc3c2dca4c9e445943a3f8e6 2757936 libc6_2.36-9+deb12u7_amd64.deb 407942f8edd746e3c6545f1d068ff21765609b47f5554f1e2993f612c6b64f77 10699468 locales-all_2.36-9+deb12u7_amd64.deb a708c1abd7a99a651884f3594f5b44194350911881c6511bd51e52824411ac2b 274684 nscd-dbgsym_2.36-9+deb12u7_amd64.deb 27b8291caf1f0cbf4cfb44b6661afc360dca3bf6a2a0cce379e4d220fb8371fe 102528 nscd_2.36-9+deb12u7_amd64.deb Files: 510f792423ab4ec80669849679d0b59a 15319 libs required glibc_2.36-9+deb12u7_amd64-buildd.buildinfo 03fffa3e2089aeb3c3ea4d1b2f26ff59 2352028 debug optional libc-bin-dbgsym_2.36-9+deb12u7_amd64.deb ce029352e3b8bca04696ace1af60e0b8 606996 libs required libc-bin_2.36-9+deb12u7_amd64.deb e0fa972c7719d802b96a635f1fadb4b8 29572 debug optional libc-dev-bin-dbgsym_2.36-9+deb12u7_amd64.deb cee2c233191418187ec19775a4e4ef4a 45784 libdevel optional libc-dev-bin_2.36-9+deb12u7_amd64.deb 824dfffa5c65f9683cb8164558d0a9d9 44736 debug optional libc-devtools-dbgsym_2.36-9+deb12u7_amd64.deb 677c6a212e917a0824cc32e7e79b2418 53448 devel optional libc-devtools_2.36-9+deb12u7_amd64.deb 632891734b34b01e7fea3e0d2937c64f 7461868 debug optional libc6-dbg_2.36-9+deb12u7_amd64.deb cf322241c886b00d6f3bff7e27e8431a 15788 debug optional libc6-dev-dbgsym_2.36-9+deb12u7_amd64.deb 0bfc101a0bce274c1d3f95383562428a 1351000 libdevel optional libc6-dev-i386_2.36-9+deb12u7_amd64.deb 73608c77398aa44924f287eaa37ef779 1515452 libdevel optional libc6-dev-x32_2.36-9+deb12u7_amd64.deb 07bf6af02d23f5537273de70933213e9 1898644 libdevel optional libc6-dev_2.36-9+deb12u7_amd64.deb 2a90885e7124bdcdf40c161d24df316f 7045808 debug optional libc6-i386-dbgsym_2.36-9+deb12u7_amd64.deb 73290b9ce75a93ed0d50e1ef3cac65ff 2460188 libs optional libc6-i386_2.36-9+deb12u7_amd64.deb f2189aa037c808a2ed7dfa8ef5132a15 1364620 debian-installer optional libc6-udeb_2.36-9+deb12u7_amd64.udeb 64a2598de8af8992917a735b55ebb2df 7262264 debug optional libc6-x32-dbgsym_2.36-9+deb12u7_amd64.deb 2bf778412427e7555bd1be0a64a36ef6 2584260 libs optional libc6-x32_2.36-9+deb12u7_amd64.deb a9480b37954b1c6327b09526cc1974c3 2757936 libs optional libc6_2.36-9+deb12u7_amd64.deb 90ba83e2de8fd175c88092614af67e2d 10699468 localization optional locales-all_2.36-9+deb12u7_amd64.deb 099b5eb78873837a8e86bb06eefa6915 274684 debug optional nscd-dbgsym_2.36-9+deb12u7_amd64.deb a8febe456e035854737805b9442be0de 102528 admin optional nscd_2.36-9+deb12u7_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE4Unr4QHS5Yi4rr9Q3KGKEAtjIVgFAmYxclMACgkQ3KGKEAtj IVig5w//TWoJtd3dSR7jmJjI1F0cv7RJ/pZgjZz4ZFPhRvvAiQPxWiMTlD8fI+0m YCFZ46ojI4RvcTYIKIL527z+egl3ix/Cb3tGQf1zcmmgVJIjaYYuwhyH9shX1XSZ q+1ys4DoJXcO6GS+4D47M3xuqG/kID5b0EMrudpNy6WUv8PEFAQlRBmVKuHJSPtd 9xxEYdz/n8C5CKSTAqvFVNgw/+2CX8RJtBps0VCejwDQVLDOVM7/PTwwH33hSq7i oUh5/pCorXC3AkUHFOqTEvLzN8Gm4QSpj/Z6Dr7r1m4pmgyah66LFtnDJH4Tyv2G LgA/chOeVbBMMLXl5YD4Ky06td+F/rUgbjPAyTkjUEY1ZyFVfFixe8rl0oGMCZ88 sTLa0nF7UBq13A/Xsyx/GVUEPhnHWt6eTBfu1kUMnohjnqvAXkLFMb6Ba35Rhqfc Zjg3kjlCUancwG+NfHM69LPgV+8MNXdnOY3x3H0MgocYggN2QRNNd7KALvFjwKNH EL0zkU82A9qA+/1A4Vj3YPYgp1cP7TzKAPfjP9SMyQdG1T4PhibJYt6DbsHOLbwx ORAME/R38+nvNtNlj4KHMGJpZgJcXWiSfBh8do5EsrNtf6+SD6mgx8lYI/XnHw/R kCT34BQHalgIvD71kNMdm7q+9NFfw/Fi7IXnK3tZt0zV3U1oYqg= =7M5g -----END PGP SIGNATURE-----