Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package glibc for openSUSE:Factory checked 
in at 2026-09-15 12:48:11
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/glibc (Old)
 and      /work/SRC/openSUSE:Factory/.glibc.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "glibc"

Tue Sep 15 12:48:11 2026 rev:308 rq:1377843 version:2.44

Changes:
--------
--- /work/SRC/openSUSE:Factory/glibc/glibc.changes      2026-09-01 
15:47:33.563087544 +0200
+++ /work/SRC/openSUSE:Factory/.glibc.new.383539/glibc.changes  2026-09-15 
12:48:14.563488410 +0200
@@ -1,0 +2,20 @@
+Mon Aug 31 10:56:20 UTC 2026 - Andreas Schwab <[email protected]>
+
+- strfmon-right-just.patch: stdlib: Fix right-justification in strfmon
+  (CVE-2026-19499, bsc#1276892, BZ #34510)
+- tdelete-oob-write.patch: misc: Fix out-of-bounds array write in tdelete
+  (CVE-2026-19542, bsc#1276946, BZ #34506)
+- sjisx-pending-char-reset.patch: iconvdata: SHIFT_JISX0213 decoding lacks
+  pending character reset (CVE-2026-77117, bsc#1277921, BZ #34556)
+- eucjisx-pending-char-reset.patch: iconvdata: EUC_JISX0213 decoding lacks
+  pending character reset (CVE-2026-80489, bsc#1277922, BZ #34568)
+- libio-fopen-ccs.patch: libio: Fix CVE-2026-18374 heap buffer overflow in
+  ccs= handling (CVE-2026-18374, bsc#1277262, BZ #34574)
+
+-------------------------------------------------------------------
+Thu Aug 27 17:10:09 UTC 2026 - Giuliano Belinassi <[email protected]>
+
+- Add -flive-patching=inline-clone to avoid untraceable inter-procedural
+  optimizations (bsc#1277247).
+
+-------------------------------------------------------------------

New:
----
  eucjisx-pending-char-reset.patch
  libio-fopen-ccs.patch
  sjisx-pending-char-reset.patch
  strfmon-right-just.patch
  tdelete-oob-write.patch

----------(New B)----------
  New:  pending character reset (CVE-2026-77117, bsc#1277921, BZ #34556)
- eucjisx-pending-char-reset.patch: iconvdata: EUC_JISX0213 decoding lacks
  pending character reset (CVE-2026-80489, bsc#1277922, BZ #34568)
  New:  pending character reset (CVE-2026-80489, bsc#1277922, BZ #34568)
- libio-fopen-ccs.patch: libio: Fix CVE-2026-18374 heap buffer overflow in
  ccs= handling (CVE-2026-18374, bsc#1277262, BZ #34574)
  New:  (CVE-2026-19542, bsc#1276946, BZ #34506)
- sjisx-pending-char-reset.patch: iconvdata: SHIFT_JISX0213 decoding lacks
  pending character reset (CVE-2026-77117, bsc#1277921, BZ #34556)
  New:
- strfmon-right-just.patch: stdlib: Fix right-justification in strfmon
  (CVE-2026-19499, bsc#1276892, BZ #34510)
  New:  (CVE-2026-19499, bsc#1276892, BZ #34510)
- tdelete-oob-write.patch: misc: Fix out-of-bounds array write in tdelete
  (CVE-2026-19542, bsc#1276946, BZ #34506)
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ glibc.spec ++++++
--- /var/tmp/diff_new_pack.ZxzbL0/_old  2026-09-15 12:48:16.382564182 +0200
+++ /var/tmp/diff_new_pack.ZxzbL0/_new  2026-09-15 12:48:16.384564265 +0200
@@ -351,6 +351,16 @@
 Patch1002:      math-x86-64-tanh-floatn-aliases.patch
 # PATCH-FIX-UPSTREAM elf: Honour skip_ifunc for cross-object IFUNC relocations 
(BZ #34428)
 Patch1003:      elf-honor-skip-ifunc-for-ifunc-relocations.patch
+# PATCH-FIX-UPSTREAM stdlib: Fix right-justification in strfmon 
(CVE-2026-19499, BZ #34510)
+Patch1004:      strfmon-right-just.patch
+# PATCH-FIX-UPSTREAM misc: Fix out-of-bounds array write in tdelete 
(CVE-2026-19542, BZ #34506)
+Patch1005:      tdelete-oob-write.patch
+# PATCH-FIX-UPSTREAM iconvdata: SHIFT_JISX0213 decoding lacks pending 
character reset (CVE-2026-77117, BZ #34556)
+Patch1006:      sjisx-pending-char-reset.patch
+# PATCH-FIX-UPSTREAM iconvdata: EUC_JISX0213 decoding lacks pending character 
reset (CVE-2026-80489, BZ #34568)
+Patch1007:      eucjisx-pending-char-reset.patch
+# PATCH-FIX-UPSTREAM libio: Fix CVE-2026-18374 heap buffer overflow in ccs= 
handling (CVE-2026-18374, BZ #34574)
+Patch1008:      libio-fopen-ccs.patch
 %endif
 
