From patchwork Tue Sep 26 11:41:01 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddhesh Poyarekar X-Patchwork-Id: 1839623 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (1024-bit key; secure) header.d=sourceware.org header.i=@sourceware.org header.a=rsa-sha256 header.s=default header.b=Zww77zsq; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=sourceware.org (client-ip=8.43.85.97; helo=server2.sourceware.org; envelope-from=libc-alpha-bounces+incoming=patchwork.ozlabs.org@sourceware.org; receiver=patchwork.ozlabs.org) Received: from server2.sourceware.org (server2.sourceware.org [8.43.85.97]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (secp384r1) server-digest SHA384) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4RvyWB3mMPz1yp0 for ; Tue, 26 Sep 2023 21:41:26 +1000 (AEST) Received: from server2.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 89DC4385C8B0 for ; Tue, 26 Sep 2023 11:41:24 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 89DC4385C8B0 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sourceware.org; s=default; t=1695728484; bh=gnUnrcLRN8YoDG29jI61vm0G3s+B4e50qM0ovj68gJo=; h=From:To:Subject:Date:List-Id:List-Unsubscribe:List-Archive: List-Post:List-Help:List-Subscribe:From; b=Zww77zsqIgXd+hEglo6FwjhEYfGF/5gwy235Tb8Br+NvNtEqY3tUzoXvD8mwj3d3R z6Sh3ONVHXZvYv9NhhUOIqNbA5WyaN4iE/AKtbyg5VdBHGklabzg7Qif3kNOYmHY4F IPvV9z9fTGQAIsZm6Vu2ghQ60fTZo/LbusyIOJ/c= X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from quail.birch.relay.mailchannels.net (quail.birch.relay.mailchannels.net [23.83.209.151]) by sourceware.org (Postfix) with ESMTPS id EFB57385DC2D for ; Tue, 26 Sep 2023 11:41:08 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org EFB57385DC2D Authentication-Results: sourceware.org; dmarc=fail (p=none dis=none) header.from=sourceware.org Authentication-Results: sourceware.org; spf=fail smtp.mailfrom=sourceware.org X-Sender-Id: dreamhost|x-authsender|siddhesh@gotplt.org Received: from relay.mailchannels.net (localhost [127.0.0.1]) by relay.mailchannels.net (Postfix) with ESMTP id C9881841DC4; Tue, 26 Sep 2023 11:41:07 +0000 (UTC) Received: from pdx1-sub0-mail-a315.dreamhost.com (unknown [127.0.0.6]) (Authenticated sender: dreamhost) by relay.mailchannels.net (Postfix) with ESMTPA id 6CB108419FA for ; Tue, 26 Sep 2023 11:41:07 +0000 (UTC) ARC-Seal: i=1; s=arc-2022; d=mailchannels.net; t=1695728467; a=rsa-sha256; cv=none; b=dh3x2ubsvIJf4UqdiJTVziyPf8/HwW2iSvMxNL2FMztbTWZ0sYSE+D5rGdVjzYMMSRwbo8 Xcy0VJ+la8Yypo45DbtuEPNycn7L5YFf/AF/7D/2MrFgznfmuW9poaxPdnGf/CzSMIi15j hj9mK+wXIJm7N8KBmRkO482N9sMgE374k7YSW4kHtYN6FGK0VnGAYVUzGYci8VITwn90Hz j5ZndE8qUEqx1ejl5Q2i6QZfQLdos9vjO2CJ28VY5bufh4gxbELQwwFli74NPS4fW/+2Hj aATeZB0Qnbz7OQy8yiDsj1Mv2RBfe8Kj4OuDSzGynxPWLoW3qHaVIkBfG+uHUg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=mailchannels.net; s=arc-2022; t=1695728467; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=gnUnrcLRN8YoDG29jI61vm0G3s+B4e50qM0ovj68gJo=; b=RGfQ4ToG1Xr76ZcQZTVTtVbYFtqrpw3ZG6KksaEEhyX8p0K9H/4O5QMeWi0VNZFJMLqQDd 6fXaIoYmyXGcaCwUXfYOTTrTfq5rcRSJuFFWKgUHUhvEq5EgoCQrDJVqHPg+CvgnPKrjf8 +wPktQ4IrWrtp0ThapkTiZHaHlEq4HCowZ4LCwYSu6o89CyDryrUTC+fqwrPGMe8WDXLID rHd/jkbudRT+t/kd1g9hR/igprNw37KmtaSI3wiwgZrWbqaaAk5iBUbqvY60eE6CyJDRom D2TosEQhoSKue/2uVgT0ISRM1JEQ8rfal27QbhFR0xBqQe4ctIi/8Dc7T4ez8Q== ARC-Authentication-Results: i=1; rspamd-7d5dc8fd68-mrvk5; auth=pass smtp.auth=dreamhost smtp.mailfrom=siddhesh@sourceware.org X-Sender-Id: dreamhost|x-authsender|siddhesh@gotplt.org X-MC-Relay: Neutral X-MC-Copy: stored-urls X-MailChannels-SenderId: dreamhost|x-authsender|siddhesh@gotplt.org X-MailChannels-Auth-Id: dreamhost X-Fearful-Sponge: 1123867465893bd4_1695728467655_3663951660 X-MC-Loop-Signature: 1695728467654:929279108 X-MC-Ingress-Time: 1695728467654 Received: from pdx1-sub0-mail-a315.dreamhost.com (pop.dreamhost.com [64.90.62.162]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384) by 100.106.112.200 (trex/6.9.1); Tue, 26 Sep 2023 11:41:07 +0000 Received: from fedora.redhat.com (bras-vprn-toroon4834w-lp130-02-142-113-138-41.dsl.bell.ca [142.113.138.41]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: siddhesh@gotplt.org) by pdx1-sub0-mail-a315.dreamhost.com (Postfix) with ESMTPSA id 4RvyVq0pvpz1b for ; Tue, 26 Sep 2023 04:41:07 -0700 (PDT) From: Siddhesh Poyarekar To: libc-alpha@sourceware.org Subject: [committed] Document CVE-2023-4806 and CVE-2023-5156 in NEWS Date: Tue, 26 Sep 2023 07:41:01 -0400 Message-ID: <20230926114101.108198-1-siddhesh@sourceware.org> X-Mailer: git-send-email 2.41.0 MIME-Version: 1.0 X-Spam-Status: No, score=-1172.4 required=5.0 tests=BAYES_00, GIT_PATCH_0, KAM_DMARC_NONE, KAM_DMARC_STATUS, RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL, SPF_HELO_NONE, SPF_SOFTFAIL, TXREP autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces+incoming=patchwork.ozlabs.org@sourceware.org These are tracked in BZ #30884 and BZ #30843. Signed-off-by: Siddhesh Poyarekar --- NEWS | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/NEWS b/NEWS index a48c32e76f..5b7b327b29 100644 --- a/NEWS +++ b/NEWS @@ -48,6 +48,15 @@ Security related changes: 2048 bytes, getaddrinfo may potentially disclose stack contents via the returned address data, or crash. + CVE-2023-4806: When an NSS plugin only implements the + _gethostbyname2_r and _getcanonname_r callbacks, getaddrinfo could use + memory that was freed during buffer resizing, potentially causing a + crash or read or write to arbitrary memory. + + CVE-2023-5156: The fix for CVE-2023-4806 introduced a memory leak when + an application calls getaddrinfo for AF_INET6 with AI_CANONNAME, + AI_ALL and AI_V4MAPPED flags set. + The following bugs are resolved with this release: [The release manager will add the list generated by