Hi Salvatore,

On 2026-08-27 15:41, Salvatore Bonaccorso wrote:
> Source: glibc
> Version: 2.43-3
> Severity: important
> Tags: security upstream
> X-Debbugs-Cc: [email protected], Debian Security Team 
> <[email protected]>
> 
> Hi Aurelien,
> 
> The following vulnerability was published for glibc.
> 
> It appeared on Red Hat but only have so far the Red Hat bugzilla
> entry.
> 
> CVE-2026-77117[0]:
> | Non-progress DoS in SHIFT_JISX0213 -&gt
> 
> Is this something reported upstream?

Yes, CVE-2026-77117 is reported here:
https://sourceware.org/bugzilla/show_bug.cgi?id=34556

It is linked to CVE-2026-80489 which is reported here:
https://sourceware.org/bugzilla/show_bug.cgi?id=34568

There are also patches being reviewed:
https://sourceware.org/pipermail/libc-alpha/2026-August/180042.html

I'll include them in one of the next upload to unstable, once they are 
committed upstream. I'll then try to get them (with a few other ones) in 
the 13.8 point release.

Regards
Aurelien

-- 
Aurelien Jarno                          GPG: 4096R/1DDD8C9B
[email protected]                     http://aurel32.net

Reply via email to