[{"id":3683024,"web_url":"http://patchwork.ozlabs.org/comment/3683024/","msgid":"<c54559a5-251f-4bdd-bea7-96252fee475e@gotplt.org>","list_archive_url":null,"date":"2026-04-27T22:18:28","subject":"Re: [PATCH] Add advisory text for CVE-2026-5435","submitter":{"id":69150,"url":"http://patchwork.ozlabs.org/api/people/69150/","name":"Siddhesh Poyarekar","email":"siddhesh@gotplt.org"},"content":"On 27/04/2026 17:52, Carlos O'Donell wrote:\n> ---\n>   advisories/GLIBC-SA-2026-0011 | 24 ++++++++++++++++++++++++\n>   1 file changed, 24 insertions(+)\n>   create mode 100644 advisories/GLIBC-SA-2026-0011\n\nLGTM.\n\nReviewed-by: Siddhesh Poyarekar <siddhesh@gotplt.org>\n\n> \n> diff --git a/advisories/GLIBC-SA-2026-0011 b/advisories/GLIBC-SA-2026-0011\n> new file mode 100644\n> index 0000000000..6c1e50fa74\n> --- /dev/null\n> +++ b/advisories/GLIBC-SA-2026-0011\n> @@ -0,0 +1,24 @@\n> +Potential buffer overflow in ns_sprintrrf TSIG handling path\n> +\n> +The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the\n> +GNU C Library version 2.2 and newer fail to enforce the caller-supplied\n> +buffer length, and can result in an out-of-bounds write when printing\n> +TSIG records.\n> +\n> +A defect in the TSIG case handling within ns_sprintrrf performs a\n> +formatted write using sprintf without checking the remaining buffer\n> +length, and may write up to 6 bytes past the end of the buffer.  If the\n> +library is compiled with assertions, and the out-of-bounds write doesn't\n> +terminate the process, then a subsequent check for \"len <= *buflen\" will\n> +trigger an assertion failure.\n> +\n> +These functions are for debugging only and hence not in the default path\n> +of code executed by the DNS resolver. Further, they have been deprecated\n> +since version 2.34 (2021-08-02) and should not be used by any new\n> +applications. Applications should consider porting away from these\n> +interfaces since they may be removed in future versions.\n> +\n> +CVE-Id: CVE-2026-5435\n> +Public-Date: 2026-04-02\n> +Vulnerable-Commit: b43b13ac2544b11f35be301d1589b51a8473e32b (2.2)\n> +Reported-by: shinobu","headers":{"Return-Path":"<libc-alpha-bounces~incoming=patchwork.ozlabs.org@sourceware.org>","X-Original-To":["incoming@patchwork.ozlabs.org","libc-alpha@sourceware.org"],"Delivered-To":["patchwork-incoming@legolas.ozlabs.org","libc-alpha@sourceware.org"],"Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=gotplt.org header.i=@gotplt.org header.a=rsa-sha256\n header.s=dreamhost header.b=gYf0eyTW;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=sourceware.org\n (client-ip=2620:52:6:3111::32; helo=vm01.sourceware.org;\n envelope-from=libc-alpha-bounces~incoming=patchwork.ozlabs.org@sourceware.org;\n receiver=patchwork.ozlabs.org)","sourceware.org;\n\tdkim=pass (2048-bit key,\n unprotected) header.d=gotplt.org header.i=@gotplt.org header.a=rsa-sha256\n header.s=dreamhost header.b=gYf0eyTW","sourceware.org;\n dmarc=none (p=none dis=none) header.from=gotplt.org","sourceware.org; spf=pass