This bug was fixed in the package glibc - 2.44-1ubuntu1
---------------
glibc (2.44-1ubuntu1) stonking; urgency=medium
* Merge from Debian experimental (LP: #2163528)
Delta dropped:
- Revert "debian/rules.d/build.mk: add a makefile function to filter out
dpkg build flags incompatible with glibc and define CFLAGS from dpkg
build flags. Closes: #1129746."
- fix ftbfs: backport OPEN_TREE conditional define (LP #2145679)
[fixed upstream in 2.44]
- debian/patches/CVE-2026-4046.patch
[fixed in 2.43-3]
- debian/patches/CVE-2026-5435.patch
[fixed in 2.43-3]
- debian/patches/CVE-2026-5450.patch
[fixed in 2.42-17]
- debian/patches/CVE-2026-5928.patch
[fixed in 2.42-17]
- debian/patches/CVE-2026-6238-*.patch
[fixed in 2.43-3]
* Delta added:
- filter -flto=auto from dpkg-buildflags to fix build
- fix tst-spawn-chdir with coreutils-rs due to invalid link name
- xfail tst-nscd-basic tstptrguard-static-dlopen (LP #2164576)
- d/tests: fix gcc dependency cross conflict on i386 autopkgtest
glibc (2.44-1) experimental; urgency=medium
[ Aurelien Jarno ]
* New upstream release:
- debian/patches/localedata/sort-UTF8-first.diff: rebased.
- debian/patches/hurd-i386/local-enable-ldconfig.diff: rebased.
- debian/patches/hurd-i386/tg-libc_rwlock_recursive.diff: dropped,
obsolete.
- debian/patches/hurd-i386/git-fork-gdb.diff: upstreamed.
- debian/patches/hurd-i386/git-sig-sig-mmx-fix.diff: upstreamed.
- debian/patches/hurd-i386/git-cancel-sig.diff: upstreamed.
- debian/patches/hurd-i386/git-mach_send_eintr.diff: upstreamed.
- debian/patches/hurd-i386/git-itimer-lock.diff: upstreamed.
- debian/patches/hurd-i386/git-posix-timers.diff: upstreamed.
- debian/patches/hurd-i386/git-sig-alarm.diff: upstreamed.
- debian/patches/hurd-i386/git-libio-mtsafe.diff: upstreamed.
- debian/patches/hurd-i386/git-timedrwlock-unlock.diff: upstreamed.
- debian/patches/hurd-i386/git-sigtimedwait-timeout.diff: upstreamed.
- debian/patches/hurd-i386/git-MSG_EXAMINE.diff: upstreamed.
- debian/patches/hurd-i386/git-interrupt-EINTR.diff: upstreamed.
- debian/patches/hurd-i386/git-SEM_FAILED.diff: upstreamed.
- debian/patches/hurd-i386/git-tst-fix.diff: upstreamed.
- debian/patches/hurd-i386/git-SO_TIMESTAMP.diff: upstreamed.
- debian/patches/hurd-i386/git-path_mounted.diff: upstreamed.
- debian/patches/any/local-nss-overflow.diff: upstreamed.
- debian/patches/any/local-ldconfig-multiarch.diff: refreshed.
- debian/symbols.wildcards: add 2.44.
- debian/sysdeps/arm64.mk: stop passing --enable-memory-tagging to
configure, support for it was removed upstream.
* debian/patches/git-updates.diff: update from upstream stable branch.
[ Samuel Thibault ]
* debian/patches/hurd-i386/submitted-net.diff: rebased.
glibc (2.43-3) unstable; urgency=medium
[ Samuel Thibault ]
* debian/testsuite-xfail-debian.mk: Update hurd results.
* debian/patches/hurd-i386/submitted-path_mounted.diff: Renamed to
git-path_mounted.diff.
[ Aurelien Jarno ]
* debian/patches/git-updates.diff: update from upstream stable branch:
- debian/patches/hurd-i386/local-disable-ioctls.diff: rebased.
- debian/patches/hurd-i386/submitted-AF_LINK.diff: upstreamed.
- debian/patches/hurd-i386/submitted-AF_ROUTE.diff: upstreamed.
- Fix a buffer overread in ns_sprintrrf with corrupted RDATA field
(CVE-2026-6238). Closes: #1135231.
- Fix an out-of-bounds write in ns_sprintrrf when printing TSIG records
(CVE-2026-5435). Closes: #1135230.
- Fix stack overflow in wordexp tilde expansion (CVE-2026-6791).
- Cache cpuid results in ld.so for Intel CPUs.
- Restore optimized memchr for POWER10.
* debian/control.in/libc, debian/rules.d/debhelper.mk: drop the libc6-dev
dependency on rpcsvc-proto.
* debian/watch: set Git-Mode to shallow.
-- Simon Poirier <[email protected]> Tue, 11 Aug 2026
18:48:32 -0400
** Changed in: glibc (Ubuntu)
Status: Fix Committed => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2026-4046
** CVE added: https://cve.org/CVERecord?id=CVE-2026-5435
** CVE added: https://cve.org/CVERecord?id=CVE-2026-5450
** CVE added: https://cve.org/CVERecord?id=CVE-2026-5928
** CVE added: https://cve.org/CVERecord?id=CVE-2026-6238
** CVE added: https://cve.org/CVERecord?id=CVE-2026-6791
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163528
Title:
FFE: Merge glibc 2.44-1 from Debian for stonking cycle
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/glibc/+bug/2163528/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs