diff options
Diffstat (limited to 'NEWS')
-rw-r--r-- | NEWS | 132 |
1 files changed, 130 insertions, 2 deletions
diff --git a/NEWS b/NEWS index 76679f3393..912a9bdc0f 100644 --- a/NEWS +++ b/NEWS @@ -125,8 +125,136 @@ Security related changes: The following bugs are resolved with this release: - [The release manager will add the list generated by - scripts/list-fixed-bugs.py just before the release.] + [10425] localedata: it_IT/it_CH: LC_TIME format is wrong + [10496] localedata: 12h time representation in multiple locales faulty + [10797] localedata: it_IT locale numeric does not have a separator for + thousands + [11319] libc: dprintf doesn't handle errors properly + [16346] time: mktime: potentially unsafe use of localtime_offset + [17248] build: glibc should not sort CFLAGS (support gcc plugins and + --param options) + [17405] libc: Implement posix_spawn_file_actions_addchdir_np, + posix_spawn_file_actions_addfchdir_np + [17426] localedata: Indian locales: set the correct date format + [17490] stdio: popen should not invoke atfork handlers + [17783] libc: TIOCSER_TEMT conditions inconsistent + [18040] regex: use-after-free in regexec/get_subexp + [18093] libc: Corrupted aux-cache causes ldconfig to segfault + [20018] network: getaddrinfo should reject IP addresses with trailing + characters (CVE-2016-10739) + [20209] localedata: Spelling mistake for Sunday in Greenlandic kl_GL + [20271] libc: Missing "\n" in __libc_fatal calls + [20480] dynamic-link: Patch: ifunc not executable, crashes sudo qemu + [20544] libc: RFE: atexit, __cxa_atexit, on_exit should assert function + pointer argument is non-NULL + [21037] stdio: open_memstream and freopen + [21286] libc: bits/siginfo.h is missing enum definition for TRAP_HWBKPT + [21716] time: Crash in glibc's mktime in low-memory situations + [22834] stdio: Subprocess forked by popen may crash in Linux when + multithreads call popen + [22927] network: crash in vn_gai_enqueue_request if requests_tail was NULL + and pthread_create fails. + [23032] hurd: sysdeps/htl/pt-barrier-init.c:39: bad call to memcmp ? + [23125] libc: riscv64: endless loop when throwing an exception from a + constructor + [23275] nptl: Race in pthread_mutex_lock while promoting to + PTHREAD_MUTEX_ELISION_NP. + [23400] libc: stdlib/test-bz22786.c creates temporary files in glibc + source tree + [23479] math: [mips] bits/fenv.h should not define some macros for soft- + float + [23490] libc: sysdeps/unix/sysv/linux/x86/tst-cet-property-2.c:49: off by + one error + [23497] libc: readdir64@GLIBC_2.1 cannot parse the kernel directory stream + [23509] dynamic-link: CET enabled glibc is incompatible with the older + linker + [23520] nscd: nscd: Use-after-free in addgetnetgrentX and its callers + [23521] nss: get_next_alias nss_files file stream leak + [23538] nptl: Hang in pthread_cond_broadcast + [23562] libc: Wrong type for si_band in Linux-specific siginfo_t + [23578] regex: Invalid memory access if regex pattern contains NUL byte + [23579] libc: Errors misreported in preadv2 + [23597] build: support/test-container.c doesn't work with different + filesystems + [23603] time: mktime signed integer overflow on large timestamps + [23606] libc: Missing ENDBR32 in sysdeps/i386/start.S + [23614] libc: powerpc: missing CFI register information in __mpn_* + functions + [23637] string: Generic strstr/strcasestr fails with huge needles + [23640] libc: no way to easily clear FD_CLOEXEC in + posix_spawn_file_actions_adddup2() + [23649] libc: [microblaze/mips/nios2/riscv] sys/procfs.h pr_uid, pr_gid + have wrong type + [23656] libc: [mips n32] sys/procfs.h pr_sigpend, pr_sighold, pr_flag have + wrong type + [23679] libc: gethostid: Missing NULL check for gethostbyname_r result + [23689] libc: Bug in documentation for rusage.ru_ixrss in + bits/types/struct_rusage.h + [23690] dynamic-link: Segfault in _dl_profile_fixup with a high number of + threads + [23707] dynamic-link: Missing unwind info in sysdeps/powerpc/powerpc32/dl- + start.S + [23709] string: glibc 2.25 lacks sse2 optimized strstr() + [23716] dynamic-link: _dl_runtime_resolve_shstk isn't selected properly + [23717] libc: glibc: stdlib/tst-setcontext9 test suite failure on + powerpc64le + [23724] localedata: Albanian date formats are incorrect + [23735] math: libnldbl_nonshared.a references internal libm symbols + [23740] localedata: kl_GL: Month names and date formats need update + [23744] regex: regex refactorings to remove BE, avoid duplication + [23745] time: mktime fix for Gnulib + coreutils + [23758] time: Improve the width of alternate representation for year in + strftime + [23783] libc: [mips] Missing CMSPAR bits/termios.h + [23789] time: mktime does not set errno on failure + [23791] localedata: Wrong monetary format for ca_ES locale + [23793] locale: c32rtomb and mbrtoc32 should not alias wcrtomb and mbrtowc + [23794] locale: c16rtomb does not handle surrogate pairs + [23821] libc: si_band in siginfo_t has wrong type long int on sparc64 + [23822] math: ia64 static libm.a is missing exp2f, log2f and powf symbols + [23836] time: time/tst-mktime2 test failure on Arm (32-bit) + [23848] libc: [sparc] Some socket syscalls wrongly assumed to be present + [23861] nptl: rdlock stalls indefinitely on an unlocked pthread rwlock + [23862] libc: [sh] missing kernel-features.h undefines + [23864] libc: [riscv] missing kernel-features.h undefines + [23867] libc: [arm/microblaze] __ASSUME_MLOCK2 incorrect + [23907] malloc: Incorrect double-free malloc tcache check disregards + tcache size + [23913] libc: off-by-one in function maybe_script_execute in + sysdeps/posix/spawni.c + [23915] libc: [arm] __ASSUME_COPY_FILE_RANGE incorrect + [23923] locale: Add --no-hard-links option to localedef + [23927] network: Linux if_nametoindex() does not close descriptor + (CVE-2018-19591) + [23961] math: powf can overflow to inf without setting errno in non- + nearest rounding mode + [23967] libc: [2.28 Regression]: New sigaction implementation breaks m68k + [23972] libc: __old_getdents64 uses wrong d_off value on overflow + [23993] libc: glibc 2.29 doesn't build with gcc 4.9 + [23995] localedata: Remove execution flags from localedata/locales/bi_VU + [24011] localedata: Fixed small type in comment for locale bs_BA + [24018] libc: gettext() may return NULL + [24022] build: riscv build failure with Linux kernel 4.20-rc7 + [24023] build: [2.29 Regression] FAIL: elf/check-localplt + [24024] string: strerror() might set errno to ENOMEM due to -fno-math- + error + [24027] malloc: glibc: realloc() ncopies 32-bit integer overflow + [24034] libc: tst-cancel21-static fails with SIGBUS on pre-ARMv7 when + using GCC 8 + [24046] localedata: en_US locale doesn't define date_fmt + [24063] manual: @var{errno} should be @code{errno} + [24066] soft-fp: Inconsistent _FP_W_TYPE_SIZE check + [24088] libc: VSCR field is not being correctly read in ucontext_t on + ppc64le + [24096] time: Specifying '_' or '-' flag for "%EY" does not produce the + expected result + [24097] string: Can't use 64-bit register for size_t in assembly codes for + x32 (CVE-2019-6488) + [24110] hurd: SS_DISABLE never set in stack_t value returned by + sigaltstack + [24112] network: Do not send DNS queries for non-host names (where all + answers will be rejected) + [24130] libc: alpha __remqu corrupts $f3 register Version 2.28 |