smtp.mailfrom=gotplt.org","server2.sourceware.org;\n arc=pass smtp.remote-ip=23.83.212.46"],"Received":["from vm01.sourceware.org (vm01.sourceware.org\n [IPv6:2620:52:6:3111::32])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4g4Hz15QTtz1yHv\n\tfor <incoming@patchwork.ozlabs.org>; Tue, 28 Apr 2026 08:18:53 +1000 (AEST)","from vm01.sourceware.org (localhost [127.0.0.1])\n\tby sourceware.org (Postfix) with ESMTP id A94994BA9018\n\tfor <incoming@patchwork.ozlabs.org>; Mon, 27 Apr 2026 22:18:51 +0000 (GMT)","from cross.elm.relay.mailchannels.net\n (cross.elm.relay.mailchannels.net [23.83.212.46])\n by sourceware.org (Postfix) with ESMTPS id AC5CD4BA9021\n for <libc-alpha@sourceware.org>; Mon, 27 Apr 2026 22:18:31 +0000 (GMT)","from relay.mailchannels.net (localhost [127.0.0.1])\n by relay.mailchannels.net (Postfix) with ESMTP id 92DFB4C2382;\n Mon, 27 Apr 2026 22:18:30 +0000 (UTC)","from pdx1-sub0-mail-a202.dreamhost.com\n (100-97-143-133.trex-nlb.outbound.svc.cluster.local [100.97.143.133])\n (Authenticated sender: dreamhost)\n by relay.mailchannels.net (Postfix) with ESMTPA id 35C204C24B9;\n Mon, 27 Apr 2026 22:18:30 +0000 (UTC)","from pdx1-sub0-mail-a202.dreamhost.com (pop.dreamhost.com\n [64.90.62.162]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384)\n by 100.97.143.133 (trex/7.1.5); Mon, 27 Apr 2026 22:18:30 +0000","from [192.168.0.247] (unknown [38.23.181.90])\n (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)\n key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest\n SHA256)\n (No client certificate requested)\n (Authenticated sender: siddhesh@gotplt.org)\n by pdx1-sub0-mail-a202.dreamhost.com (Postfix) with ESMTPSA id 4g4HyY5yl6zSQ;\n Mon, 27 Apr 2026 15:18:29 -0700 (PDT)"],"DKIM-Filter":["OpenDKIM Filter v2.11.0 sourceware.org A94994BA9018","OpenDKIM Filter v2.11.0 sourceware.org AC5CD4BA9021"],"DMARC-Filter":"OpenDMARC Filter v1.4.2 sourceware.org AC5CD4BA9021","ARC-Filter":"OpenARC Filter v1.0.0 sourceware.org AC5CD4BA9021","ARC-Seal":["i=2; a=rsa-sha256; d=sourceware.org; s=key; t=1777328312; cv=pass;\n b=L+9u/Djrw2YqkJy89kbt4Sx4DWwhQSdIaleEEjVpKaFRr3dJcAU2oATAqNvFTTqRpNAx//BRwGCDxn1BT5ubEwenMrcGzzKqK+7waPDi+Kp2mR+mb3Ok3cRzCQ/KtTzDg5d7EpvzyldvLWud9EWtqnE5fKCBIPM2A3FqYg829L4=","i=1; a=rsa-sha256; d=mailchannels.net; s=arc-2022; cv=none;\n t=1777328310;\n b=kyKO12mEHZ6XMR6guhxa1Jb+EropjvhHQpeswbgxhn/NBiwbYx1+q1Op6zi2MwGr9PZIMg\n 9AcOOgUWljS1BkGQuR0sE8Irq0klphoGe20C242m/yx99lCy5tfVqMqaAevmRYcY4ue/zV\n YTJbr9o8sRZjWnk+Z8ABieZXZOy0JP4R0VE5vFZg98jyGy6+ZIgTx4ufNNDpSqFil7AkhL\n DMJavGpvq1+ncM/PBT/Q0BETUd37tXuQY4foFOFBY23K8QxK40kLntYy5r/0bHgVnA0wp7\n q34GWYoaBw954zHtP3/TJm6Z+AdBhtEIes0PzGlUiZzuId/Tq9Q4jbIMmMi/6Q=="],"ARC-Message-Signature":["i=2; a=rsa-sha256; d=sourceware.org; s=key;\n t=1777328312; c=relaxed/simple;\n bh=mZQKoR+5Km49iUlYh6kyBPldL+eS4vNDhYKva1Dfnbs=;\n h=DKIM-Signature:Message-ID:Date:MIME-Version:Subject:To:From;\n b=oB6E1q0UkiVzRKeaKuB4PLyhxMOkmOuoJI3dj0hJBKXNbCru0ncPZm/MX2qOWzHn78c37sv1lpymWkFz4tXHHkCJnhXfWAGXgPZw/rGMHDkrrW0UEFrvP3IUy+QvOvytFcK9O5BCysUf1wtYTZ8vVgUa90Qju6IfUBUHgSmgBmU=","i=1; a=rsa-sha256; c=relaxed/relaxed;\n