On Thu, 5 Oct 2023, Mike Crowe wrote: > On Thursday 05 October 2023 at 11:16:29 -0400, Scott Murray wrote: > > Debian's page at https://security-tracker.debian.org/tracker/CVE-2023-4911 > > indicates at the bottom that they're only vulnerable on their 2.31 based > > versions because they backported the change that introduced the > > vulnerability, which I don't believe has been done in oe-core... > > It has. > > The openembedded-core dunfell branch is using glibc > 2d4f26e5cfda682f9ce61444b81533b83f6381af. This commit is a successor of > 8e88c0d8885f68d22f47b22969c273004c6e719f, which is the backport of > 2ed18c5b534d9e92fc006202a5af0df6b72e7aca (as mentioned in the Qualsys > advisory) that introduced the vulnerability.
Hrm, yes, I had not realized that glibc had backported it on the 2.31 branch itself versus distros picking it themselves, my apologies. There sadly does not seem to be any public declaration yet if it is actually exploitable on pre-2.35 or not. Scott
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#188731): https://lists.openembedded.org/g/openembedded-core/message/188731 Mute This Topic: https://lists.openembedded.org/mt/101773057/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
