Hi Salvatore, On 2026-08-27 15:41, Salvatore Bonaccorso wrote: > Source: glibc > Version: 2.43-3 > Severity: important > Tags: security upstream > X-Debbugs-Cc: [email protected], Debian Security Team > <[email protected]> > > Hi Aurelien, > > The following vulnerability was published for glibc. > > It appeared on Red Hat but only have so far the Red Hat bugzilla > entry. > > CVE-2026-77117[0]: > | Non-progress DoS in SHIFT_JISX0213 -> > > Is this something reported upstream?
Yes, CVE-2026-77117 is reported here: https://sourceware.org/bugzilla/show_bug.cgi?id=34556 It is linked to CVE-2026-80489 which is reported here: https://sourceware.org/bugzilla/show_bug.cgi?id=34568 There are also patches being reviewed: https://sourceware.org/pipermail/libc-alpha/2026-August/180042.html I'll include them in one of the next upload to unstable, once they are committed upstream. I'll then try to get them (with a few other ones) in the 13.8 point release. Regards Aurelien -- Aurelien Jarno GPG: 4096R/1DDD8C9B [email protected] http://aurel32.net