d=mailchannels.net; s=arc-2022; t=1777328310;\n h=from:from:reply-to:subject:subject:date:date:message-id:message-id:\n to:to:cc:mime-version:mime-version:content-type:content-type:\n content-transfer-encoding:content-transfer-encoding:\n in-reply-to:in-reply-to:references:references:dkim-signature;\n bh=9ReGOqHd9Urcv4aPC4McigfeZEl100mQU2zyMkXe46Q=;\n b=U6eUvk6Cc3N0M7MRPoLGe585WTIsErRj9UxrxEfcL39AMn3HxuTRbSeQ7n7eib+uymCWQy\n nZ51zfCjIJh4141CwqFmPM7K/xwS4hHRh2BNRaTaQb3HYlUZlzP/KLYC9h/j/RdEZt02xV\n 7adDa4T0yy2qbFgjs6j/u9iMy+OT+63rMM6ATPKV2iH6bQb+aAKOGKa7nSAj/STfoT77Lk\n Ky+7Wua5ZbYMosdkyERSi3TXZx4gkfQW5jJUZPt+5m7GhY60NdmI9YCz3DYHH3fD7Vr7Mq\n izPR4sQqQpKW0vPinTHupzObeWBHsdrEIOri9sDFWncMp+iP9Bckp6wr/GOORg=="],"ARC-Authentication-Results":["i=2; server2.sourceware.org","i=1; rspamd-55bb47d7db-wpv7b;\n auth=pass smtp.auth=dreamhost smtp.mailfrom=siddhesh@gotplt.org"],"X-Sender-Id":["dreamhost|x-authsender|siddhesh@gotplt.org","dreamhost|x-authsender|siddhesh@gotplt.org"],"X-MC-Relay":"Neutral","X-MailChannels-SenderId":"dreamhost|x-authsender|siddhesh@gotplt.org","X-MailChannels-Auth-Id":"dreamhost","X-Spicy-Wide-Eyed":"34d2bc6a579b3165_1777328310432_1458281806","X-MC-Loop-Signature":"1777328310432:2805479696","X-MC-Ingress-Time":"1777328310432","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=gotplt.org;\n s=dreamhost; t=1777328310;\n bh=9ReGOqHd9Urcv4aPC4McigfeZEl100mQU2zyMkXe46Q=;\n h=Date:Subject:To:From:Content-Type:Content-Transfer-Encoding;\n b=gYf0eyTWiLAPEmG6zsq73rAmudXtAJddvvyPTcP1lxtXSgvJR3o6IDU92kq1IXjoJ\n 45nDDax9sWBYB1G9D/5XUnGP8r1QO1SylHmds9wgR3itOnrhRZpkt9LtD2iHlLr31i\n 5CV0Hx/oYuHKlGqfURid/k7WN7Bsi6Zs8pW73KtfZOgVsuNAceJe80TRMbNJ2Qd9Ag\n vTEBXyf2/n/UizaAYIDROOmF58aAk6BFkK1qfAKjJtxYlwHxKxTvF621Qcc+cqWT4n\n yBJhQkRhARih4DmC6D2xGjP4oRDW/nuzi7m2M2gYaxtqaM6ud5o0YGzf1E+FSRDmej\n smjEj36T2E4Ig==","Message-ID":"<c54559a5-251f-4bdd-bea7-96252fee475e@gotplt.org>","Date":"Mon, 27 Apr 2026 18:18:28 -0400","MIME-Version":"1.0","User-Agent":"Mozilla Thunderbird","Subject":"Re: [PATCH] Add advisory text for CVE-2026-5435","To":"Carlos O'Donell <carlos@redhat.com>, libc-alpha@sourceware.org","References":"<20260427215230.629899-1-carlos@redhat.com>","Content-Language":"en-US","From":"Siddhesh Poyarekar <siddhesh@gotplt.org>","In-Reply-To":"<20260427215230.629899-1-carlos@redhat.com>","Content-Type":"text/plain; charset=UTF-8; format=flowed","Content-Transfer-Encoding":"7bit","X-BeenThere":"libc-alpha@sourceware.org","X-Mailman-Version":"2.1.30","Precedence":"list","List-Id":"Libc-alpha mailing list <libc-alpha.sourceware.org>","List-Unsubscribe":"<https://sourceware.org/mailman/options/libc-alpha>,\n <mailto:libc-alpha-request@sourceware.org?subject=unsubscribe>","List-Archive":"<https://sourceware.org/pipermail/libc-alpha/>","List-Post":"<mailto:libc-alpha@sourceware.org>","List-Help":"<mailto:libc-alpha-request@sourceware.org?subject=help>","List-Subscribe":"<https://sourceware.org/mailman/listinfo/libc-alpha>,\n <mailto:libc-alpha-request@sourceware.org?subject=subscribe>","Errors-To":"libc-alpha-bounces~incoming=patchwork.ozlabs.org@sourceware.org"}},{"id":3683109,"web_url":"http://patchwork.ozlabs.org/comment/3683109/","msgid":"<lhu1pfzy9lk.fsf@oldenburg.str.redhat.com>","list_archive_url":null,"date":"2026-04-28T04:47:35","subject":"Re: [PATCH] Add advisory text for CVE-2026-5435","submitter":{"id":14312,"url":"http://patchwork.ozlabs.org/api/people/14312/","name":"Florian Weimer","email":"fweimer@redhat.com"},"content":"* Carlos O'Donell:\n\n> +These functions are for debugging only and hence not in the default path\n> +of code executed by the DNS resolver. Further, they have been deprecated\n> +since version 2.34 (2021-08-02) and should not be used by any new\n> +applications. Applications should consider porting away from these\n> +interfaces since they may be removed in future versions.\n\nDrop the “default”, maybe say “application debugging”?  The proposed\nwording makes it sound like it's configurable to be on the execution\npath, which is I believe not the case.\n\nThanks,\nFlorian","headers":{"Return-Path":"<libc-alpha-bounces~incoming=patchwork.ozlabs.org@sourceware.org>","X-Original-To":["incoming@patchwork.ozlabs.org","libc-alpha@sourceware.org"],"Delivered-To":["patchwork-incoming@legolas.ozlabs.org","libc-alpha@sourceware.org"],"Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (1024-bit key;\n unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256\n header.s=mimecast20190719 header.b=GFXPolou;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=sourceware.org\n (client-ip=2620:52:6:3111::32; helo=vm01.sourceware.org;\n envelope-from=libc-alpha-bounces~incoming=patchwork.ozlabs.org@sourceware.org;\n receiver=patchwork.ozlabs.org)","sourceware.org;\n\tdkim=pass (1024-bit key,\n unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256\n header.s=mimecast20190719 header.b=GFXPolou","sourceware.org; dmarc=pass (p=quarantine dis=none)\n header.from=redhat.com","sourceware.org; spf=pass smtp.mailfrom=redhat.com","server2.sourceware.org;\n arc=none smtp.remote-ip=170.10.129.124"],"Received":["from vm01.sourceware.org (vm01.sourceware.org\n [IPv6:2620:52:6:3111::32])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4g4Sc63J7Zz1yHv\n\tfor <incoming@patchwork.ozlabs.org>; Tue, 28 Apr 2026 14:48:06 +1000 (AEST)","from vm01.sourceware.org (localhost [127.0.0.1])\n\tby sourceware.org (Postfix) with ESMTP id 909954B9DB5D\n\tfor <incoming@patchwork.ozlabs.org>; Tue, 28 Apr 2026 04:48:04 +0000 (GMT)","from us-smtp-delivery-124.mimecast.com\n (us-smtp-delivery-124.mimecast.com [170.10.129.124])\n by sourceware.org (Postfix) with ESMTP id DBA394B9DB52\n for <libc-alpha@sourceware.org>; Tue, 28 Apr 2026 04:47:44 +0000 (GMT)","from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com\n (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by\n relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3,\n cipher=TLS_AES_256_GCM_SHA384) id us-mta-501-E45-nKXPPliwgsq0bxCbkA-1; Tue,\n 28 Apr 2026 00:47:40 -0400","from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com\n (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93])\n (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest\n SHA256)\n (No client certificate requested)\n by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS\n id A7B4A19560A3; Tue, 28 Apr 2026 04:47:39 +0000 (UTC)","from fweimer-oldenburg.csb.redhat.com (unknown [10.44.48.4])\n by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with\n ESMTPS\n id 568CA180047F; Tue, 28 Apr 2026 04:47:38 +0000 (UTC)"],"DKIM-Filter":["OpenDKIM Filter v2.11.0 sourceware.org 909954B9DB5D","OpenDKIM Filter v2.11.0 sourceware.org DBA394B9DB52"],"DMARC-Filter":"OpenDMARC Filter v1.4.2 sourceware.org DBA394B9DB52","ARC-Filter":"OpenARC Filter v1.0.0 sourceware.org DBA394B9DB52","ARC-Seal":"i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1777351665; cv=none;\n b=bKXh1Gif1SRSd0eATTbBLwbVyhD7cjQyLvOAeUzXwP3EH9cCfF0mWz/MMaYzgKCar6Id9BCIc6EBVzBvhNrwrRyBVbft63bzY/1wqxlSjE2XFYcAG5EPf9SzK3vg+TFz0m+E3PxLwxNtvrph5r7nGWu61/1YDnAOcjX3tWXGatc=","ARC-Message-Signature":"i=1; a=rsa-sha256; d=sourceware.org; s=key;\n t=1777351665; c=relaxed/simple;\n bh=f3KYHgBjAY00OuaTea3bTHtICoEwMKysBAHgSPD4J2A=;\n h=DKIM-Signature:From:To:Subject:Date:Message-ID:MIME-Version;\n b=K5XtSRqJ6oLbGnnedhHXwTIP+UoQ5Dc/5I+EXmZb/FsP40UKY97VqJGviCVSzvl6hbfrSob/rSFBHlds8tXOBitRV9QsC4NcMyZ6AXK0HtI7JxvrNse0ZBkEzAPbltb6OFHMdFvbHExtMVmMx4MX7eNohBLf5ZWDge0Ll0rasDQ=","ARC-Authentication-Results":"i=1; server2.sourceware.org","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com;\n s=mimecast20190719; t=1777351664;\n h=from:from:reply-to:subject:subject:date:date:message-id:message-id:\n to:to:cc:cc:mime-version:mime-version:content-type:content-type:\n content-transfer-encoding:content-transfer-encoding:\n in-reply-to:in-reply-to:references:references;\n bh=sZSFfECjHhyHvZDjBvUfa8puHHfzlvQ1MxLlMMFvC/M=;\n b=GFXPoloupHx3KewT3oKx0JIbdllGHNDvEWB51IsoQ4oYRX3RWa2gjhWAwZNdcMOgIyKxd1\n qO/+nzWpdYGK56JURoPC8j857WBTrQZI2Vtbahc0B36Ok5BGVQvDDd2+wqDbkEQCzc0FXi\n l9sGHnwVXvbtlzy9MsOpf/nqJWvzn6U=","X-MC-Unique":"E45-nKXPPliwgsq0bxCbkA-1","X-Mimecast-MFC-AGG-ID":"E45-nKXPPliwgsq0bxCbkA_1777351659","From":"Florian Weimer <fweimer@redhat.com>","To":"Carlos O'Donell <carlos@redhat.com>","Cc":"libc-alpha@sourceware.org,  siddhesh@gotplt.org","Subject":"Re: [PATCH] Add advisory text for CVE-2026-5435","In-Reply-To":"<20260427215230.629899-1-carlos@redhat.com> (Carlos O'Donell's\n message of \"Mon, 27 Apr 2026 17:52:10 -0400\")","References":"<20260427215230.629899-1-carlos@redhat.com>","Date":"Tue, 28 Apr 2026 06:47:35 +0200","Message-ID":"<lhu1pfzy9lk.fsf@oldenburg.str.redhat.com>","User-Agent":"Gnus/5.13 (Gnus v5.13)","MIME-Version":"1.0","X-Scanned-By":"MIMEDefang 3.4.1 on 10.30.177.93","X-Mimecast-Spam-Score":"0","X-Mimecast-MFC-PROC-ID":"JCZ8vvuzxEL4DtTTReu-2Z8eIQS7SX0hr_4kP4mMh80_1777351659","X-Mimecast-Originator":"redhat.com","Content-Type":"text/plain; charset=utf-8","Content-Transfer-Encoding":"quoted-printable","X-BeenThere":"libc-alpha@sourceware.org","X-Mailman-Version":"2.1.30","Precedence":"list","List-Id":"Libc-alpha mailing list <libc-alpha.sourceware.org>","List-Unsubscribe":"<https://sourceware.org/mailman/options/libc-alpha>,\n <mailto:libc-alpha-request@sourceware.org?subject=unsubscribe>","List-Archive":"<https://sourceware.org/pipermail/libc-alpha/>","List-Post":"<mailto:libc-alpha@sourceware.org>","List-Help":"<mailto:libc-alpha-request@sourceware.org?subject=help>","List-Subscribe":"<https://sourceware.org/mailman/listinfo/libc-alpha>,\n <mailto:libc-alpha-request@sourceware.org?subject=subscribe>","Errors-To":"libc-alpha-bounces~incoming=patchwork.ozlabs.org@sourceware.org"}},{"id":3683402,"web_url":"http://patchwork.ozlabs.org/comment/3683402/","msgid":"<6bbf0c2f-2638-4dce-b8a2-9ab0d414ec45@redhat.com>","list_archive_url":null,"date":"2026-04-28T11:38:16","subject":"Re: [PATCH] Add advisory text for CVE-2026-5435","submitter":{"id":22438,"url":"http://patchwork.ozlabs.org/api/people/22438/","name":"Carlos O'Donell","email":"carlos@redhat.com"},"content":"On 4/28/26 12:47 AM, Florian Weimer wrote:\n> * Carlos O'Donell:\n> \n>> +These functions are for debugging only and hence not in the default path\n>> +of code executed by the DNS resolver. Further, they have been deprecated\n>> +since version 2.34 (2021-08-02) and should not be used by any new\n>> +applications. Applications should consider porting away from these\n>> +interfaces since they may be removed in future versions.\n> \n> Drop the “default”, maybe say “application debugging”?  The proposed\n> wording makes it sound like it's configurable to be on the execution\n> path, which is I believe not the case.\n\nCorrect, it's not the case that this code is ever in the execution pathh\nof the stub resolver.\n\nI've used your suggestions in my advisory text.","headers":{"Return-Path":"<libc-alpha-bounces~incoming=patchwork.ozlabs.org@sourceware.org>","X-Original-To":["incoming@patchwork.ozlabs.org","libc-alpha@sourceware.org"],"Delivered-To":["patchwork-incoming@legolas.ozlabs.org","libc-alpha@sourceware.org"],"Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (1024-bit key;\n unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256\n header.s=mimecast20190719 header.b=BbtWlHmB;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=sourceware.org\n (client-ip=38.145.34.32; helo=vm01.sourceware.org;\n envelope-from=libc-alpha-bounces~incoming=patchwork.ozlabs.org@sourceware.org;\n receiver=patchwork.ozlabs.org)","sourceware.org;\n\tdkim=pass (1024-bit key,\n unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256\n header.s=mimecast20190719 header.b=BbtWlHmB","sourceware.org; dmarc=pass (p=quarantine dis=none)\n header.from=redhat.com","sourceware.org; spf=pass smtp.mailfrom=redhat.com","server2.sourceware.org;\n arc=none smtp.remote-ip=170.10.133.124"],"Received":["from vm01.sourceware.org (vm01.sourceware.org [38.145.34.32])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4g4djz5Df6z1yHv\n\tfor <incoming@patchwork.ozlabs.org>; Tue, 