 ###

++++++ eucjisx-pending-char-reset.patch ++++++
>From cb61572ea3f773e1e1978f6c412cc36a30acdb0c Mon Sep 17 00:00:00 2001
From: Florian Weimer <[email protected]>
Date: Fri, 28 Aug 2026 10:26:07 +0200
Subject: [PATCH] iconvdata: EUC_JISX0213 decoding lacks pending character
 reset (CVE-2026-80489)

This fixes bug 34568.

Reviewed-by: Carlos O'Donell <[email protected]>
(cherry picked from commit 4dafa087ff5fe7df45bd37dc727e988da6b8c935)
---
 iconvdata/euc-jisx0213.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/iconvdata/euc-jisx0213.c b/iconvdata/euc-jisx0213.c
index 5572bbdb7b..61c22231e1 100644
--- a/iconvdata/euc-jisx0213.c
+++ b/iconvdata/euc-jisx0213.c
@@ -224,6 +224,9 @@
            STANDARD_FROM_LOOP_ERR_HANDLER (1);                               \
          }                                                                   \
       }                                                                        
      \
+    else                                                                     \
+      /* There was a pending character.  Clear it.  */                       \
+      *statep = 0;                                                           \
                                                                              \
     put32 (outptr, ch);                                                        
      \
     outptr += 4;                                                             \
-- 
2.55.0



++++++ libio-fopen-ccs.patch ++++++
>From 0b4e41fc51e6aba6216a908961b49b0622b47fa0 Mon Sep 17 00:00:00 2001
From: Dongkyun Son <[email protected]>
Date: Fri, 4 Sep 2026 21:28:41 +0900
Subject: [PATCH] libio: Fix CVE-2026-18374 heap buffer overflow in ccs=
 handling

When fopen() is called with a ,ccs= parameter whose value becomes empty
after strip(), the code must reject it with EINVAL instead of attempting
to use it.  The original upstr() fallback could read past the ',' delimiter
and cause a heap buffer overflow.

The fix checks if the charset specification is empty after strip() and
returns EINVAL immediately, preventing the overflow and following the
approach described in BZ #34574.

CVE-2026-18374 - CVSS 4.9 (AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)

Reported-by: AISLE in partnership with Red Hat
Signed-off-by: Dongkyun Son <[email protected]>
Reviewed-by: Florian Weimer <[email protected]>
(cherry picked from commit 9765a538ebf8661a6e5578e01e35a3dd30db7eb4)
---
 libio/fileops.c | 12 +++++++-----
 1 file changed, 7 insertions(+), 5 deletions(-)

diff --git a/libio/fileops.c b/libio/fileops.c
index 9348d7c3a1..5a249725ee 100644
--- a/libio/fileops.c
+++ b/libio/fileops.c
@@ -355,12 +355,14 @@ _IO_new_file_fopen (FILE *fp, const char *filename, const 
char *mode,
          *((char *) __mempcpy (ccs, cs + 5, endp - (cs + 5))) = '\0';
          strip (ccs, ccs);
 
-         if (__wcsmbs_named_conv (&fcts, ccs[2] == '\0'
-                                  ? upstr (ccs, cs + 5) : ccs) != 0)
+         /* After stripping, ccs[2] == '\0' means the charset name is empty.
+            This is not a valid charset and would cause problems downstream.
+            Reject it with EINVAL (BZ #34574, CVE-2026-18374).  */
+         if (ccs[2] == '\0' || __wcsmbs_named_conv (&fcts, ccs) != 0)
            {
-             /* Something went wrong, we cannot load the conversion modules.
-                This means we cannot proceed since the user explicitly asked
-                for these.  */
+             /* Either the charset name is empty after strip(), or conversion
+                modules cannot be loaded.  This means we cannot proceed since
+                the user explicitly asked for character conversion.  */
              (void) _IO_file_close_it (fp);
              free (ccs);
              __set_errno (EINVAL);
-- 
2.55.0


++++++ sjisx-pending-char-reset.patch ++++++
>From 6f9b2bfa500bf5d1cff5d990adfff4b71298dadd Mon Sep 17 00:00:00 2001
From: Florian Weimer <[email protected]>
Date: Fri, 28 Aug 2026 10:26:07 +0200
Subject: [PATCH] iconvdata: SHIFT_JISX0213 decoding lacks pending character
 reset (CVE-2026-77117)

This fixes bug 34556.

Reviewed-by: Carlos O'Donell <[email protected]>
(cherry picked from commit 68d94bbe50b7577d48998107d632ef3a0df050e3)
---
 iconvdata/shift_jisx0213.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/iconvdata/shift_jisx0213.c b/iconvdata/shift_jisx0213.c
index 61c9c3ce6d..e9179f605e 100644
--- a/iconvdata/shift_jisx0213.c
+++ b/iconvdata/shift_jisx0213.c
@@ -226,6 +226,9 @@
            STANDARD_FROM_LOOP_ERR_HANDLER (1);                               \
          }                                                                   \
       }                                                                        
      \
+    else                                                                     \
+      /* There was a pending character.  Clear it.  */                       \
+      *statep = 0;                                                           \
                                                                              \
     put32 (outptr, ch);                                                        
      \
     outptr += 4;                                                             \
-- 
2.55.0


++++++ strfmon-right-just.patch ++++++
>From 63b53df549451a5d69fcba6d7612ea99f517e8e3 Mon Sep 17 00:00:00 2001
From: Florian Weimer <[email protected]>
Date: Thu, 27 Aug 2026 13:34:54 +0200
Subject: [PATCH] stdlib: Fix right-justification in strfmon (bug 34510,
 CVE-2026-19499)

The memmove call did not take into account that __printf_buffer_pad
updated the buffer pointers.

Fixes commit e88b9f0e5cc50cab57a299dc7efe1a4eb385161d
("stdio-common: Convert vfprintf and related functions to buffers"),
which went into glibc 2.37.

Reviewed-by: Adhemerval Zanella  <[email protected]>
(cherry picked from commit b090cf226ff65b913e41536f1f573f500855615c)
---
 stdlib/Makefile               |  1 +
 stdlib/strfmon_l.c            |  5 +++--
 stdlib/tst-strfmon-bug34510.c | 33 +++++++++++++++++++++++++++++++++
 3 files changed, 37 insertions(+), 2 deletions(-)
 create mode 100644 stdlib/tst-strfmon-bug34510.c

diff --git a/stdlib/Makefile b/stdlib/Makefile
index addf7dc99f..16948eb512 100644
--- a/stdlib/Makefile
+++ b/stdlib/Makefile
@@ -347,6 +347,7 @@ tests := \
   tst-stdc_leading_zeros \
   tst-stdc_trailing_ones \
   tst-stdc_trailing_zeros \
+  tst-strfmon-bug34510 \
   tst-strfmon_l \
   tst-strfrom \
   tst-strfrom-locale \
diff --git a/stdlib/strfmon_l.c b/stdlib/strfmon_l.c
index f864289480..c39babaeae 100644
--- a/stdlib/strfmon_l.c
+++ b/stdlib/strfmon_l.c
@@ -549,7 +549,8 @@ __vstrfmon_l_buffer (struct __printf_buffer *buf, locale_t 
loc,
       /* Now test whether the output width is filled.  */
       if (buf->write_ptr - startp < width)
        {
-         size_t pad_width = width - (buf->write_ptr - startp);
+         size_t written_width = buf->write_ptr - startp;
+         size_t pad_width = width - written_width;
          __printf_buffer_pad (buf, ' ', pad_width);
          if (__printf_buffer_has_failed (buf))
            /* Implies length check.  */
@@ -558,7 +559,7 @@ __vstrfmon_l_buffer (struct __printf_buffer *buf, locale_t 
loc,
             Otherwise move the field contents in place.  */
          if (!left)
            {
-             memmove (startp + pad_width, startp, buf->write_ptr - startp);
+             memmove (startp + pad_width, startp, written_width);
              memset (startp, ' ', pad_width);
            }
        }
diff --git a/stdlib/tst-strfmon-bug34510.c b/stdlib/tst-strfmon-bug34510.c
new file mode 100644
index 0000000000..b187bde1f4
--- /dev/null
+++ b/stdlib/tst-strfmon-bug34510.c
@@ -0,0 +1,33 @@
+/* Test handling of right-padding in strfmon (bug 34510, CVE-2026-19499).
+   Copyright (C) 2026 Free Software Foundation, Inc.
+   This file is part of the GNU C Library.
+
+   The GNU C Library is free software; you can redistribute it and/or
+   modify it under the terms of the GNU Lesser General Public
+   License as published by the Free Software Foundation; either
+   version 2.1 of the License, or (at your option) any later version.
+
+   The GNU C Library is distributed in the hope that it will be useful,
+   but WITHOUT ANY WARRANTY; without even the implied warranty of
+   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
+   Lesser General Public License for more details.
+
+   You should have received a copy of the GNU Lesser General Public
+   License along with the GNU C Library; if not, see
+   <https://www.gnu.org/licenses/>.  */
+
+#include <monetary.h>
+#include <errno.h>
+#include <support/check.h>
+#include <support/next_to_fault.h>
+
+static int
+do_test (void)
+{
+  struct support_next_to_fault ntf = support_next_to_fault_allocate (100);
+  TEST_COMPARE (strfmon (ntf.buffer, ntf.length, "%100n", 1.23), -1);
+  TEST_COMPARE (errno, E2BIG);
+  return 0;
+}
+
+#include <support/test-driver.c>
-- 
2.55.0


++++++ tdelete-oob-write.patch ++++++
>From d6ff274313d79feb864cc10eb775b91c817a67e9 Mon Sep 17 00:00:00 2001
From: Florian Weimer <[email protected]>
Date: Fri, 14 Aug 2026 13:41:16 +0200
Subject: [PATCH] misc: Fix out-of-bounds array write in tdelete (bug 34506)

Allocate the maximum array sizes directly, instead of resizing
the arrays as needed.  This eliminates alloca usage from the
function, and fixes the out-of-bounds accesses.  The asserts
guard against the bug coming back if the balancing of the tree
turns out not to work correctly.

Reviewed-by: Adhemerval Zanella <[email protected]>
(cherry picked from commit e2789c46e3bfdcd67a82bea9946b315c179e83d3)
---
 misc/tsearch.c | 31 +++++++++++--------------------
 1 file changed, 11 insertions(+), 20 deletions(-)

diff --git a/misc/tsearch.c b/misc/tsearch.c
index 9b2eb34b25..e517dfa712 100644
--- a/misc/tsearch.c
+++ b/misc/tsearch.c
@@ -85,6 +85,7 @@
 #include <assert.h>
 #include <stdalign.h>
 #include <stddef.h>
+#include <stdint.h>
 #include <stdlib.h>
 #include <string.h>
 #include <search.h>
@@ -406,12 +407,13 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t 
compar)
   int cmp;
   node *rootp = (node *) vrootp;
   node root, unchained;
-  /* Stack of nodes so we remember the parents without recursion.  It's
-     _very_ unlikely that there are paths longer than 40 nodes.  The tree
-     would need to have around 250.000 nodes.  */
-  int stacksize = 40;
+  /* Stack of nodes so we remember the parents without recursion.  The
+     stack size is a conservative approximation of the maximum height
+     of a red-black tree, based on size of the address space.
+     Actual numbers are closer to 57 (32 bit) and 117 (63 bit).  */
+  enum { stacksize = 2 * UINTPTR_WIDTH };
   int sp = 0;
-  node **nodestack = alloca (sizeof (node *) * stacksize);
+  node *nodestack[stacksize];
 
