On Wed Aug 19, 2026 at 11:26 AM CEST, Hemanth Kumar M D via lists.openembedded.org wrote: > From: Hemanth Kumar M D <[email protected]> > > resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435) > > Specifically, CERT, TKEY, TSIG, OPT. This removes the buggy > implementations of TSIG, fixing bug 34033, and partially > fixing bug 34069. > > Reference: > [1] https://nvd.nist.gov/vuln/detail/CVE-2026-5435 > [2] https://sourceware.org/bugzilla/show_bug.cgi?id=34033 > [3] > https://sourceware.org/git/?p=glibc.git;a=commit;h=ca44a6609c29a683b03575fa035c6d17aa591e72 > > Signed-off-by: Hemanth Kumar M D <[email protected]> > --- > .../glibc/glibc/0024-CVE-2026-5435.patch | 137 ++++++++++++++++++ > meta/recipes-core/glibc/glibc_2.39.bb | 1 + > 2 files changed, 138 insertions(+) > create mode 100644 meta/recipes-core/glibc/glibc/0024-CVE-2026-5435.patch
Hello, As fas as I can tell, a fix for this CVE is also needed on wrynose. I can't merge here until this is fixed there. Can you send a patch to fix this on these branches and then, ping back here? Thanks! -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#244752): https://lists.openembedded.org/g/openembedded-core/message/244752 Mute This Topic: https://lists.openembedded.org/mt/120826884/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