28 Apr 2026 21:38:47 +1000 (AEST)","from vm01.sourceware.org (localhost [127.0.0.1])\n\tby sourceware.org (Postfix) with ESMTP id 9ADAD4BABF0C\n\tfor <incoming@patchwork.ozlabs.org>; Tue, 28 Apr 2026 11:38:43 +0000 (GMT)","from us-smtp-delivery-124.mimecast.com\n (us-smtp-delivery-124.mimecast.com [170.10.133.124])\n by sourceware.org (Postfix) with ESMTP id 80E604BAE7FF\n for <libc-alpha@sourceware.org>; Tue, 28 Apr 2026 11:38:21 +0000 (GMT)","from mail-qk1-f200.google.com (mail-qk1-f200.google.com\n [209.85.222.200]) by relay.mimecast.com with ESMTP with STARTTLS\n (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id\n us-mta-384-V_ebVcNhMOW4fvnJyWojIg-1; Tue, 28 Apr 2026 07:38:19 -0400","by mail-qk1-f200.google.com with SMTP id\n af79cd13be357-8eaf1ce4a9bso1623698785a.1\n for <libc-alpha@sourceware.org>; Tue, 28 Apr 2026 04:38:19 -0700 (PDT)","from [192.168.0.116] ([198.48.244.52])\n by smtp.gmail.com with ESMTPSA id\n 6a1803df08f44-8b3e281c5f8sm17523406d6.7.2026.04.28.04.38.16\n (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128);\n Tue, 28 Apr 2026 04:38:17 -0700 (PDT)"],"DKIM-Filter":["OpenDKIM Filter v2.11.0 sourceware.org 9ADAD4BABF0C","OpenDKIM Filter v2.11.0 sourceware.org 80E604BAE7FF"],"DMARC-Filter":"OpenDMARC Filter v1.4.2 sourceware.org 80E604BAE7FF","ARC-Filter":"OpenARC Filter v1.0.0 sourceware.org 80E604BAE7FF","ARC-Seal":"i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1777376301; cv=none;\n b=JXVHkwMAzAvRfsTf16kWHY4P14iJJV3lbTOe+hkfMUGtQEVgMPqmBBUNc7wgCRj1oHJcuhlFl+ZntLMR4TioeY2oSgexZNORVA+SUgU39303JHSHXTJN7mnIH0S/IeJADGq1pdBOsFDooGlPa45EJi38njBqlHJX0VOdW3wjrbg=","ARC-Message-Signature":"i=1; a=rsa-sha256; d=sourceware.org; s=key;\n t=1777376301; c=relaxed/simple;\n bh=F56h2BSXVeM2s6Tky1pspgQCzfxYyxHU4LaWpXuURiw=;\n h=DKIM-Signature:Message-ID:Date:MIME-Version:Subject:To:From;\n b=e1UGv/S5LJEEftQhV12UmnH+MU8AqGaeV1XDevI2bVUl60TEnM/U3jRuFCWgQ9x81vVyr8n9jS9CWOqS2VMPSiP1Jsp462FFeakxhq5OgCG5b1xMXNT7/4toSPCj/XzClPL4Rq7AV5Z+LmPjue2QOwRR9MbvNBfyzsaShzubv3I=","ARC-Authentication-Results":"i=1; server2.sourceware.org","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com;\n s=mimecast20190719; t=1777376301;\n h=from:from:reply-to:subject:subject:date:date:message-id:message-id:\n to:to:cc:cc:mime-version:mime-version:content-type:content-type:\n content-transfer-encoding:content-transfer-encoding:\n in-reply-to:in-reply-to:references:references;\n bh=nLb/oAK1LwnmBYqbgFn4x9ZgZOThhsZTVmGzOzggN84=;\n b=BbtWlHmBeLm6yYZzTEMDvJOgdR1dh4eV5gn3zKzCG67zQ9Q95jnFcOuzR8hHVe3Pwt9f8U\n qKaKznn9ujN0fOmowOz4xG/GMDJmta+zdQl9cloRkoujqIT7Y9+oEoRxZssyhslIqRsyL3\n GqYPtptOdNQQ1yVhTElm+kIinhkFwMU=","X-MC-Unique":"V_ebVcNhMOW4fvnJyWojIg-1","X-Mimecast-MFC-AGG-ID":"V_ebVcNhMOW4fvnJyWojIg_1777376299","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=1e100.net; s=20251104; t=1777376299; x=1777981099;\n h=content-transfer-encoding:in-reply-to:organization:from\n :content-language:references:cc:to:subject:user-agent:mime-version\n :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date\n :message-id:reply-to;\n bh=nLb/oAK1LwnmBYqbgFn4x9ZgZOThhsZTVmGzOzggN84=;\n b=Mks3vsqChc4IZBqAWpFbaffhImto3/8pqvrmkeky3WGAXc7J8IouvgKTClA7FXKdAZ\n c+EqQ4Y4Ex+VB6N+E2JfLtw9gu5PSBPImcGFn5aecm4PN9BpDzYWXATaN4MWqeOQL5AV\n fD4Gme1wBsQjDpxpuTOFm0AcIIJEUNaLSRXDJwLzO76DDIjNfEaq46BcGbPYvTIARCW2\n pFQcQTUuHGUvHZB7tgKG6xWzQGvJcNcPUgRKPHAGC5xrmCW6eVORLJzyg4I2x48/M1E1\n fGcMcXo7h1v95vIExrb6zRkhsrSgcaC5iXY69/45whJM6IYximSvScwa+ZqE7pSmKSfy\n 9iNw==","X-Gm-Message-State":"AOJu0YyFk1HDHQt3oGXxksI2ctm8wDZn9UqTsKxUi0yTJmz8R3OQBoAl\n rlgOhk35cObE23LiwmddfY6E5c14/0SGKXBH92DhdI3tTZECMJmIW4CvnV4J1l3jd0J5VxDYSWz\n HhF3glWVaOFCLcnbRky1d95I1iKHlYgG3NwVKzv6KmIJZezabYwa1ENEqVCTFv5Yc3BI8Kg==","X-Gm-Gg":"AeBDietVJjmdcBauJXgts5Xmz5JDuxggKr69UG9F05t5JZQ4OaNDAewBUdS82eaCf26\n Klr79IZ3d7Ee6Nm+KYhhbX0WVhyREkYviqj4gBOXJSCRSI+QzNN/eCa5tsvWqKNqlmgYZCfbOpZ\n PoWCM/1SgLOa/qxubhJ/kj9G+9tYb9/JqXb5BnmaqkDCOTowxQ5MHOLoyVuDAagTIs1G++Utts1\n tydqxE1KVrer5BAR326OQ/X3HYxItPQxne79msmVavYUqT/Zsrw2yIm8/iAef194xB7DF6PUdVN\n mYZ7OfC4eUFS2HsL1EjTD6Ne/WRFrrGsjkXgjN2CO3XfXYPRDwclU85lKJJr7WMOKLaTHZQChVs\n OY1ayqbPLRNuGoLz6L6S222q/dTDr383Tq1ImKAKsprpGGtzEg0idx5ExRev+dK0j5rEDSVPeHA\n 07EVW061/Lzru+reEWlE61VbjlWdAOUEcO","X-Received":["by 2002:a05:620a:4115:b0:8ee:cbf0:82f8 with SMTP id\n af79cd13be357-8f7cf0f5cd0mr303954785a.28.1777376298704;\n Tue, 28 Apr 2026 04:38:18 -0700 (PDT)","by 2002:a05:620a:4115:b0:8ee:cbf0:82f8 with SMTP id\n af79cd13be357-8f7cf0f5cd0mr303951885a.28.1777376298278;\n Tue, 28 Apr 2026 04:38:18 -0700 (PDT)"],"Message-ID":"<6bbf0c2f-2638-4dce-b8a2-9ab0d414ec45@redhat.com>","Date":"Tue, 28 Apr 2026 07:38:16 -0400","MIME-Version":"1.0","User-Agent":"Mozilla Thunderbird","Subject":"Re: [PATCH] Add advisory text for CVE-2026-5435","To":"Florian Weimer <fweimer@redhat.com>","Cc":"libc-alpha@sourceware.org, siddhesh@gotplt.org","References":"<20260427215230.629899-1-carlos@redhat.com>\n <lhu1pfzy9lk.fsf@oldenburg.str.redhat.com>","From":"Carlos O'Donell <carlos@redhat.com>","Organization":"Red Hat, LLC.","In-Reply-To":"<lhu1pfzy9lk.fsf@oldenburg.str.redhat.com>","X-Mimecast-Spam-Score":"0","X-Mimecast-MFC-PROC-ID":"IU7-iHSLMxBF3acTu1w1JDYPbaWZRIzVosFsPhUck-0_1777376299","X-Mimecast-Originator":"redhat.com","Content-Language":"en-US","Content-Type":"text/plain; charset=UTF-8; format=flowed","Content-Transfer-Encoding":"8bit","X-BeenThere":"libc-alpha@sourceware.org","X-Mailman-Version":"2.1.30","Precedence":"list","List-Id":"Libc-alpha mailing list <libc-alpha.sourceware.org>","List-Unsubscribe":"<https://sourceware.org/mailman/options/libc-alpha>,\n <mailto:libc-alpha-request@sourceware.org?subject=unsubscribe>","List-Archive":"<https://sourceware.org/pipermail/libc-alpha/>","List-Post":"<mailto:libc-alpha@sourceware.org>","List-Help":"<mailto:libc-alpha-request@sourceware.org?subject=help>","List-Subscribe":"<https://sourceware.org/mailman/listinfo/libc-alpha>,\n <mailto:libc-alpha-request@sourceware.org?subject=subscribe>","Errors-To":"libc-alpha-bounces~incoming=patchwork.ozlabs.org@sourceware.org"}}]