   if (rootp == NULL)
     return NULL;
@@ -424,14 +426,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t 
compar)
   root = DEREFNODEPTR(rootp);
   while ((cmp = (*compar) (key, root->key)) != 0)
     {
-      if (sp == stacksize)
-       {
-         node **newstack;
-         stacksize += 20;
-         newstack = alloca (sizeof (node *) * stacksize);
-         nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
-       }
-
+      assert (sp < stacksize);
       nodestack[sp++] = rootp;
       p = DEREFNODEPTR(rootp);
       if (cmp < 0)
@@ -470,13 +465,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t 
compar)
       node upn;
       for (;;)
        {
-         if (sp == stacksize)
-           {
-             node **newstack;
-             stacksize += 20;
-             newstack = alloca (sizeof (node *) * stacksize);
-             nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
-           }
+         assert (sp < stacksize);
          nodestack[sp++] = parentp;
          parentp = up;
          upn = DEREFNODEPTR(up);
@@ -541,6 +530,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t 
compar)
                  SETNODEPTR(pp,q);
                  /* Make sure pp is right if the case below tries to use
                     it.  */
+                 assert (sp < stacksize);
                  nodestack[sp++] = pp = LEFTPTR(q);
                  q = RIGHT(p);
                }
@@ -625,6 +615,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t 
compar)
                  SETLEFT(p,RIGHT(q));
                  SETRIGHT(q,p);
                  SETNODEPTR(pp,q);
+                 assert (sp < stacksize);
                  nodestack[sp++] = pp = RIGHTPTR(q);
                  q = LEFT(p);
                }
-- 
2.55.0


++++++ ulp-prologue-into-asm-functions.patch ++++++
--- /var/tmp/diff_new_pack.ZxzbL0/_old  2026-09-15 12:48:16.865584302 +0200
+++ /var/tmp/diff_new_pack.ZxzbL0/_new  2026-09-15 12:48:16.873584635 +0200
@@ -1,4 +1,4 @@
-From a4b0acf5c85f303aa7c8ebc0f1c9b890b1451320 Mon Sep 17 00:00:00 2001
+From dd8e26e7d170bb7d1b81d9f2a4ab704f3b08a746 Mon Sep 17 00:00:00 2001
 From: Giuliano Belinassi <[email protected]>
 Date: Fri, 18 Apr 2025 14:22:49 -0300
 Subject: [PATCH] Add Userspace Livepatch prologue into ASM functions
@@ -179,13 +179,13 @@
  RELEASE=`sed -n -e 's/^#define RELEASE "\([^"]*\)"/\1/p' < $srcdir/version.h`
  AC_SUBST(VERSION)
 diff --git a/sysdeps/powerpc/powerpc64/le/Makefile 
b/sysdeps/powerpc/powerpc64/le/Makefile
-index b77775cf95..8340a8e02f 100644
+index b77775cf95..a8250947fd 100644
 --- a/sysdeps/powerpc/powerpc64/le/Makefile
 +++ b/sysdeps/powerpc/powerpc64/le/Makefile
 @@ -1,3 +1,11 @@
 +# Add flags for Userspace Livepatching support.
 +ifeq (yes,$(enable-userspace-livepatch))
-++cflags += -fpatchable-function-entry=14,13
+++cflags += -fpatchable-function-entry=14,13 -flive-patching=inline-clone
 +ifeq (yes,$(supports-msplit-patch-nops))
 ++cflags += -msplit-patch-nops
 +endif
@@ -277,13 +277,13 @@
  #define ENTRY(name, ...)                      \
        ENTRY_TOCLESS(name, ## __VA_ARGS__)
 diff --git a/sysdeps/x86_64/Makefile b/sysdeps/x86_64/Makefile
-index ff0463d7ca..3d81acbcfa 100644
+index ff0463d7ca..6b01b14475 100644
 --- a/sysdeps/x86_64/Makefile
 +++ b/sysdeps/x86_64/Makefile
 @@ -1,3 +1,8 @@
 +# Add flags for Userspace Livepatching support.
 +ifeq (yes,$(enable-userspace-livepatch))
-++cflags += -fpatchable-function-entry=16,14
+++cflags += -fpatchable-function-entry=16,14 -flive-patching=inline-clone
 +endif
 +
  # The i387 `long double' is a distinct type we support.

Reply via email to