On Thu, 5 Oct 2023, Mike Crowe wrote:

> On Thursday 05 October 2023 at 11:16:29 -0400, Scott Murray wrote:
> > Debian's page at https://security-tracker.debian.org/tracker/CVE-2023-4911
> > indicates at the bottom that they're only vulnerable on their 2.31 based
> > versions because they backported the change that introduced the
> > vulnerability, which I don't believe has been done in oe-core...
>
> It has.
>
> The openembedded-core dunfell branch is using glibc
> 2d4f26e5cfda682f9ce61444b81533b83f6381af. This commit is a successor of
> 8e88c0d8885f68d22f47b22969c273004c6e719f, which is the backport of
> 2ed18c5b534d9e92fc006202a5af0df6b72e7aca (as mentioned in the Qualsys
> advisory) that introduced the vulnerability.

Hrm, yes, I had not realized that glibc had backported it on the 2.31
branch itself versus distros picking it themselves, my apologies.  There
sadly does not seem to be any public declaration yet if it is actually
exploitable on pre-2.35 or not.

Scott

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#188731): 
https://lists.openembedded.org/g/openembedded-core/message/188731
Mute This Topic: https://lists.openembedded.org/mt/101773057/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to