Your message dated Mon, 10 Aug 2026 12:33:53 +0000
with message-id <[email protected]>
and subject line Bug#1135231: fixed in glibc 2.43-3
has caused the Debian Bug report #1135231,
regarding glibc: CVE-2026-6238
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1135231: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1135231
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: glibc
Version: 2.42-15
Severity: important
Tags: security upstream
Forwarded: https://sourceware.org/bugzilla/show_bug.cgi?id=34069
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for glibc, filling mainly
for tracking.

CVE-2026-6238[0]:
| The deprecated functions ns_printrrf, ns_printrr and fp_nquery in
| the GNU C Library version 2.2 and newer fail to validate the RDATA
| content against the RDATA length in a DNS response when processing
| LOC, CERT, TKEY or TSIG records, which may allow an attacker to
| craft a DNS response, causing a target application to crash or read
| uninitialized memory.  These functions are for application debugging
| only and hence not in the path of code executed by the DNS resolver.
| Further, they have been deprecated since version 2.34 and should not
| be used by any new applications.  Applications should consider
| porting away from these interfaces since they may be removed in
| future versions.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-6238
    https://www.cve.org/CVERecord?id=CVE-2026-6238
[1] https://sourceware.org/bugzilla/show_bug.cgi?id=34069
[2] 
https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0012

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: glibc
Source-Version: 2.43-3
Done: Aurelien Jarno <[email protected]>

We believe that the bug you reported is fixed in the latest version of
glibc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Aurelien Jarno <[email protected]> (supplier of updated glibc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 10 Aug 2026 14:19:03 +0200
Source: glibc
Architecture: source
Version: 2.43-3
Distribution: unstable
Urgency: medium
Maintainer: GNU Libc Maintainers <[email protected]>
Changed-By: Aurelien Jarno <[email protected]>
Closes: 1135230 1135231
Changes:
 glibc (2.43-3) unstable; urgency=medium
 .
   [ Samuel Thibault ]
   * debian/testsuite-xfail-debian.mk: Update hurd results.
   * debian/patches/hurd-i386/submitted-path_mounted.diff: Renamed to
     git-path_mounted.diff.
 .
   [ Aurelien Jarno ]
   * debian/patches/git-updates.diff: update from upstream stable branch:
     - debian/patches/hurd-i386/local-disable-ioctls.diff: rebased.
     - debian/patches/hurd-i386/submitted-AF_LINK.diff: upstreamed.
     - debian/patches/hurd-i386/submitted-AF_ROUTE.diff: upstreamed.
     - Fix a buffer overread in ns_sprintrrf with corrupted RDATA field
       (CVE-2026-6238).  Closes: #1135231.
     - Fix an out-of-bounds write in ns_sprintrrf when printing TSIG records
       (CVE-2026-5435).  Closes: #1135230.
     - Fix stack overflow in wordexp tilde expansion (CVE-2026-6791).
     - Cache cpuid results in ld.so for Intel CPUs.
     - Restore optimized memchr for POWER10.
   * debian/control.in/libc, debian/rules.d/debhelper.mk: drop the libc6-dev
     dependency on rpcsvc-proto.
   * debian/watch: set Git-Mode to shallow.
Checksums-Sha1:
 f3350d9c0a75462395929125eb3594be653febc4 8571 glibc_2.43-3.dsc
 d72782636b9ef765895fa28fd9f1056c9cf6bc8b 479456 glibc_2.43-3.debian.tar.xz
 61b194bc811152ac0b89d27c3898759cdfdf96bd 9529 glibc_2.43-3_source.buildinfo
Checksums-Sha256:
 256b1d37ce7a0e46e40f70b9faba73e4130bcf737eba2f9f8a966e0b268485db 8571 
glibc_2.43-3.dsc
 f0163ed968b7e9e935833dc2e0478bb6bcf6d772ff2879f14b4c14115eedfb84 479456 
glibc_2.43-3.debian.tar.xz
 eb4a01d9ea4e24d892dee2e4bccbc8ad1f58b827efedbfc9c7e22a76c30893bf 9529 
glibc_2.43-3_source.buildinfo
Files:
 04ba19527762484383c06d5aa45adfaa 8571 libs required glibc_2.43-3.dsc
 35eaff73603a66441a469b644f41cb2f 479456 libs required 
glibc_2.43-3.debian.tar.xz
 74ff9c1093798f88180e132938ab64ae 9529 libs required 
glibc_2.43-3_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUryGlb40+QrX1Ay4E4jA+JnoM2sFAmp5wtsACgkQE4jA+Jno
M2teHg//f/bux+rbHTdkFgCHQSwBAYhHljyscftGamSGqarbjvcGJ/v+m1G+XGQk
mcOjRMz48QB9IB++2ZqKlywIpFyKJrFufUqwnSkSeVP5+sUYn6kbhmpXGk79S9Xd
o15+0LbmGU2s1MXPYAP5nwDrAr9Isre8e0GojLQRNXW0jbcg9jCTNA1vaoNOECNg
3oEjFNv6JADCaPvWjyIaZNn0e7hV+E7DeAaMqY87NWbFysIZl2M4K59G4QV5B5he
DUdFCvlLjT7XXD2Ysy+MrdHpdx82vu2rN+wLmhBxvaQZ4lR9EkmtFqeQcOsDVd17
iOwwK9hGdERWRMo06BI/VzaMNGBA7SoFYXH8LPgLRF+Tazy4ObLIZRtwBWUP4qAt
y0uK5BhaMCAC4iLALBSDHNRsUvou3XMV8VAJOHLPVmA5kgjnw6hN1rPKITe7nNrA
uilL6A3aaogP+A0yE1RGnvUOIapgFSmIqPKEugjenf9pUfbZHE7hiFx2a4Th2vtS
osmXu//XFjYdRVZ+acq7XqG3bbUHaMiOc4ecl128JIrxdBKY6oHO28dCLl2/JoaV
PmltWkknAz7Yoalg8F7mTKZKLXcHp9fg7BLrkhubkoZUF51uHHOwJWdWND9hdEyg
bT1HE11rI9491x8W66GTavkiyvBoaZh7h+AM+2W1djywujMfv1M=
=Z7Tl
-----END PGP SIGNATURE-----

Attachment: pgpE8WfDJpxVU.pgp
Description: PGP signature


--- End Message ---

Reply via email to